Full-Time

Associate Director

Risk Consulting

Updated on 9/12/2026

Marsh & McLennan

Marsh & McLennan

Risk, insurance and business consulting

No salary listed

Pune, Maharashtra, India

Hybrid

At least three days per week in the local office or onsite with clients; travel may be required within India, the Middle East, Africa, and globally or regionally.

Bachelor's

Category
Consulting (1)
Required Skills
Incident Response
Computer Networking
Word/Pages/Docs
Cybersecurity
Vulnerability Analysis
Penetration Testing
Excel/Numbers/Sheets
Requirements
  • The candidate must have 10 to 15 years of professional experience in cybersecurity consulting in Big Four or boutique firms.
  • At least one professional operational technology cybersecurity certification, such as ISA/IEC 62443, EXIDA CACS, GICSP, ISO 27001, or Security+, is mandatory.
  • The candidate must have expertise in operational technology security principles and controls, including hands-on experience conducting operational technology cyber risk assessments, designing cybersecurity frameworks, implementing controls, performing audits, managing vendor risk, and delivering user awareness training.
  • The candidate must understand cybersecurity standards and regulations such as ISA/IEC 62443, NIST 800-82, and ISO 27001.
  • The candidate must understand industrial automation control systems such as programmable logic controllers, human-machine interfaces, distributed control systems, and supervisory control and data acquisition systems, as well as operational technology networking technologies.
  • The candidate must understand network security control devices and systems such as firewalls, intrusion detection systems, and intrusion prevention systems.
  • The candidate must understand the Open Systems Interconnection model and various operational technology protocols.
  • The candidate must understand operational technology incident response plans and business continuity plans.
  • The candidate must be able to develop quality reports, presentations, and project trackers.
  • The candidate must be proficient in Microsoft Office applications, including Word, PowerPoint, and Excel, and have basic knowledge of Project, Teams, and Visio.
  • The candidate must communicate effectively with clients and stakeholders and explain technical matters to non-technical audiences.
  • The candidate must have strong analytical and problem-solving skills.
  • The candidate must be able to make decisions under ambiguity, prioritize competing assignments, escalate issues, and formulate solutions.
  • The candidate must have effective organizational skills, attention to detail, and the ability to deliver high-quality documentation and influence or implement change.
  • The candidate must demonstrate strong business ethics and principles.
  • The candidate must have a graduate degree in Electronics, Computer Science, Cybersecurity, or a related field.
  • The candidate must have excellent verbal and written English language skills.
  • The candidate must be able to travel globally or regionally as needed.
Responsibilities
  • Collaborate with Cyber Risk Consulting practice leaders globally to deliver the practice’s value proposition across regions.
  • Support the delivery of client deliverables according to the agreed scope of work and provide an efficient delivery model for the Cyber Risk Consulting practice.
  • Lead the delivery of multiple Cyber Risk Consulting projects.
  • Review junior colleagues’ work and train them to ensure deliverables meet the expected quality framework.
  • Support the Global Operational Technology Cybersecurity practice through hands-on delivery of consulting projects and mentoring junior colleagues.
  • Prepare deliverables for the cyber consulting practice under the guidance of the Cyber Risk Consulting practice.
  • Research clients’ cybersecurity risk areas and prepare consulting points of view.
  • Support continuous innovation of the cybersecurity approach and go-to-market strategy.
  • Learn and explain Cyber Risk Consulting practices, procedures, and policies to non-technical clients and colleagues.
  • Contribute research to build robust Cyber Risk Consulting practice deliverables.
  • Maintain key project track records and detailed process documentation.
  • Deliver projects remotely or onsite according to client requirements.
  • Build proposals and pitch to potential clients, including developing presentations and communicating the Cyber Risk Consulting practice’s value proposition.
Desired Qualifications
  • Experience configuring operational technology cybersecurity solutions such as Dragos and Claroty.
  • Experience conducting internal or external information technology audits.
  • Knowledge of technical assessments such as vulnerability assessment and penetration testing, web application penetration testing, and configuration reviews.
  • Experience developing cybersecurity strategies.
  • Experience with Microsoft Visio and Microsoft Project.
  • Fluency in additional foreign languages.

Marsh, formerly Marsh McLennan, is a global professional services firm focused on risk, insurance, reinsurance, talent and business strategy. Its operating businesses help organizations arrange coverage, model and transfer risk, design workforce programs and address complex management questions. Clients range from growing companies to governments and multinational enterprises. The group combines advisory expertise with insurance-market access and data, making it broader than an insurance broker alone while remaining primarily a business-to-business services organization.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A