IT&Data Risk & CS Manager
Infosys
- Cyber Risk Governance
- Maintain and execute the Cyber Risk Management Framework and associated governance processes.
- Manage and maintain the cyber risk register, ensuring risks are documented, assessed, and regularly reviewed.
- Support risk governance committees and cybersecurity steering forums.
- Ensure cyber risks are aligned with Enterprise Risk Management (ERM) standards and methodologies.
- Risk Assessment & Monitoring
- Conduct cyber risk assessments for applications, infrastructure, cloud platforms, projects, and third-party services.
- Evaluate emerging threats, vulnerabilities, and risk exposures impacting business operations. Track risk treatment plans and ensure timely remediation of identified risks.
- Control Assurance & Compliance
- Manage security risk exceptions and compensating control assessments.
- Ensure alignment with cybersecurity frameworks, standards, and regulations (e.g., ISO 27001, NIST CSF, CIS Controls, GDPR, DORA, NIS2).
- Reporting & Stakeholder Management
- Prepare regular cyber risk reports and dashboards for management and leadership teams.
- Present cyber risk exposure, remediation progress, and risk trends to stakeholders.
- Collaborate with Security Operations, Infrastructure, Application, Data, and Business teams to drive risk reduction initiatives.
- Act as a trusted advisor on cyber risk-related matters for business and technology stakeholders.
- Functional & Technical Skills[RN2.1][SK2.2]
- Cyber Risk Management and Risk Assessment methodologies.
- Strong understanding of Information Security and Cybersecurity principles.
- Knowledge of Governance, Risk, and Compliance (GRC) processes.
- Experience with cybersecurity frameworks and standards (ISO 27001, NIST, CIS Controls).
- Basic understanding of cloud security, infrastructure security, application security, and data protection concepts.
- Experience in preparing and advising business on different mitigation strategies that would best fit the situation
- Experience managing risk registers, KRIs, KPIs, and remediation tracking.
- Strong reporting, dashboarding, and analytical skills. Behavioral Competencies
- Strong stakeholder management and influencing skills.
- Flexibility and ability to adjust approach, frameworks and controls to specific business cases and risks
- Excellent communication and presentation capabilities.
- Analytical and problem-solving mindset.
- Ability to prioritize and manage multiple risks and initiatives.
- Collaboration and teamwork across global and multicultural environments.
- High attention to detail and governance discipline. Good to Have
- Functional & Technical Skills
- Experience with NIS2, GDPR, and other regulatory frameworks.
- Knowledge of Third-Party Risk Management (TPRM).
- Experience with cybersecurity risk management tools and GRC platforms (e.g., ServiceNow GRC, Archer).
- Understanding of Security Operations, Vulnerability Management, and Incident Response processes.
- Data analytics and reporting automation capabilities (Power BI, Tableau, Excel advanced analytics).