Skip to content
All open roles

Cyber security

Internal Risk

HyderabadHybridFull TimeMidPosted 17 Sept 2026

About the role

At least 5 years of experience executing key risk management activities, including conducting risk assessments using various quantitative and qualitative methodologies, such as the FAIR model (Factor Analysis of Information Risk), ensuring a deep understanding of risk analysis methodologies. At least 3 years of active participation in the design and implementation of at least 2 comprehensive risk management programs (e.g., risk assessments, regulatory assessments) within a large, complex organization, including hands-on experience with program execution and improvement. Practical experience with risk identification, analysis, evaluation, treatment, acceptance or escalation, monitoring, reporting, and reassessment. Proven expertise in process design and improvement related to risk management frameworks and methodologies, ensuring effective risk mitigation strategies are incorporated into operational processes. Experience conducting NIST risk assessments (e.g., NIST CSF, NIST 800-53) and applying their standards and recommendations to improve organizational cybersecurity postures. Strong knowledge of regulatory changes and trends impacting IT risk assessments, including compliance requirements such as GDPR, HIPAA, and others, ensuring risk management strategies align with the latest regulatory standards. Knowledge of Operational Technology (OT) risk management is a plus, with the ability to assess risks related to OT environments and integrate them into overall IT risk strategies. Minimum 3 years of experience evaluating technical design documents for systems or environments to assess associated risks, including reviewing architectural, infrastructure, and application designs for security and operational risk vulnerabilities. Experience maintaining risk registers and managing remediation, issues, exceptions, risk acceptance, and treatment plans.  

Responsibilities

  • Leads internal cybersecurity risk assessments from intake and scoping through analysis, treatment, acceptance or escalation, monitoring, reassessment, and closure.
  • Identifies and documents risk scenarios involving assets, business processes, data, systems, services, suppliers, threats, vulnerabilities, control weaknesses, dependencies, and potential consequences.
  • Evaluates inherent and residual risk using defensible qualitative, semi-quantitative, and quantitative methods, including FAIR or comparable cyber-risk quantification when appropriate.
  • Reviews security architecture, data flows, system descriptions, technical designs, control narratives, audit reports, penetration-test results, vulnerability information, incident history, and third-party assurance evidence.
  • Assesses security control design and operating effectiveness across identity and access management, vulnerability management, secure configuration, logging and monitoring, encryption, backup and recovery, software development, cloud security, data protection, incident response, and resilience.
  • Maintains accurate, complete, and audit-ready risk records, including risk statements, evidence, scoring rationale, control mappings, treatment plans, accountable owners, milestones, decisions, and next-review dates.
  • Facilitates risk-owner decisions, documents exceptions and compensating controls, and escalates material, high, critical, systemic, or aggregating risks through the GRC governance process.
  • Creates and tracks Risk Treatments/Issues and remediation tasks and coordinates related intake, vulnerability, asset, incident, and issue data across enterprise systems.
  • Monitors changes in threats, vulnerabilities, incidents, control performance, technology, business context, M&A activity, and regulatory requirements that may trigger reassessment.
  • Develops risk metrics and reporting for risk owners, GRC leadership, executive stakeholders, governance forums, auditors, and regulators.
  • Applies NIST CSF 2.0, NIST RMF, NIST SP 800-30, ISO/IEC 27005, ISO 31000, FAIR, COBIT, COSO ERM, and comparable methods to support risk-based decision-making.
  • Improves GRC processes through standardized processes, reusable evidence, control mappings, automation, workflow design, integrations, data-quality practices, and continuous improvement.
  • Collaborate with teams across various departments, including IT, legal, compliance, and product security, to identify, assess, and mitigate cybersecurity risks across a broad range of products and services, ensuring security is integrated throughout the entire product lifecycle and operational processes.

Requirements

  • Leads internal cybersecurity risk assessments from intake and scoping through analysis, treatment, acceptance or escalation, monitoring, reassessment, and closure.
  • Identifies and documents risk scenarios involving assets, business processes, data, systems, services, suppliers, threats, vulnerabilities, control weaknesses, dependencies, and potential consequences.
  • Evaluates inherent and residual risk using defensible qualitative, semi-quantitative, and quantitative methods, including FAIR or comparable cyber-risk quantification when appropriate.
  • Reviews security architecture, data flows, system descriptions, technical designs, control narratives, audit reports, penetration-test results, vulnerability information, incident history, and third-party assurance evidence.
  • Assesses security control design and operating effectiveness across identity and access management, vulnerability management, secure configuration, logging and monitoring, encryption, backup and recovery, software development, cloud security, data protection, incident response, and resilience.
  • Maintains accurate, complete, and audit-ready risk records, including risk statements, evidence, scoring rationale, control mappings, treatment plans, accountable owners, milestones, decisions, and next-review dates.
  • Facilitates risk-owner decisions, documents exceptions and compensating controls, and escalates material, high, critical, systemic, or aggregating risks through the GRC governance process.
  • Creates and tracks Risk Treatments/Issues and remediation tasks and coordinates related intake, vulnerability, asset, incident, and issue data across enterprise systems.
  • Monitors changes in threats, vulnerabilities, incidents, control performance, technology, business context, M&A activity, and regulatory requirements that may trigger reassessment.
  • Develops risk metrics and reporting for risk owners, GRC leadership, executive stakeholders, governance forums, auditors, and regulators.
  • Applies NIST CSF 2.0, NIST RMF, NIST SP 800-30, ISO/IEC 27005, ISO 31000, FAIR, COBIT, COSO ERM, and comparable methods to support risk-based decision-making.
  • Improves GRC processes through standardized processes, reusable evidence, control mappings, automation, workflow design, integrations, data-quality practices, and continuous improvement.
  • Collaborate with teams across various departments, including IT, legal, compliance, and product security, to identify, assess, and mitigate cybersecurity risks across a broad range of products and services, ensuring security is integrated throughout the entire product lifecycle and operational processes.