Cyber Technical Assurance Manager

Apex Group Ltd (India Branch)

Pune District

On-site

INR 350,000 - 520,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Apex Group Ltd (India Branch) is seeking a senior IT/Cyber Risk leader to govern and improve risk metrics, align with Cyber Strategy, and support the Group CISO.

You will drive RCSA across technology domains, coordinate remediation plans, and deliver automated dashboards with clear ownership and evidence for regulatory and internal stakeholders.

Qualifications

  • 10–15+ years in IT/Cyber Risk, GRC, or Technical Assurance within financial services.
  • Hands-on designing/operating KRIs/KPIs and turning failing metrics green.

Responsibilities

  • Govern, monitor, and improve IT & Cyber risk metrics to align with Cyber Strategy and Group CISO expectations.
  • Lead annual RCSA across technology domains with governance and reporting.
  • Provide strategic inputs to the Technology Risk Forum with posture, trends, and remediation.
  • Deliver automated dashboards and a single source of truth for metric definitions, thresholds, owners, and evidence.
  • Coordinate cross-framework mapping (ISO 27001:2022, NIST CSF 2.0, COBIT, ISO 31000; plus SOX 404, GDPR, DORA, PCI DSS).
  • Liaise with Application, Infrastructure, Service Owners, SOC, IT Ops, Risk, Compliance, and regulators.

Skills

KRIs/KPIs design
RCSA leadership
Stakeholder engagement
Vulnerability governance
IAM/PAM
Cloud security
Regulatory compliance
ServiceNow/Jira
Communication

Tools

ServiceNow
Jira

Job description

This role governs, monitors, and continuously improves IT & Cyber risk metrics so they are

fit for purpose, aligned with Cyber Strategy, and meet expectations set by the Group CISO.

Operating within Banking, Finance, and Hedge Fund environments, the role ensures metrics

reflect financial risk exposure, operational resilience, and compliance with global regulatory

frameworks. The role leads the annual Risk & Control Self-Assessment (RCSA) and provides

strategic inputs to the Technology Risk Forum.

Key Responsibilities:
  • Metrics Governance & Cyber Strategy Alignment: Define, review, and maintain IT & Cyber KRIs/KPIs in line with Cyber Strategy and Group CISO directives; map to risk appetite thresholds and business services.
  • Continuous Improvement & Remediation: Monitor failing metrics; lead root cause analysis and remediation plans. Implement a Metric Rewrite Protocol for metrics that consistently fail or are misaligned.
  • RCSA Execution: Lead annual RCSA across technology domains; ensure residual risk remains within appetite and align methodology with Group CISO expectations.
  • Strategic Reporting & Governance: Provide decision-ready inputs to the Technology Risk Forum: posture, trends, material events, remediation, and asks.
  • Compliance & Regulatory Alignment (Global): Maintain cross-framework control mapping and evidence across ISO/IEC 27001:2022, NIST CSF 2.0, COBIT, ISO 31000; and regulations/obligations including SOX 404, GDPR, DORA (EU), PCI DSS v4.0, and applicable regional rules (e.g., FFIEC/US, UK PRA/FCA, MAS TRM, HKMA, APRA CPS 234).
  • Stakeholder Engagement: Liaise with Application, Infrastructure, Service Owners, SOC, IT Ops, Risk, Compliance, and external auditors/regulators. Influence remediation and strategic risk initiatives.
  • Automation & Reporting: Partner with BI/GRC teams to deliver automated dashboards and single source of truth for metric definitions, thresholds, owners, and evidence.
  • Execute delegated tasks as deemed appropriate by the Group CISO and other empowered Group Cyber leadership authorities, ensuring timely and effective completion in alignment with organizational priorities.
  • Support the Group Cyber Strategy end-to-end, driving alignment of all activities, decisions, and deliverables with strategic objectives and business outcomes.
Candidate Profile:
Experience:
  • 10–15+ years in IT/Cyber Risk, GRC, or Technical Assurance within financial services.
  • Hands-on designing/operating KRIs/KPIs and turning failing metrics green.
  • Led RCSA and audit/regulator engagements across multiple regions.
Skills:
  • Technical: vulnerability and patch governance, IAM/PAM, cloud security, incident 31000), SOX 404, DORA, GDPR, PCI DSS. ticketing (ServiceNow/Jira).
  • Soft Skills: communication, articulation, presentation, stakeholder influence, executive
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Risk Analyst
IT Risk Analyst

Sayyam Investments Private Limited • Bengaluru

On-site
INR 1,200,000 - 2,000,000
IT&Data Risk & CS Manager
IT&Data Risk & CS Manager

Infosys Limited • Telangana

On-site
INR 180,000 - 300,000
Senior Manager – Digital, Cyber Security (GRC)
Senior Manager – Digital, Cyber Security (GRC)

Tata Consumer Products • Bengaluru

On-site
INR 1,500,000 - 1,900,000
Technical Security Manager
Technical Security Manager

Pay10 India • New Delhi

On-site
INR 1,300,000 - 2,100,000
ITandData Risk And CS Manager
ITandData Risk And CS Manager

Infosys • Hyderabad

On-site
INR 1,500,000 - 2,500,000
IT & Cyber_Technical_Risk_Metrics_Specialist_Compliance_Manager
IT & Cyber_Technical_Risk_Metrics_Specialist_Compliance_Manager

CO_AFATI Apex Fund Services LLP • Pune District

On-site
INR 2,500,000 - 6,000,000
Cybersecurity & Compliance Advisor
Cybersecurity & Compliance Advisor

Siemens • Gurugram District

On-site
INR 2,800,000 - 4,200,000
Information Security II-SUPPORT SERVICES-CTO - Support services
Information Security II-SUPPORT SERVICES-CTO - Support services

Kotak Mahindra Bank • Mumbai

On-site
INR 2,500,000 - 4,500,000
Consultant
Consultant

Deloitte Shared Services India • Gurugram District

On-site
INR 1,500,000 - 3,500,000
Cybersecurity & Compliance Advisor
Cybersecurity & Compliance Advisor

Sourceo • Mumbai

On-site
INR 2,000,000 - 3,600,000