Position: Information Technology Risk Management Consultant Location: Chennai Experience: 8-12 years Education: B. E. / B. Tech. /MCA
Role Overview
Responsible for developing, implementing, and maintaining the organisation s IT Risk Management framework. This role focuses on identifying, assessing, and mitigating risks to protect information assets, ensure regulatory compliance, and enhance overall IT governance. The position requires a deep understanding of risk frameworks, threat modelling, control evaluation, and GRC tools, combined with strong stakeholder management skills.
Job Profile:
Conduct comprehensive risk assessments: identification, impact analysis, heatmap/matrix creation, inherent vs. residual risk scoring, and control gap analysis.
Perform threat modelling and develop detailed risk scenarios for IT infrastructure, applications, and cloud environments.
Align IT risk practices with industry frameworks and standards (ISO 27005/27001, NIST RMF, PCI DSS, DORA).
Evaluate and maintain IT controls and security posture, recommending enhancements where necessary.
Support internal and external IT audit processes, ensuring timely remediation of findings.
Work with GRC teams (ServiceNow GRC, RSA) to track and manage risk compliance workflows.
Prepare and present risk dashboards, KRIs, and management reports to senior leadership.
Desired Skills
Proven experience in IT Risk Management frameworks, threat modelling, and risk scenario planning.
Strong understanding of regulatory requirements and compliance frameworks.
Expertise in GRC platforms (ServiceNow GRC, RSA).
Proficiency in risk scoring methodologies and control gap analysis.
Preferred Certifications
CRISC Certified in Risk and Information Systems Control / CISSP - Certified Information Systems Security Professional (Preferred)
PMI-RMP Project Management Institute Risk Management Professional (Optional)
ISO 27001 / 27005 Risk Manager Certification (Optional)
Job Classification
Industry: IT Services & ConsultingFunctional Area / Department: IT & Information SecurityRole Category: IT SecurityRole: Cyber SecurityEmployement Type: Full time