Cybersecurity Consultant - GRC (Product)
Job details
Description About the job Join our Team - Your career journey starts here – not just a job, but a future. Our Potential Opportunity INTECH Automation Intelligence is seeking an experienced Cybersecurity Consultant with expertise in Governance, Risk, and Compliance (GRC), Vulnerability Management and Incident Management to join our OT Cybersecurity Product Team . This role is pivotal in delivering and implementing OT Cybersecurity Solutions to ensure the protection of critical industrial infrastructure across industries such as Oil & Gas, Petrochemicals, Utilities, and Manufacturing. The ideal candidate will work closely with portfolio manager, product managers, developers, and security engineers to ensure that security is embedded throughout the projects, product design, development, and testing lifecycle . The consultant will also be responsible for consulting for GRC application, customer focused GRC Consulting, automation, streamlining compliance workflows, and enhancing the security posture of the product. INTECH’s commitment to delivering cutting-edge OT cybersecurity services, including Resident, On-Call, and Remote services, ensures you will be part of transformative projects that safeguard critical infrastructure and enable secure, reliable operations. What You’ll Lead and Deliver
- Security Governance, Risk, and Compliance (GRC)
- Design, implement, and maintain security risk management frameworks aligned with ISO 27001, NIST, ISA 62443, and other industry standards.
- Lead GRC automation efforts to streamline security risk, audit, and compliance processes within the product lifecycle .
- Work with internal and external stakeholders to align product security controls with industry and regulatory requirements.
- Develop policies, procedures, and security documentation for compliance with global security standards.
- Perform assessments and develop roadmaps for assigned clients and product-based work.
- Product Security and Vulnerability Management
- Provide security guidance throughout the product lifecycle, from requirements gathering to deployment .
- Collaborate with development teams to ensure secure software design (SDLC) practices are followed.
- Support and manage automated vulnerability scanning and manual penetration testing of applications and infrastructure.
- Define risk-based security testing strategies to identify vulnerabilities before release.
- Lead incident response planning and threat modeling exercises for new and existing products.
- GRC Automation & Security Testing Tools
- Implement and manage GRC platforms (e.g., Archer, OneTrust, LogicGate, ServiceNow GRC) to track risks, compliance gaps, and audit workflows.
- Configure security testing tools such as Nessus, Qualys, Burp Suite, OWASP ZAP, and others.
- Develop custom security dashboards and reporting mechanisms to provide real-time visibility into vulnerabilities and compliance status.
- Automate compliance and risk reporting to support audits, certifications, and regulatory assessments .
- Collaboration with Development & Engineering Teams
- Work closely with product managers to integrate security requirements into product roadmaps.
- Provide security awareness training for developers and DevOps teams .
- Define secure coding practices and conduct code reviews to detect security flaws.
- Conduct security architecture reviews for new product features and integrations.
- Help teams respond to security incidents, customer security assessments, and compliance requests .
- 10+ years of cybersecurity experience , with a strong background with industrial customers .
- Worked with multiple companies/clients in GRC consulting.
- Experience working in a product development or SaaS company is highly preferred.
- Proven ability to automate security processes and improve compliance workflows.
- Computer sciences, BS or MS in cybersecurity, etc.
- CISSP – Certified Information Systems Security Professional.
- CISM – Certified Information Security Manager.
- CRISC – Certified in Risk and Information Systems Control.
- CEH – Certified Ethical Hacker.
- ISO 27001 Lead Implementer/Auditor.
- Strong knowledge of GRC frameworks (ISO 27001, NIST 800-53, NIST CSF, SOC 2, ISA 62443).
- Experience implementing and managing GRC platforms (e.g., Archer, OneTrust, ServiceNow GRC, LogicGate).
- Expertise in vulnerability management tools (e.g., Tenable Nessus, Qualys, Rapid7, OpenVAS).
- Deep understanding of application security testing (e.g., SAST, DAST, SCA).
- Hands-on experience with security automation .
- Strong documentation and policy-writing skills.
- Strong problem-solving and analytical skills .
- Excellent communication and stakeholder management skills.
- Ability to train and mentor development teams in secure coding practices.
- Experience working in cross-functional teams (Engineering, Compliance, IT, Legal).
- Global Exposure: Opportunities to work on international projects and collaborate with global teams.
- Competitive Compensation: A salary package that recognizes your expertise and contributions.
- Annual Bonus: Performance-driven rewards based on your gross pay to celebrate your achievements and contributions.
- In-House Lunch: Delicious meals provided during work hours to keep you fueled and focused.
- Health Insurance: OPD coverage for you and your parents, plus IPD coverage for you and your dependents.
- Learning Opportunities: Access to training programs, workshops, and certifications to enhance your skills.
- Work-Life Balance: Paid time off, including annual leave and holidays.
- Inclusive Environment: A workplace that celebrates diversity and fosters collaboration.
Apply safely
To stay safe in your job search, information on common scams and to get free expert advice, we recommend that you visit SAFERjobs, a non-profit, joint industry and law enforcement organization working to combat job scams.