Verified today
Manager – Information Security Governance
About the role
As a Manager – Information Security Governance within Cognizant Corporate's Extended CISO Tower (Cybersecurity Architecture & Risk practice), you will own the operational health of Cognizant's ISO/IEC 27001 ISMS and serve as ISO/IEC 42001 Lead Auditor for the AI Management System, while consolidating Key Monthly Operations Metrics across CAR teams into leadership-ready reporting. Day-to-day, you will maintain the Statement of Applicability, Risk Treatment Plans, policies and control documentation; plan and execute internal and external audits; coordinate remediation across Enterprise Architecture, IT and business stakeholders; and build Power BI/Tableau dashboards and GRC-based tracking for KPIs, KRIs and SLA data. This is a hybrid role based in Chennai, Tamil Nadu, India, requiring 2 days a week in a Cognizant office in Chennai.
What you’ll do
- Own the day-to-day operation of Cognizant's ISO/IEC 27001 ISMS – maintaining the Statement of Applicability, Risk Treatment Plans, policies and control documentation.
- Plan and execute the internal audit program, and coordinate external certification and surveillance audits, ensuring non-conformities and corrective actions (NC/CAPA) are tracked to verified closure.
- Serve as ISO/IEC 42001 Lead Auditor for Cognizant's AI Management System (AIMS) – planning and conducting audits against Annex A controls (data governance, human oversight, AI impact assessment, trans
- Act as the central coordination point across CAR sub-teams, Enterprise Architects, IT, Compliance and business stakeholders, driving open items, validations and remediation actions to closure.
- Maintain strong working knowledge of Cognizant's information security processes, policies and control framework, ensuring day-to-day CAR activities stay aligned to them.
- Own Key Monthly Operations Metrics – defining, tracking and consolidating KPIs, KRIs and SLA/turnaround-time data across CAR teams into a single, consistent reporting cadence.
- Partner with CAR team leads to collect, validate and normalize metrics (validation volumes, findings/remediation aging, audit closure rates) across platform, application and vendor go-live validations
- Prepare and present monthly and quarterly leadership decks and dashboards, translating operational metrics into clear trends, risk narratives and business impact for the CISO Tower and senior stakehol
What you’ll bring
- 9-12 years of experience in information security governance, risk & compliance, including hands-on ISO/IEC 27001 ISMS management.
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity or a related field.
- ISO/IEC 27001 Lead Auditor or Lead Implementer certification.
- ISO/IEC 42001 (AI Management System) Lead Auditor certification, or equivalent AIMS audit experience.
- Strong working knowledge of enterprise information security processes, controls and validation practices.
- Proven experience defining and consolidating security metrics, KPIs and KRIs, with hands-on dashboarding/reporting (Power BI, Tableau or similar).
- Excellent stakeholder coordination, communication and project-management skills, with the ability to drive closure across multiple teams.
- Strong sense of ownership, desire to create meaningful outcomes, and passion for work that serves a greater good.
Nice to have
- CISA or CISM certification.
- Experience with GRC platforms (ServiceNow GRC, MetricStream) for metrics tracking and reporting.
- Working knowledge of India's DPDP Act (2023 / 2025 Rules) and CERT-In directions.
- ISO/IEC 27701 or ITIL certification.
- Experience preparing leadership-visibility dashboards consolidating metrics across multiple teams.
- Exposure to AI governance concepts (NIST AI RMF) supporting the AIMS audit function.
Skills
Education
Bachelor's degree in Computer Science, Information Technology, Cybersecurity or a related field.