- Company Name
- EY
- Job Title
- Manager or Senior Manager - Cybersecurity Strategy and Governance - Industries
- Job Description
-
**Job Title**
Manager or Senior Manager – Cybersecurity Strategy & Governance (Industries)
**Role Summary**
Lead and deliver client engagements focused on cybersecurity strategy, governance, and resilience. Design and strengthen security programs that align with business objectives, regulatory requirements, and long‑term resilience. Act as subject‑matter expert, mentor team members, and identify business opportunities to grow the practice.
**Expectations**
- Deliver high‑quality, client‑centric services that improve security posture and risk management.
- Demonstrate expertise in cybersecurity frameworks, maturity assessment, and improvement road‑mapping.
- Lead or support internal teams, act in interim governance roles (CISO, CSO), and collaborate cross‑functionally.
- Proactively uncover and pursue new engagement opportunities and commercial growth.
**Key Responsibilities**
1. **Client Strategy & Governance** – Analyze risk exposure, develop tailored cybersecurity strategies, and evaluate maturity of existing programs.
2. **Road‑mapping & Implementation** – Build prioritized road‑maps for investments, change initiatives, and validate security improvements.
3. **Framework & Policy Development** – Define and implement ISO 27001/27003, NIST, COBIT, OWASP, and other relevant frameworks; create policies, standards, and procedures.
4. **Team Leadership & Intermediary Roles** – Lead engagement teams, provide interim governance leadership (CISO, CSO, etc.), and mentor junior staff.
5. **Stakeholder Management** – Communicate progress, risks, and outcomes to clients and internal stakeholders; maintain executive relationships.
6. **Business Development** – Identify and pursue new service opportunities, support go‑to‑market strategy, and contribute to revenue growth.
7. **Continuous Improvement** – Stay current on industry trends, emerging threats, and regulatory changes; incorporate insights into engagements.
**Required Skills**
- Deep knowledge of cybersecurity strategy, governance, and resilience.
- Proficiency with ISO 2700x, NIST, COBIT, SABSA, OWASP, GAPP, and related frameworks.
- Experience conducting maturity assessments, risk analyses, and roadmap development.
- Strong project delivery skills: scoping, planning, monitoring, and stakeholder communication.
- Leadership abilities: team management, mentorship, and executive liaison.
- Analytical mindset focused on quality, results, and continuous improvement.
- Excellent written and verbal communication for IT and business audiences.
**Required Education & Certifications**
- Bachelor’s or Master’s degree in Information Technology, Information Security, Cybersecurity, or related field.
- Professional certifications such as CISSP, ISO 27001 Lead Implementer, CISM, CRISC, CISA, or COBIT.
- Active membership in industry organisations (ISACA, ISF, L‑SEC, etc.) is an asset.
---