Director Risk Operation Center

Grant Thornton INDUS

Kolkata District

On-site

INR 3,000,000 - 5,400,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Grant Thornton INDUS is seeking a senior cyber risk leader to design and run a global Cyber Risk Operations Center, embedding risk management across security, infrastructure, and cloud teams.

You will own risk visibility, run vulnerability programs with Qualys and CrowdStrike, manage third-party risk, and report to executives on trends and risk posture. Requirements include 12+ years in cybersecurity with leadership and Azure expertise, plus familiarity with NIST/ISO frameworks.

Qualifications

  • 12+ years of experience in cybersecurity, infrastructure security, or technology risk.
  • 5+ years in senior leadership roles.
  • Hands-on with enterprise security tools and platforms.
  • Strong understanding of cyber risk frameworks (NIST, ISO, CIS).
  • Ability to translate technical findings into business risk decisions.

Responsibilities

  • Design and stand up a global Cyber Risk Operations Center (ROC) including operating model, workflows, and governance.
  • Define and operationalize a framework for identifying, prioritizing, tracking, and remediating cyber and infrastructure risk.
  • Partner with security architecture, infrastructure, cloud, and application teams to embed risk management into day-to-day operations.
  • Own enterprise technology risk visibility across on-prem, cloud, hybrid, and SaaS environments.
  • Lead risk assessment and exception management processes, including risk acceptance and executive reporting.
  • Drive secure configuration assessment and risk management aligned to CIS, NIST, and Microsoft benchmarks.

Skills

Cybersecurity leadership
Cloud platforms (Azure)
Risk management
Vulnerability management
Identity & access management
Security architecture
Executive communication
Risk governance

Education

CISSP
CISM
CCSP
CRISC

Tools

Qualys
CrowdStrike
Wiz
Azure Security/Defender
Microsoft Entra ID

Job description

Key Responsibilities
Cyber Risk Operations & Strategy
  • Design and stand up a global Cyber Risk Operations Center (ROC), including operating model, workflows, tooling integration, metrics, and governance.
  • Define and operationalize a consistent framework for identifying, prioritizing, tracking, and remediating cyber and infrastructure risk.
  • Partner with security architecture, infrastructure, cloud, and application teams to embed risk management into daytoday Operations.
Technology & Infrastructure Risk Management
  • Own enterprise technology risk visibility across onprem, cloud, hybrid, and SaaS environments.
  • Lead risk assessment and exception management processes, including risk acceptance, compensating controls, and executivelevel risk reporting.
  • Drive secure configuration assessment and risk management aligned to industry standards (CIS, NIST, Microsoft benchmarks, etc.).
Cloud Exposure & Attack Surface Management
  • Oversee cloud security posture, exposure management, and attack path analysis across Azure and multicloud environments.
  • Leverage tools such as Wiz, Azure Security Center / Defender, and related platforms to identify toxic combinations, misconfigurations, and highrisk attack paths.
  • Partner with cloud engineering teams to prioritize remediation based on risk and business impact.
Vulnerability & Endpoint Risk
  • Lead vulnerability management and endpoint exposure programs using tools such as Qualys and CrowdStrike.
  • Ensure riskbased prioritization of vulnerabilities beyond CVSS, incorporating exploitability, asset criticality, and exposure.
Identity & Access Risk
  • Oversee identityrelated risk management, including privileged access, misconfigurations, and conditional access gaps using Microsoft Entra ID and related tooling.
  • Partner with IAM teams to reduce identitydriven attack paths and enforce least privilege at scale.
ThirdParty Risk Management
  • Own the cyber risk aspects of thirdparty and supply chain risk, including technology assessments, ongoing monitoring, and issue remediation.
  • Integrate thirdparty risk insights into enterprise risk reporting and decisionmaking.
Leadership & Stakeholder Engagement
  • Build and lead a highperforming, globally distributed team of cyber risk professionals.
  • Communicate complex technical risk clearly to executives, auditors, and nontechnical stakeholders.
  • Provide regular risk posture updates to senior leadership, including trends and systemic issues.
Qualifications
  • 12+ years of experience in cybersecurity, infrastructure security, or technology risk, with 5+ years in senior leadership roles.
  • Deep technical background in enterprise infrastructure, cloud platforms (especially Azure), identity systems, and security architecture.
  • Handson experience with tools such as Qualys, CrowdStrike, Wiz, Azure Security/Defender, and Microsoft Entra ID.
  • Proven experience building or scaling cyber risk, vulnerability management, or exposure management programs.
  • Strong understanding of cyber risk frameworks (NIST CSF, NIST80053, ISO27001, CIS).
  • Demonstrated ability to translate technical findings into businessrelevant risk decisions.
Preferred Qualifications
  • Experience standing up a centralized risk operations or exposure management function.
  • Background in highly regulated or global enterprise environments.
  • Familiarity with SOC2, cloud compliance, and auditdriven risk management.
Relevant Certifications
  • (CISSP, CISM, CCSP, CRISC, or equivalent) .
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Lead
Cybersecurity Lead

Epergne Solutions • Chennai District

On-site
INR 1,500,000 - 2,500,000
Threat Vulnerability Manager
Threat Vulnerability Manager

Trekrecruit India. • Hyderabad

On-site
INR 3,500,000 - 7,000,000
Project Manager + Cybersecurity
Project Manager + Cybersecurity

Sonata Software • Dadri

On-site
INR 3,000,000 - 5,400,000
Solution Architect
Solution Architect

Jobtailor • Bengaluru

On-site
INR 4,500,000 - 6,500,000
Security Operations Manager
Security Operations Manager

Angel One • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Network & Cloud Cybersecurity Lead
Network & Cloud Cybersecurity Lead

Adani Group • Ahmedabad District

On-site
INR 400,000 - 700,000
Director Cyber Risk Quantification
Director Cyber Risk Quantification

TAC Security • Delhi

On-site
INR 4,000,000 - 7,000,000
Risk Consulting - Digital Risk - Senior - Cloud Professional
Risk Consulting - Digital Risk - Senior - Cloud Professional

EY • Gurugram District

On-site
INR 1,200,000 - 1,800,000
Chief Information Security Officer
Chief Information Security Officer

adani capital pvt ltd • Ahmedabad District

On-site
INR 3,000,000 - 9,000,000
Manager- GRC
Manager- GRC

CyberCube Services • Gurugram District

On-site
INR 1,500,000 - 2,100,000