At EG, we develop software for our customers so they can focus on their profession.
Our industry-specific software is built by peers from the industry, and backed by the scale of EG for stability, innovation, and security.
We are committed to advancing industries by tackling big challenges such as resource use, efficiency, and sustainability.
We are a thriving global workforce of 3000+ employees, with a 850+ strong team based in Mangaluru, India. We have a people first culture fostering innovation, collaboration and continuous learning
Join us in creating software that works for people, not software that makes people work. Visit our career page to meet some of your future colleagues, explore our culture, and watch our video We Make a Difference .
Learn more about EG here .
About The Team
We think that security can be an exciting journey. With constantly evolving threat landscape and new technologies around, our success depends on our creativity in identifying new ways of securing what matters most to us. If you like to
work smart, be creative, deliver results, develop yourself, act as a team player, and really enjoy cybersecurity, you will fit perfectly for our team. Working with us will allow you to cooperate in very good atmosphere with motivated, multinational team and gain experience with leading security solutions. You will be responsible for your part of our security playground and have perspectives to grow your team in the future.
If it sounds good to you, join our boutique team of experts developing cybersecurity in diverse organizations supporting a wide spectrum of public and private entities by delivering them specialized IT solutions.
We are looking for a strategic and analytical Cybersecurity Governance Specialist to lead the development and maintenance of our information security framework and monitor compliance. Additionally, the person will be responsible for creating and executing awareness program (based on KnowB4).
Your Workday, Your Tasks And Mandatory Skill Set
- Governance Framework
- Develop, maintain, and oversee the organization's Information Security Governance Framework, ensuring alignment with CIS Controls.
- Policy & Standards Management
- Own the policy lifecycle: Author, review, update, and retire information security policies, standards, and procedures.
- Ensure all policies are written in clear, accessible language and are communicated effectively to all stakeholders.
- Ensure that policies and lower level documents are aligned with CIS Controls framework and effectively translate CIS control requirements into organization-specific requirements
- Performance Measurement and monitoring
- Measure security framework implementation progress and compliance throughout various businesses and organizational units.
- Monitor compliance with internal security policies and grant exceptions or waivers where necessary, documenting the associated risks.
- Security Awareness & Culture
- Ensure that governance requirements are translated into actionable training for employees to foster a culture of security.
- Create and execute a security awareness program for different types of audience (regular employees, developers, administrators, management).
- Operate KnowB4 platform in terms of training and phishing campaigns delivery.
Required Skills
- Minimum of 35 years of experience in Cybersecurity, IT Audit, or GRC (Governance, Risk, and Compliance).
- Proven experience writing and implementing information security policies and standards.
- Framework Proficiency: Deep understanding of frameworks such as ISO/IEC 27001/2, NIST SP 800-53, NIST CSF, COBIT, or SOC 2.
- Regulatory Knowledge: Familiarity with relevant legal and regulatory requirements (e.g., GDPR, CCPA, PCI-DSS, SOX).
- GRC Tools: Experience using GRC platforms (e.g., ServiceNow, Archer, OneTrust) to manage policy and compliance workflows is highly desirable.
- Awareness & Training Tools: Experience using KnowB4 platform is an advantage
Good To Have
- Education: Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Business Administration, or related field.
- Communication: Exceptional written and verbal communication skills; ability to explain complex security concepts to non-technical stakeholders.
- Analytical Thinking: Strong problem-solving skills with the ability to analyze data and identify trends.
- Collaboration: Ability to work cross-functionally with Legal, IT, HR, and Operations teams.
Preferred Certifications
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- CISA (Certified Information Systems Auditor)
- CISSP (Certified Information Systems Security Professional)
What Can You Expect From Us
- A professional, innovative, and business-driven environment with exposure to real-world problems and large-scale cybersecurity solutions.
- Work with super-talented and committed colleagues in a culture of collaboration, curiosity, and continuous learning.
- Flexibility to experiment and ownership to implement ideas that matter.
- Extensive opportunities for personal and professional development through our learning academies.
- A strong focus on employee well-being, inclusion, and best-in-class benefits.