Bestkaam Logo
PwC India Logo

Risk Manager

Actively Reviewing the Applications

PwC India

India, Maharashtra, Mumbai Full-Time
Posted 6 days ago Apply by July 2, 2026

Job Description

Cyber risk assessments

Grade: Associate, Senior Associate, Manager

Experience: 3 – 10 years

  • Role Overview: Conduct end-to-end cyber risk assessments across applications, infrastructure, cloud, third parties, and business processes, translating technical risks into business impact and actionable recommendations.
  • Experience: Minimum 3 years of hands-on experience in cyber/information security with a focus on risk assessments, security controls evaluation, and risk treatment planning in medium-to-large organizations.
  • Frameworks & Standards: Strong working knowledge of risk and security frameworks such as NIST CSF/800-53, ISO 27001/27005, CIS Controls, and familiarity with regulatory and compliance requirements (e.g., GDPR, PCI-DSS, SOX, HIPAA as applicable).
  • Risk Methodology & Tools: Proven ability to perform qualitative and quantitative risk assessments, threat and vulnerability analysis, and use of GRC or risk tools (e.g., Archer, ServiceNow GRC, OneTrust, MetricStream) to document risks, controls, and remediation plans.
  • Technical Security Knowledge: Solid understanding of network security, endpoint security, identity and access management, cloud security (AWS/Azure/GCP), and application security concepts to effectively challenge technical stakeholders and validate control effectiveness.
  • Certifications (Required/Preferred): Relevant certifications such as CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer/Lead Auditor, or equivalent; additional cloud security certs (e.g., CCSP, AWS Security Specialty, Azure Security Engineer) are highly desirable.
  • Communication & Stakeholder Management: Strong ability to communicate complex security and risk topics in clear business terms to technical and non-technical stakeholders, produce high-quality risk reports, and present findings to senior management.
  • Risk Governance & Reporting: Experience contributing to risk registers, key risk indicators (KRIs), risk dashboards, and supporting risk committees or governance forums with structured, data-driven insights.


Check Qualification

Quick Tip

Customize your resume and cover letter to highlight relevant skills for this position to increase your chances of getting hired.