30 Jul
|
HCLTech
|
Uttar Pradesh
30 Jul
HCLTech
Uttar Pradesh
Role & responsibilities
- Manage end-to-end Compliance, Information Security, and Customer Data Protection programs in an outsourcing environment.
- Conduct risk assessments, compliance audits, and gap analyses to identify vulnerabilities and recommend remediation.
- Lead development and enforcement of Risk & Compliance programs, procedures, and standards.
- Engage with business leadership through regular governance meetings to provide risk insights and ensure remediation plans are agreed upon.
- Coordinate with support functions (IT, Physical Security, HR, etc.) for risk mitigation.
- Maintain risk registers and R&C; calendars for engagements.
- Review and improve security and compliance control frameworks.
- Ensure adherence to regulatory and contractual requirements (e.g., ISO 27001, SOC2, SOX, NIST, PCI-DSS, HIPAA).
Preferred candidate profile
- Extensive experience in risk management, compliance monitoring, and auditing within IT outsourcing/service delivery.
- Strong knowledge of control frameworks for IT and non-IT domains.
- Hands-on experience with compliance programs such as ISO 27001, SOC2, SOX, NIST, PCI-DSS, HIPAA.
- Proven ability to lead small teams and manage cross-functional stakeholders.
- Excellent communication and analytical skills.
Qualifications
- 10+ relevant years of experience in Information Risk Management / Information Security
- Certifications: CISA, CISSP, CISM, CRISC, ISO 27001
- Solid communication, analytical, and leadership skills
📌 Manager - ARM (Uttar Pradesh)
🏢 HCLTech
📍 Uttar Pradesh