31 Jul
|
HCLTech
|
Uttar Pradesh
31 Jul
HCLTech
Uttar Pradesh
Role & responsibilities
Manage end-to-end Compliance, Information Security, and Customer Data Protection programs in an outsourcing setting.
Conduct risk assessments, compliance audits, and gap analyses to identify vulnerabilities and recommend remediation.
Lead development and enforcement of Risk & Compliance programs, procedures, and standards.
Engage with business leadership through regular governance meetings to provide risk insights and ensure remediation plans are agreed upon.
Coordinate with support functions (IT, Physical Security, HR, etc.) for risk mitigation.
Maintain risk registers and R&C; calendars for engagements.
Review and improve security and compliance control frameworks.
Ensure adherence to regulatory and contractual requirements (e.g., ISO 27001, SOC2, SOX, NIST, PCI-DSS, HIPAA).
Preferred candidate profile
Extensive experience in risk management, compliance monitoring, and auditing within IT outsourcing/service delivery.
Solid knowledge of control frameworks for IT and non-IT domains.
Hands-on experience with compliance programs such as ISO 27001, SOC2, SOX, NIST, PCI-DSS, HIPAA.
Proven ability to lead small teams and manage cross-functional stakeholders.
Excellent communication and analytical skills.
Qualifications
10+ relevant years of experience in Information Risk Management / Information Security
Certifications: CISA, CISSP, CISM, CRISC, ISO 27001
Solid communication, analytical, and leadership skills
📌 Manager Arm Uttar Pradesh
🏢 HCLTech
📍 Uttar Pradesh