Skip to main content
Back to Jobs
G
Director

Director - Risk Operation Center

GRANT THORNTON BHARAT LLP·Posted 1 week ago

Location

Bangalore, Kolkata

Experience

15–22 years

Required Skills

Information SecurityCyber SecurityIT SecurityChief Information Security OfficerBusiness ContinuityIT Risk ManagementIT Infrastructure

About the Role

Description:

Role Summary:

We are seeking a Director of Cyber Risk Operations to design, build, and lead a global Cyber Risk Operations Center (ROC). This role will own the continuous identification, assessment, prioritization, and management of technology and infrastructure risk across the enterprise.

The ideal candidate brings deep hands-on technical expertise, strong risk judgment, and the ability to operationalize cyber risk at scaletranslating technical exposures into actionable, business-aligned risk insights. This leader will work closely with infrastructure, cloud, engineering, IAM, compliance, and third-party stakeholders globally.

Key Responsibilities:

Cyber Risk Operations & Strategy

- Design and stand up a global Cyber Risk Operations Center (ROC), including operating model, workflows, tooling integration, metrics, and governance.

- Define and operationalize a consistent framework for identifying, prioritizing, tracking, and remediating cyber and infrastructure risk

- Partner with security architecture, infrastructure, cloud, and application teams to embed risk management into day-to-day Operations.

Technology & Infrastructure Risk Management

- Own enterprise technology risk visibility across on-prem, cloud, hybrid, and SaaS environments.

- Lead risk assessment and exception management processes, including risk acceptance, compensating controls, and executive-level risk reporting.

- Drive secure configuration assessment and risk management aligned to industry standards (CIS, NIST, Microsoft benchmarks, etc.)

Cloud Exposure & A/ack Surface Management

- Oversee cloud security posture, exposure management, and attack path analysis across Azure and multi-cloud environments.

- Leverage tools such as Wiz, Azure Security Center / Defender, and related platforms to identify toxic combinations, misconfigurations, and high-risk attack paths.

- Partner with cloud engineering teams to prioritize remediation based on risk and business impact.

Vulnerability & Endpoint Risk

- Lead vulnerability management and endpoint exposure programs using tools such as Qualys and CrowdStrike.

- Ensure risk-based prioritization of vulnerabilities beyond CVSS, incorporating exploitability, asset criticality, and exposure

Identity & Access Risk

- Oversee identity-related risk management, including privileged access, misconfigurations, and conditional access gaps using Microsoft Entra ID and related tooling.

- Partner with IAM teams to reduce identity-driven attack paths and enforce least privilege at scale

Third-Party Risk Management

- Own the cyber risk aspects of third-party and supply chain risk, including technology assessments, ongoing monitoring, and issue remediation.

- Integrate third-party risk insights into enterprise risk reporting and decision-making.

Leadership & Stakeholder Engagement

- Build and lead a high-performing, globally distributed team of cyber risk professionals.

- Communicate complex technical risk clearly to executives, auditors, and non-technical stakeholders.

- Provide regular risk posture updates to senior leadership, including trends, systemic issues, and material risks.

Skills/Qualification/Experience:

- 12+ years of experience in cybersecurity, infrastructure security, or technology risk, with 5+ years in senior leadership roles.

- Deep technical background in enterprise infrastructure, cloud platforms (especially Azure), identity systems, and security architecture.

- Hands-on experience with tools such as Qualys, CrowdStrike, Wiz, Azure Security/Defender, and Microsoft Entra ID.

- Proven experience building or scaling cyber risk, vulnerability management, or exposure management programs.

- Strong understanding of cyber risk frameworks (NIST CSF, NIST 800-53, ISO 27001, CIS).

- Demonstrated ability to translate technical findings into business-relevant risk decisions

Preferred Qualifications

- Experience standing up a centralized risk operations or exposure management function.

- Background in highly regulated or global enterprise environments.

- Familiarity with SOC 2, cloud compliance, and audit-driven risk management.

Relevant certifications (CISSP, CISM, CCSP, CRISC, or equivalent).


HireIQ AI InsightsBeta

Ideal Candidate

Someone who has scaled a risk or security operations function from concept to production at a large enterprise—ideally having built vulnerability management, cloud security posture, or SOC-adjacent programs.

Estimated Salary Range(medium confidence)

24 L – ₹36 L per year

Likely Interview Questions

  1. 1.Walk us through a Cyber Risk Operations Center or equivalent program you designed end-to-end—what was your operating model, how did you integrate with engineering/cloud teams, and what metrics proved material to leadership?
  2. 🔒 4 more questions locked — unlock with Professional + run a full mock interview

🔒 Strengths to highlight + red flags locked.

Land this role fasterProfessional
🎙️

SAGE

Mock interview coach

Rehearse the 5 most-likely questions for this role with live AI feedback.

📄

SPAR

Resume tailoring

Rewrite your resume to lead with what this hiring panel cares about.

🤝

REACH

Warm intro outreach

Find the hiring manager + 2nd-degree intros and draft the messages.

More Engineering & Technology Roles

View all

90% of leadership roles never appear on job boards

Join HireIQ to access confidential opportunities, AI-powered matching, and direct connections to hiring decision-makers.

Join the Talent Network