Job Title: Consultant | ISO:27001 | Bengaluru | Cyber Strategy & Transformation
Your work profile
As a Consultant in our Cyber Team you’ll build and nurture positive working relationships with teams and clients with the intention to exceed client expectations: -
• 2+ Years of experience ISO 27001 based Information Security Management System implementation and sustenance based projects
• Guide teams to assess client information security posture, identify the gaps/risks in the existing environment and develop solutions to mitigate the identified gaps/risk
• Responsible to assist client in review / implement Information Security controls in areas as mentioned, but not limited to: Change management process, Incident management process, Backup process, User identity and access management, Antivirus management, SLA performance and monitoring, Media handling & Exchange of information, Physical and environmental Security, and Media & Information Handling
• Manages multiple clients vendors risk assessments projects and guides team in providing a holistic view of clients risk exposure due to outsourcing
• Lead teams to conduct Information Systems audits covering IT infrastructure assets Advice clients on data privacy, data leakage prevention, identity and access management
• Manages security and privacy projects, guides the team on a day-to-day basis and ensures that assigned tasks and responsibilities are fulfilled in a timely fashion
• Demonstrates understanding of complex business and information technology management processes
• Interacts with clients, managers and partners to build and nurture strong relationships
• Tailors firm tools and methodologies as per client requirements
• Evaluates, counsels, mentors and provides feedback on performance of others
• Assist in retention of people and lead training efforts
• Manages day-to-day client relationships at appropriate senior management levels
• Contributes to sales process by participating and/or leading proposal development efforts to sell "add-on" work to client
• Identifies opportunities for cross selling across service lines
• Play substantive/lead role in engagement planning, economics, and billing
• Demonstrates a general knowledge of market trends, competitor activities, firm products and service lines
Desired qualifications
• Extensive experience in leveraging industry standards and frameworks such as ISO/IEC 17799, ISO/IEC 27001, COBIT, ITIL, etc.
• Experience in design, development and roll-out of security and privacy programs, developing IT risk management strategies, compliance programs
• Experience in building vulnerability management programs for organizations
• Experience in designing Secure Development Lifecycle for organizations (Strategic roadmap and implementation)
• Cyber Threat and Risk Assessment - Ability to identify business implications and identifying tactical and strategic recommendations to mitigate the risk.
• Possesses certifications such as ISO27001 LA/ LI, ISO22301 LA/LI, Prince2, PMP, CISSP, CISA, CISM certification- preferred
• Ability to define the business & technical scope of a project. Should be able to independently lead delivery teams to deliver projects according to client specifications after such scope is defined
• B.E / B.Tech (Tier 1/2) in Computer Science, Information Technology or related fields
• ISO 27001 LA/LI, ISO 31000 LA/LI, ISO 22301 LA/LI, CISA, ITIL, or equivalent certification preferred
• CISSP, GSEC, GCIH, CEH, LPT, CCSK, eGRC tools like Archer, OpenPages or functional certifications would be preferred
Location and way of working
• Base location: Bangalore
• This profile involves frequent / occasional travelling to client locations OR this profile does not involve extensive travel for work.
Hybrid is our default way of working. Each domain has customised the hybrid approach to their unique needs.