Associate Director, Cybersecurity & GRC
Department: Cybersecurity & Governance, Risk & Compliance (GRC) Domain
Reports To: Vice President, Business (Operations & Growth) / CEO (as applicable)
Role Type: Full-Time | Leadership
Role Purpose
The Associate Director, Cybersecurity & GRC provides strategic and commercial leadership for Cybersecurity and Governance, Risk & Compliance (GRC) Domain. The role is responsible for driving business growth, leading client engagements, overseeing solution delivery, and developing market-leading cybersecurity, information security, privacy, and governance services.
As the domain leader, the role combines business development, technical leadership, client relationship management, and practice development to position iCentra as a trusted partner for enterprise resilience and regulatory compliance.
Key Responsibilities
1. Business Growth & Practice Development
- Develop and execute the growth strategy for the Cybersecurity & GRC Domain.
- Drive revenue generation through consulting, managed services, training, and certification offerings.
- Build and manage a healthy pipeline of enterprise opportunities.
- Develop strategic relationships with corporate clients, regulators, technology partners, and industry stakeholders.
- Support proposal development, commercial negotiations, and solution positioning.
2. Cybersecurity & GRC Advisory
Lead the delivery of advisory services across areas such as:
- Information Security Management Systems (ISO/IEC 27001)
- Business Continuity Management (ISO 22301)
- IT Governance
- Enterprise Risk Management
- Cybersecurity Governance
- Privacy and Data Protection
- Security Assessments and Gap Analysis
- Security Policies and Framework Development
- Governance Frameworks and Compliance Programs
3. Solution Delivery & Client Success
- Provide leadership and oversight for cybersecurity consulting engagements.
- Ensure projects are delivered on time, within scope, and to quality standards.
- Manage client expectations and executive stakeholder relationships.
- Oversee quality assurance across all domain deliverables.
- Ensure measurable business value is delivered to clients.
4. Product & Service Development
- Develop and enhance cybersecurity consulting offerings.
- Expand managed security and GRC service portfolio.
- Develop new learning and certification programs in collaboration with the Learning & Talent Domain.
- Monitor emerging threats, technologies, and regulatory developments to continuously improve service offerings.
5. Thought Leadership & Market Positioning
- Represent iCentra at conferences, webinars, and executive forums.
- Publish articles, white papers, and industry insights.
- Support brand positioning through thought leadership and technical expertise.
- Build strategic alliances with certification bodies and technology partners.
6. Leadership & Capability Development
- Mentor consultants, associates, and project teams.
- Build a network of subject matter experts and delivery partners.
- Promote knowledge sharing and continuous capability development.
- Foster a culture of innovation, quality, and client excellence.
Requirements
Education
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related discipline.
- Master’s degree (MBA, Information Security, Cybersecurity, or related field) is an advantage.
Professional Certifications
Candidates should possess several of the following certifications:
- ISO/IEC 27001 Lead Implementer and/or Lead Auditor
- ISO 22301 Lead Implementer and/or Lead Auditor
- ISO 31000 Risk Management
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Data Privacy Solutions Engineer (CDPSE)
- Certified Ethical Hacker (CEH) or equivalent (desirable)
- Relevant cloud security certifications (Microsoft, AWS, Google Cloud) are an advantage.
Experience
- Minimum 10–15 years of progressive experience in cybersecurity, information security, governance, risk management, or technology consulting.
- Demonstrated experience leading enterprise cybersecurity and GRC engagements.
- Proven business development and client relationship management experience.
- Experience delivering ISO implementation and certification projects.
- Experience working with executive leadership and large organizations.
Core Competencies
- Cybersecurity strategy and governance
- Enterprise risk management
- Regulatory compliance
- Consulting and advisory
- Business development
- Solution architecture
- Commercial acumen
- Executive stakeholder engagement
- Team leadership and mentoring
- Proposal development and presentation
Personal Attributes
- Strategic thinker with strong commercial orientation.
- High integrity and professional credibility.
- Client-focused and results-driven.
- Strong leadership presence and communication skills.
- Ability to build and grow a consulting practice.
- Passion for continuous learning and innovation.