Company Description CyberSRC® Consultancy is a CERT-In empanelled, award-winning organization delivering cyber security, data protection, and assurance services aligned with clients security and business objectives. The company provides integrated solutions across IT governance, cyber risk management, digital risk management, and cloud and information security. CyberSRC® also specializes in external threat intelligence, phishing simulation, information privacy, control life-cycle management, vendor security risk management, and compliance with global regulations such as SOX, HIPAA, GDPR, CCPA, RBI guidelines, and others. In addition, the organization offers security and operational controls (SOC 1/2/3), IT and security audits, system and process audits, and managed security solutions to help clients strengthen their overall risk posture.
Role Description The Senior Manager – Risk Advisory is a full-time, on-site role based in Noida, responsible for leading and delivering risk advisory and cyber security consulting engagements. This role involves overseeing risk assessments, gap analyses, compliance reviews, and audit assignments across domains such as IT governance, cyber risk management, and regulatory compliance. The Senior Manager will guide client stakeholders on risk mitigation strategies, design and implement risk frameworks, and ensure alignment with standards, regulations, and organizational objectives. Day-to-day responsibilities include managing project teams, coordinating with clients, preparing high-quality reports and presentations, and monitoring engagement timelines and quality. The role also involves contributing to service improvements, mentoring team members, supporting business development activities, and staying updated on evolving cyber laws, standards, and best practices.
Qualifications
- Strong experience in IT Governance, Cyber Security Risk Management, Digital Risk Management, and Cloud Security, with the ability to design and implement risk frameworks and security controls.
- Proficiency in Information Security, Information Privacy, Control Life-cycle Management, and Vendor Security Risk Management, including assessment and remediation planning.
- Hands-on expertise in Compliance Management for regulations and standards such as SOX, HIPAA, GDPR, CCPA, Cyber Laws, PPI, Aadhar Act, RBI guidelines, and related frameworks.
- Experience with Security & Operation Controls (SOC 1/2/3), IT and Security Audits, System Audits, and Process Audits, including reporting and stakeholder communication.
- Knowledge of External Threat Intelligence, Phishing Simulation, and Managed Security Solutions, with the ability to interpret threat data and recommend defensive measures.
- Relevant academic background in Information Security, Computer Science, IT, or a related field; professional certifications such as CISA, CISM, CISSP, ISO 27001 LA, or similar are highly beneficial.
- Demonstrated leadership in managing consulting teams and client engagements, strong analytical and problem-solving skills,