Cybersecurity Control Gap Validator Lead

Protiviti India

Bengaluru, Delhi, Mumbai

On-site

INR 4,000,000 - 7,000,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Protiviti India seeks an experienced Cybersecurity Control Gap Validator Lead to independently assess and challenge remediation activities, aligning with security requirements and frameworks.

The candidate will validate control gaps, oversee remediation programs, and collaborate across Information Security, Risk, Compliance, Audit and Technology teams.

Qualifications

  • 12+ years of experience in Information Security, Cybersecurity GRC, Technology Risk, IT Audit.
  • Knowledge of ISO 27001, NIST Cybersecurity Framework, ORM and RCSA.
  • Professional certifications preferred: CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer/Auditor.

Responsibilities

  • Lead independent validation of cybersecurity control gaps and remediation activities.
  • Assess control design and operating effectiveness across security domains.
  • Review remediation evidence and challenge control owners where required.
  • Evaluate residual risks, compensating controls, and risk acceptance requests.
  • Conduct control-assurance reviews and validate audit observations closure.
  • Support regulatory, internal audit and compliance initiatives.
  • Drive governance and reporting of remediation programs and control improvements.

Skills

Information Security
Cybersecurity GRC
Technology Risk
IT Audit
Cyber Risk Management
Control Assurance
Audit Remediation

Education

Bachelor's Degree in Computer Science/Information Security or related field

Job description

Cybersecurity Control Gap Validator Lead

Department: Information Security
Location: India (Multiple Locations)
Experience: 12+ Years

Job Summary

We are seeking an experienced Cybersecurity Control Gap Validator Lead to independently assess, validate, and challenge cybersecurity control remediation activities across the organization. The role will be responsible for evaluating control gaps, remediation plans, control effectiveness, risk treatment strategies, and residual risk to ensure alignment with internal security requirements and industry frameworks.

The ideal candidate will have a strong background in Information Security GRC, Technology Risk, IT Audit, Cybersecurity Control Assurance, and Risk Management, preferably within the Banking, Financial Services, Consulting, or Global Capability Center environment.

Key Responsibilities
  • Lead independent validation of cybersecurity control gaps and remediation activities.
  • Assess control design and operating effectiveness across security domains.
  • Review remediation evidence and challenge control owners where required.
  • Evaluate residual risks, compensating controls, and risk acceptance requests.
  • Conduct control-assurance reviews and validate audit observations closure.
  • Support regulatory, internal audit, and compliance initiatives.
  • Perform risk-based assessments against security frameworks and standards.
  • Drive governance and reporting of remediation programs and control improvements.
  • Identify systemic control weaknesses and recommend sustainable remediation strategies.
  • Collaborate with stakeholders across Information Security, Risk, Compliance, Audit, and Technology teams.
Required Skills & Experience
  • 12+ years of experience in:
    • Information Security
    • Cybersecurity GRC
    • Technology Risk
    • IT Audit
    • Cyber Risk Management
    • Control Assurance
    • Audit Remediation
  • Strong experience in:
    • Control Gap Assessment
    • Control Testing & Validation
    • Risk Assessments
    • Audit Issue Management
    • Remediation Validation
    • Security Governance
  • Strong knowledge of:
    • ISO 27001
    • NIST Cybersecurity Framework
    • Risk Management Frameworks
    • Operational Risk Management (ORM)
    • RCSA
    • Regulatory Compliance Requirements
Preferred Qualifications
  • Bachelor's Degree in Computer Science, Information Technology, Information Security, or related field.
  • Professional certifications preferred:
    • CISSP
    • CISM
    • CISA
    • CRISC
    • ISO 27001 Lead Implementer/Auditor
Desired Competencies
  • Excellent stakeholder management and communication skills.
  • Strong analytical and risk-based decision-making ability.
  • Experience managing multiple priorities and cross-functional programs.
  • Ability to challenge remediation plans and provide independent assurance.
  • High level of integrity, professionalism, leadership, and attention to detail.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager- GRC
Manager- GRC

CyberCube Services • Gurugram District

On-site
INR 1,500,000 - 2,100,000
IT Security Compliance and Assurance Manager
IT Security Compliance and Assurance Manager

wk • India

On-site
INR 2,000,000 - 3,600,000
Lead Compliance Specialist
Lead Compliance Specialist

TAC Security • Chandigarh

On-site
INR 2,600,000 - 3,200,000
Security Controls
Security Controls

Deloitte Shared Services India • Hyderabad

On-site
INR 800,000 - 1,100,000
IT Audit
IT Audit

Deloitte Shared Services India • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Cyber Security Deputy Manager
Cyber Security Deputy Manager

Wsne Consulting • Pune District

On-site
INR 1,200,000 - 2,400,000
ISMS-IT Audit Director
ISMS-IT Audit Director

EY • India

On-site
INR 3,500,000 - 6,500,000
Security Control Assessor
Security Control Assessor

IDFC FIRST Bank • Navi Mumbai

On-site
INR 1,200,000 - 1,800,000
Lead Security GRC Analyst
Lead Security GRC Analyst

Providence India • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000