Senior Manager - Cyber Risk, Governance & Managed Services

KrollBengaluru, KarnatakaOn-siteFull-timeStaff, 8–12 yearsListed 1 hour ago

Apply now

About this role

Senior Manager - Cyber Security Strategy, Governance & Managed Security Services is responsible for leading enterprise cyber security strategy, governance, risk management, compliance, data protection, and security operations initiatives. This role provides leadership across consulting engagements, managed security services, risk management programs, and cyber transformation initiatives while helping build and scale offshore managed security capabilities. The individual will partner with executive stakeholders to strengthen cyber resilience, define security roadmaps, establish governance frameworks, and deliver high-quality cyber security services across global clients and enterprise environments.

Day to Day Responsibilities

Cyber Security Strategy & Governance

- Develop and execute enterprise cyber security strategies aligned with business objectives and regulatory requirements
- Establish and mature cyber security governance frameworks, policies, standards, and operating models
- Define security roadmaps, transformation programs, and strategic initiatives to improve organizational security posture
- Engage with executive leadership and business stakeholders to drive cyber risk-informed decision making
- Develop cyber security metrics, KPIs, KRIs, and executive reporting frameworks
- Lead enterprise risk management programs and cyber governance initiatives
- Oversee implementation and maintenance of security control frameworks and compliance programs
- Conduct cyber risk assessments and facilitate risk treatment and remediation activities
- Ensure adherence to industry standards, regulatory requirements, and security frameworks
- Provide governance oversight for audits, regulatory reviews, and compliance assessments
- Lead Risk and Control Self-Assessment (RCSA) programs across business and technology functions
- Establish risk identification, analysis, quantification, and reporting methodologies
- Develop cyber risk registers and oversee remediation tracking activities
- Facilitate risk workshops and control assessment exercises with stakeholders
- Provide strategic recommendations for risk mitigation and control optimization
- Define and implement enterprise data governance and data protection strategies
- Establish data classification, retention, handling, and protection standards
- Lead Data Loss Prevention (DLP) programs across endpoints, cloud platforms, email, and enterprise applications
- Collaborate with legal, compliance, privacy, and business teams to strengthen data security controls
- Ensure data governance programs align with regulatory and organizational requirements
- Provide strategic oversight for enterprise security architecture initiatives
- Review and approve security architecture designs for critical business projects and technology platforms
- Lead threat modeling exercises for applications, cloud environments, and enterprise infrastructure
- Ensure security-by-design principles are incorporated into technology initiatives
- Establish security architecture standards and design review processes
- Provide leadership and governance over incident response and cyber crisis management programs
- Guide investigation and response efforts during major cyber security incidents
- Support development and testing of incident response plans, playbooks, and recovery procedures
- Drive lessons learned activities and continuous improvement initiatives following security incidents
- Coordinate with SOC, IR, legal, compliance, and business stakeholders during cyber events
- Help define, build, and scale offshore managed security service capabilities and operating models
- Develop service offerings, delivery frameworks, governance processes, and operational standards
- Establish service delivery KPIs, staffing models, and resource planning frameworks
- Support business development, solutioning, transition, and service transformation activities
- Drive operational excellence, client satisfaction, and service maturity across managed security programs
- Lead and mentor high-performing cyber security teams across multiple security domains
- Define workforce planning, hiring strategies, skill development, and succession planning initiatives
- Manage resource allocation, utilization, and capacity planning across consulting and managed service engagements
- Foster a culture of innovation, accountability, and continuous learning
- Build strong relationships with clients, executives, and cross-functional leadership teams
- 15+ years of experience in Cyber Security, Information Security, Risk Management, Governance, Consulting, or Managed Security Services
- Strong experience leading Cyber Security Strategy and Transformation programs
- Extensive experience in Governance, Risk, and Compliance (GRC) initiatives
- Proven expertise in Risk and Control Self-Assessment (RCSA) programs and enterprise risk management
- Strong experience driving Data Governance and Data Protection programs
- Hands-on knowledge of Data Loss Prevention (DLP) technologies and control implementation
- Experience leading Threat Modeling and Security Architecture review processes
- Experience overseeing Digital Forensics and Incident Response (DFIR) programs
- Strong understanding of cloud security, enterprise security controls, and modern cyber security practices
- Demonstrated success building, transitioning, and scaling Managed Security Services operations
- Experience working across both consulting and managed services delivery models
- Strong executive stakeholder management and client-facing leadership experience
- Proven ability to develop offshore cyber security delivery capabilities and teams
- Experience managing large-scale transformation programs and global delivery models
- Exposure to AI-enabled cyber security solutions, security automation, cyber analytics, and AI governance frameworks preferred
- Bachelor's degree in Computer Science, Information Technology, Cyber Security, Engineering, or equivalent practical experience
- 15+ years of progressive experience across Cyber Security, Risk Management, Security Consulting, and Managed Security Services
- Proven experience leading large-scale cyber transformation, governance, and security modernization initiatives
- Demonstrated experience building and managing offshore delivery teams and managed service practices
- Strong background in consulting engagements, client advisory services, and executive stakeholder management
- Experience leading enterprise risk assessments, compliance programs, and security governance frameworks
- Deep understanding of regulatory compliance requirements and security control frameworks
- Industry certifications such as CISSP, CISM, CRISC, CGEIT, CCSP, SABSA, or equivalent are highly preferred
- Experience working with global clients and distributed delivery models
- Experience leveraging AI-driven security capabilities, automation platforms, security analytics, and emerging cyber technologies is preferred

Governance, Risk & Compliance (GRC)

Cyber Security Risk Management & RCSA

Data Governance & Data Protection

Security Architecture & Threat Modeling

Digital Forensics & Incident Response (DFIR)

Managed Security Services Leadership

People Leadership & Resource Planning

Essential Traits

Prerequisites

#LI-SP1

#LI-Hybrid