STStack Digital
Information Security Risk Specialist
Kolkata ₹7-9 LPA Posted 18 Jun 2025
FULL TIME
Iso 27001
Vulnerability Management
Incident Response
Risk Assessment
nist
Job Description
- Develop, implement, and maintain an enterprise-wide information security risk management program.
- Identify, assess, and document information security risks, ensuring alignment with business objectives.
- Perform risk assessments, vulnerability analyses, and impact evaluations on IT systems and processes.
- Collaborate with cross-functional teams to establish risk mitigation strategies and action plans.
- Monitor, track, and report on risk metrics and key performance indicators (KPIs).
- Stay updated on regulatory requirements and ensure compliance with standards such as ISO 27001, NIST, GDPR, etc.
- Develop and maintain comprehensive process documentation and generate reports tailored to the needs of various stakeholders.
- Drive security awareness programs and train employees on risk management practices.
- Prepare and present detailed risk assessment reports to senior management.
- Lead incident response planning and participate in cybersecurity investigations when necessary.
- Qualifications:
- Education:
- Bachelor s degree in Information Security, Cyber Security, Computer Science, Information Science, or a related field.
- Advanced degrees (e.g., Master s) or certifications (e.g., CISSP, CRISC, CISM, CEH) are a plus.
- Experience:
- 5+ years of experience in information security, risk management, or related domains.
- Skills and Competencies:
- Comprehensive understanding of frameworks such as ISO 27001, NIST Cybersecurity Framework, COSO, and COBIT.
- Proven analytical expertise in evaluating and prioritizing risks effectively.
- Advanced proficiency in utilizing security tools for risk assessment and mitigation.
- Strong preference for candidates with certifications like CISSP, CISM, CRISC, or equivalent.
- Exceptional communication and presentation skills, with a proven ability to collaborate effectively across diverse teams.
- Demonstrated problem-solving capabilities, including critical thinking and informed decision-making under pressure.
- Skilled in leading security initiatives and managing projects across global teams.
- A strategic mindset paired with keen attention to detail.
- Resourceful and decisive under high-pressure situations.
- An effective team player with exceptional interpersonal and collaboration skills.