HamburgerMenu
hirist

Nexdigm - Assistant Manager - Technology Risk Advisory

Nexdigm
5 - 6 Years
Multiple Locations

Posted on: 03/06/2026

Job Description

JOB DESCRIPTION :

Job Title : Assistant Manager

Location : Pune / Mumbai

Experience : 5 to 6 years

Educational Qualification : Bachelors degree in information technology, Computer Science, Cybersecurity, or a related field

Work Mode : Hybrid

About the department :

Our Cybersecurity team helps businesses safeguard digital assets by identifying vulnerabilities, mitigating threats, and ensuring regulatory compliance. The practice works across cloud, infrastructure, applications, and networks to build resilient and secure environments.

Whats in it for you?

In a world where cyber threats evolve faster than ever, organizations need more than just defense they need proactive, intelligent security strategies. At Nexdigm, our Cybersecurity practice enables clients to transform their risk posture, build digital trust, and safeguard their critical assets.

We are looking for Assistant Managers and Deputy Managers to strengthen our delivery and leadership bench. This role offers a unique opportunity to work across industries, lead project streams, and grow into a trusted cybersecurity advisor within a fast-paced consulting environment.

Role Description :

The Assistant Manager Technology Risk Advisory will lead and manage multiple cybersecurity risk assessments, vulnerability management, and IT governance engagements. The ideal candidate will have a strong background in cybersecurity, VAPT, and ITGRC frameworks and proven experience in managing client relationships, leading project teams, and delivering high-quality advisory services. You will also be responsible for helping clients strengthen their cybersecurity posture while adhering to industry regulations and standards

- Demonstrated expertise in conducting Vulnerability Assessments and Penetration Testing (VAPT) across various systems, applications, and networks.

- Deep understanding of IT Governance, Risk, and Compliance (ITGRC) frameworks such as ISO 27001, COBIT, NIST, GDPR, and PCI DSS.

- Experience with ethical hacking techniques, exploitation of vulnerabilities, and knowledge of industry-standard tools such as Nessus, Metasploit, Burp Suite, etc.

- Solid experience in IT Audits, controls assessments, and creating security remediation plans.

- Strong project management skills, including planning, execution, resource management, and meeting project deadlines.

- Excellent communication skills, with the ability to present complex technical findings to business stakeholders and senior executives.

- Strong analytical and problem-solving abilities, with a keen eye for detail

- Certifications include CISSP, CISM, CEH, CISA, CRISC, or ISO 27001 Lead Auditor/Implementer.

- Experience with Cloud Security, Dev SecOps, and advanced cybersecurity technologies.

- Familiarity with data protection laws and regulations such as GDPR, HIPAA, SOX, etc.

- Prior experience working in a Big Four firm or large-scale advisory firm

- Experience providing Virtual Chief Information Security Officer (vCISO) services, including cybersecurity strategy development, security governance, risk management, board-level reporting, and security program oversight.

- Conducted enterprise-wide cybsersecurity assessments, cyber maturity assessments, security posture reviews, gap assessments, and risk-based evaluations aligned with industry frameworks and regulatory requirements.

- Exposure to Reserve Bank of India (RBI) cybersecurity guidelines, Digital Lending Guidelines, IT Governance Directions, Cyber Security Frameworks, Outsourcing Guidelines, and regulatory compliance requirements applicable to banks, NBFCs, and financial institutions.

- Experience in designing, implementing, and integrating Security Operations Center (SOC) technology stacks, including SIEM, SOAR, Threat Intelligence Platforms (TIP), EDR/XDR, UEBA, and log management solutions.

- Hands-on experience in integrating and onboarding log sources from applications, databases, operating systems, cloud platforms, network devices, firewalls, security appliances, and third-party systems into SIEM platforms.

- Experience in Security Operations (SecOps) analytics, use case development, correlation rule creation, threat detection engineering, security monitoring, and alert optimization.

- Expertise in developing and implementing SOC use cases, detection logic, dashboards, reporting frameworks, and Key Risk Indicators (KRIs) to enhance threat visibility and incident response effectiveness.

- Experience in creating, testing, and optimizing incident response playbooks, automation workflows, and orchestration processes using SOAR platforms and security automation technologies.

- Knowledge of cyber threat intelligence, threat hunting methodologies, MITRE ATT&CK framework mapping, and adversary simulation techniques.

- Experience conducting security architecture reviews and recommending improvements for enterprise security controls, monitoring capabilities, and operational resilience.

- Ability to support clients in developing cybersecurity roadmaps, governance frameworks, risk management programs, and regulatory compliance initiatives.

- Experience collaborating with cross-functional teams including IT, Security Operations, Risk Management, Compliance, Internal Audit, and Business stakeholders to strengthen organizational cybersecurity posture.

- Ability to lead cybersecurity consulting engagements, manage client relationships, and deliver strategic advisory services across cybersecurity, governance, risk, compliance, and security operations domains.

1. Cybersecurity Engagement Execution : Independently manage and execute cybersecurity assessments (e.g., IT risk assessments, vulnerability assessments, cloud security reviews, policy audits) for at least 3 clients per quarter. 95% on-time delivery; <10% rework from internal QA or client reviews.

2. Technical Documentation & Reporting : Prepare high-quality technical deliverables such as risk reports, control gap analyses, and remediation plans aligned with frameworks like ISO 27001, NIST, or RBI/SEBI guidelines. >90% of deliverables accepted in first client/internal review; no major revisions flagged during quality checks.

3. Client Interaction & Stakeholder Coordination : Serve as the point of contact for day-to-day client interactions, including scheduling, status updates, and clarifications. Positive feedback from clients; 2 communication escalations per quarter.

4. People Development & Team Support : Provide guidance and task-level supervision to junior team members (analysts/trainees) and contribute to internal knowledge-sharing sessions. Minimum 2 internal sessions conducted; peer feedback rating 4/5.

5. Continuous Learning & Compliance Readiness : Stay current with cybersecurity trends, frameworks, and regulatory changes; complete required certifications or learning modules. Completion of at least 1 industry-recognized certification (e.g., ISO 27001 LA, CompTIA Security+, CISA/CISM) or firm-mandated training per year.

Required Competencies, Skills, and Experience :

- Advanced Security Operations

- SIEM & Threat Hunting

- Vulnerability & Patch Management

- Penetration Testing & Red Teaming

- Cloud Security Management

- Identity and Access Management

- Risk & Compliance Management

- Security Frameworks & Standards

- Network & Application Security

- Cryptography & Data Protection

- Business Continuity & Disaster Recovery

Hiring Process :

Your interaction with us will include, but not be limited to :

- Technical / HR Interviews

- Assessment

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...