Responsibilities
* Define and maintain security governance frameworks, policies, and standards.
* Lead cyber risk assessments and maintain the risk register.
* Manage compliance with standards such as ISO 27001, NIST, SOC 2, and applicable regulations.
* Coordinate internal and external audits and track remediation of findings.
* Oversee third‑party risk management activities.
* Produce executive‑level risk and compliance reporting.
Must Have
* 7–12 years of experience in cybersecurity, with strong GRC exposure.
* Hands‑on experience with risk management and compliance frameworks.
* Strong stakeholder management and communication skills.
Good to Have
* Experience in Railway Domain.
* CISM, CISA, CRISC, CISSP, ISO 27001 Lead Implementer/Auditor Certifications
#J-18808-Ljbffr