As the Director of Cyber Risk and Controls, you will lead EXL’s Cyber Security, Governance, Risk, and Compliance portfolio, focusing on building, managing, and supporting the organization's risk management capabilities to enhance cyber maturity.
Job Title. Director of Cyber Risk and Controls
Responsibilities
- Leading Cyber Security Risk Management. Lead the effective functioning of the Cyber Security Risk Management function, ensuring continuous improvement of risk management capabilities.
- Risk Management Framework. Establish and maintain an effective IT and OT security risk management framework to identify, measure, mitigate, monitor, and report risks associated with day-to-day business activities.
- Promoting Risk Management Culture. Promote a culture of sound and effective risk management at all levels of the organization through active participation in governance, management frameworks, and employee education.
- Policy Development. Define, develop, and enhance policies, processes, procedures, controls, and governance for integrated security risk management within the organization.
- Risk Assessment and Remediation. Conduct periodic risk assessments using quantitative and qualitative techniques, develop remediation plans, and roadmaps to address identified risks.
- External Environment Awareness. Keep the Cyber Security Risk function updated on developments in the external regulatory environment and evaluate best practices for adoption.
- Enhancing Cyber Maturity. Proactively identify improvement opportunities and drive initiatives to enhance the organization's overall cyber maturity and security posture.
- Stakeholder Management. Provide oversight to Client Business Security, engage with RFI/RFP clients, and participate in operational and technical discussions and presentations.
- Collaboration. Work closely with security operations, data protection, and BCM teams to create and publish risk advisories for executive management.
- Partnership. Partner with functional teams to develop Cyber capabilities/solutions and proof of concepts.
Technical Skills
- IT Security Expertise. Broad technical knowledge and experience with IT security, Zero Trust Architecture, Risk Management, Compliance frameworks, and Cloud computing.
- Hands-on Experience. Experience in contributing to security design and implementing multiple security technologies and capabilities.
- Stakeholder Engagement. Ability to work with stakeholders in identifying, prioritizing, and developing plans and roadmaps for cybersecurity programs.
Process Specific Skills
- Cybersecurity Trends. Knowledge of the latest cybersecurity trends and global industry best practices.
- Domain Expertise. Strong understanding of various cyber security domains including Cyber risk strategy, Third party risk management, Cloud security, Incident Response, etc.
Soft Skills
- Autonomous Operation. Ability to operate independently and deliver quality work products.
- Communication. Effective oral, written, and interpersonal communication skills, including strong presentation skills.
- Influence. Ability to influence and guide both customers and internal stakeholders in business and technical risk mitigation strategies.
- Decision Making. Strong decision-making skills with a risk management mindset.
- Business Acumen. Understanding of business operations in a global, multi-industry, regulated growth environment.
- Leadership. Experience in interacting with senior leaders and managing global teams effectively.
This role demands a seasoned Cyber Security professional with a strong risk management acumen, outstanding stakeholder management skills, and the ability to drive transformational risk and controls programs to mitigate cyber security threats effectively.