Job Title: Cybersecurity Manager
Location: Bengaluru / Hybrid
Department: Information Security
Role Overview
We are seeking an experienced Cybersecurity Manager to lead and mature enterprise security programs across governance, cyber risk management, compliance, cloud security, AI security governance, and certification initiatives.
This role will be responsible for cyber risk management, IT audits, vulnerability governance, certification ownership, and enterprise security programs across key standards including SOC 2 Type II, ISO 27001, PCI-DSS, and HIPAA.
The role will also lead AI risk management and Responsible AI initiatives to ensure secure adoption of emerging technologies.
Key Responsibilities
- Security Strategy & Governance
- Define and execute enterprise cybersecurity strategy aligned to business objectives and regulatory requirements
- Establish security policies, standards, and governance frameworks
- Drive adoption of security frameworks including NIST CSF, ISO 27001, and CIS Controls
- Govern security operations from risk and governance perspective
- Review security incidents, operational risks, trends, and management reporting
- Support incident readiness and post-incident governance activities
- Cyber Risk Management
- Lead enterprise cyber risk management programs including risk identification, assessment, treatment, and reporting
- Maintain risk registers and executive reporting
- Integrate cyber risks across cloud, applications, AI systems, infrastructure, and third parties
- IT Audits & Compliance Ownership
Own enterprise certification and audit programs including:
- SOC 2 Type II
- ISO 27001 / ISO 27701
- PCI-DSS
- HIPAA
Responsibilities include: Responsibilities include IT audits, certification readiness, evidence management, remediation tracking, and client assurance support.
- Vulnerability Governance
- Govern enterprise vulnerability management programs
- Oversee VAPT activities and remediation tracking
- Drive risk-based prioritization and exposure reduction initiatives
- AI Risk Management & Responsible AI
- Define AI security and AI risk management frameworks
- Identify risks related to AI systems including data leakage, model manipulation, privacy, and bias risks
- Drive Responsible AI governance and policy implementation
- Support secure AI lifecycle initiatives
- Security Architecture & Engineering Governance
- Collaborate with IT and engineering teams on secure architecture initiatives
- Promote Zero Trust, identity-first security, and secure SDLC practices
- Vendor Risk Management & Security Awareness
- Conduct vendor risk assessments and third-party reviews
- Support supplier security governance and contractual security requirements
- Lead enterprise awareness programs and phishing initiatives
- Promote organization-wide security culture initiatives
Required Qualifications
- Bachelor’s degree in Cybersecurity / IT / Engineering or related fields
- 8–12+ years cybersecurity experience
- 3–5 years in leadership roles
- Experience in cyber risk, audits, certifications, cloud security, and governance programs
- Experience supporting client assurance and regulatory initiatives
Preferred Certifications
CISSP | CISM | CISA | CRISC | CCSP | ISO 27001 Lead Implementer / Lead Auditor | SC-100 | AZ-500
Key Skills
- Cyber Risk Management
- IT Audit & Compliance (SOC2, ISO, PCI-DSS, HIPAA)
- Vulnerability Governance & VAPT
- Cloud Security Governance
- AI Risk Management & Responsible AI
- Security Governance
- Vendor Risk Management
- Leadership & Stakeholder Management
Note:
By submitting your application, you consent to being contacted by our Talent Acquisition team via phone call, email, SMS, WhatsApp, or other communication channels regarding your application and relevant career opportunities.Skills Required
- Bachelor's degree in Cybersecurity, IT, Engineering, or a related field
- 8-12+ years of cybersecurity experience
- 3-5 years of experience in leadership roles
- Experience in cyber risk management, IT audits, certifications, cloud security, and governance programs
- Experience supporting client assurance and regulatory initiatives
- CISSP certification
- CISM certification
- CISA certification
- CRISC certification
- CCSP certification
- ISO 27001 Lead Implementer or Lead Auditor certification
- SC-100 certification
- AZ-500 certification
What We Do
Sigmoid is a leading data engineering and AI solutions company that helps enterprises gain a competitive advantage with effective data-driven decision-making. Our team is strongly driven by the passion to unravel data complexities. We generate actionable insights and translate them into successful business strategies. We leverage our expertise in open-source and cloud technologies to develop innovative frameworks catering to specific customer needs. Our unique approach has positively influenced the business performance of our Fortune 500 clients across CPG, retail, banking, financial services, manufacturing, and other verticals. Backed by Sequoia Capital, Sigmoid has offices in New York, San Francisco, Dallas, Lima, Amsterdam, and Bengaluru. We are recognized among the world's fastest growing and innovative tech companies, winning several awards and recognition like the Deloitte Technology Fast 500, Financial Times- The Americas’ Fastest Growing Companies, Inc. 5000, Great Place To Work- India’s Best Leaders in Times of Crisis, Data Breakthrough, Aegis Graham Bell, TiE50, NASSCOM Emerge 50, and others. Learn more: https://www.sigmoid.com/ or https://sigmoid.com/careers/ for careers.









