Verified today
Cybersecurity Control Testing & CRI Maturity Assessor
About the role
CISO of America’s team within MUFG Cybersecurity GRC, responsible for independent control testing, CRI Profile maturity assessments and third‑party cybersecurity evaluations. The manager plans and executes control testing across on‑prem and cloud environments, validates SDLC security controls, and documents findings and remediation. Bengaluru, India office, on-site work model.
What you’ll do
- Plan and scope control testing engagements for on‑prem and cloud environments
- Execute evidence‑based control testing across identity, network, endpoint, data protection, logging, vulnerability management and configuration controls
- Perform CRI Profile maturity assessments and document gaps
- Conduct third‑party vendor cybersecurity assessments and risk rating
- Validate security controls embedded in the SDLC pipeline
- Produce detailed workpapers, test scripts and assessment reports
- Re‑test remediated controls to confirm remediation effectiveness
- Communicate findings and remediation actions to stakeholders
What you’ll bring
- 8-12 years risk management or IT audit experience
- Professional certifications (CISSP, CISM, CRISC, CISA, CGEIT, CCSK/CCAK)
- Knowledge of banking/financial regulations (FFIEC, OCC, GDPR, etc.)
- Experience with on‑prem and cloud security controls
- Third‑party cyber risk assessment experience
- CRI Profile maturity assessment expertise
- SDLC security control validation (SAST/DAST, CI/CD, change management)
- Bachelor’s degree in Information Security, Computer Science or related field
Skills
Education
Bachelor’s degree in Information Security, Computer Science, Information Systems or related discipline