02 Aug
|
Copeland Supply
|
Pune
02 Aug
Copeland Supply
Pune
About Us We are a global climate technologies company engineered for sustainability. We create sustainable and efficient residential, commercial and industrial spaces through HVACR technologies. We protect temperature-sensitive goods throughout the cold chain.
And we bring comfort to people globally. Best-in-class engineering, design and manufacturing combined with category-leading brands in compression, controls, software and monitoring solutions result in next-generation climate technology that is built for the needs of the world ahead. Whether you are a professional looking for a career change, an undergraduate student exploring your first opportunity, or recent graduate with an advanced degree, we have opportunities that will allow you to innovate, be challenged and make an impact.
Join our team and start your journey today!
Position Summary The Risk Management & Compliance Lead is responsible for leading Copeland cybersecurity risk management and compliance programs. This role drives the identification, assessment, treatment, and monitoring of cybersecurity risks while ensuring alignment with regulatory requirements, industry frameworks, and internal policies. The individual serves as a trusted advisor to business and technology stakeholders, facilitating risk-informed decision-making and fostering a culture of security, governance, and compliance.
Responsibilities include oversight of cybersecurity risk assessments, policy exceptions, third-party risk management activities, audit support, compliance initiatives, and continuous improvement of the cybersecurity governance framework. Principal Functional Responsibilities Cybersecurity Risk Management - Lead the Cybersecurity Risk Management Program.
- Conduct and facilitate enterprise cybersecurity risk assessments.
- Maintain and oversee the cybersecurity risk register.
- Evaluate, document, and monitor risk treatment plans and compensating controls.
- Manage cybersecurity policy exception and risk acceptance processes.
- Support integration of cybersecurity risks into Enterprise Risk Management (ERM).
- Develop risk metrics, dashboards, and executive reporting.
Compliance
Management - Lead cybersecurity compliance initiatives across regulatory, contractual, and industry requirements.
- Coordinate internal and external audits and assessments.
- Track and manage remediation plans resulting from audits, assessments, and compliance reviews.
- Monitor emerging cybersecurity laws, regulations, and standards and assess organizational impact.
- Partner with Legal, Privacy, Internal Audit, and business stakeholders to maintain compliance obligations. Third-Party Risk Management - Lead third-party cybersecurity risk assessments and due diligence activities.
- Evaluate vendors, suppliers, and service providers for cybersecurity and compliance risks.
- Track remediation activities and reassessments for high-risk vendors.
- Collaborate with vendor management and procurement teams to strengthen third-party risk governance.
- Stakeholder Engagement & Reporting
- Provide guidance to business leaders on cybersecurity risks and compliance obligations.
- Present risk and compliance metrics to management and governance committees.
- Facilitate cross-functional collaboration among IT, Security, Legal, Privacy, Audit, and business functions.
- Mentor GRC analysts and support team development activities.
Basic
Requirements - Bachelor's degree in computer science, Information Systems, or related degree plus three (3+) years of experience or equivalent combination of education and experience.
- Strong knowledge of security and risk management frameworks like NIST CSF, CIS Critical Security Controls, ISO 27001, NIST 800-53, FAIR, and CIS
- Must possess excellent oral and written communication skills and the ability to communicate in technical and business terms. Additionally, must be comfortable developing presentations and delivering them to senior management.
- 3+ years of experience in cybersecurity, governance, risk, and compliance.
- Experience conducting risk assessments, control evaluations, and compliance audits.
- Strong knowledge of cybersecurity best practices, policies, and procedures.
- Excellent analytical, problem-solving, and communication skills.
- Ability to work independently and collaboratively in a dynamic environment.
- Professional certifications in IT and Cybersecurity a plus (e.g., Security+, GCRP, CGRC etc.).
Preferred
Requirements - Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Risk Management, Business Administration, or related fields.
- 4-7+ years of experience in cybersecurity, risk management, compliance, audit, or governance.
- Experience with cybersecurity frameworks such as:
- NIST Cybersecurity Framework (CSF)
- NIST Risk Management Framework (RMF)
- CIS Critical Security Controls
- ISO 27001 - Strong understanding of risk assessment methodologies and control frameworks.
- Experience managing audits, assessments, and remediation programs.
- Excellent communication, presentation, and stakeholder management skills. Preferred - Professional certifications such as:
- CISSP
- CISM
- CRISC
- CISA
- ISO 27001 Lead Implementer or Lead Auditor - Experience with GRC platforms (ServiceNow IRM, Archer, AuditBoard, etc.).
- Knowledge of privacy, regulatory, and compliance requirements relevant to global operations.
- Experience supporting customer security assessments and third-party risk programs.
Competencies - Tech Savvy: Anticipating and adopting innovations in business-building digital and technology applications.
- Optimizes Work Processes:
Knowing the most effective and efficient processes to get things done, focusing on continuous improvement.
- Plans & Aligns: Planning and prioritizing work to meet commitments aligned with the interpersonal goals.
- Business Insight: Applying knowledge of business and the marketplace to advance the organization's goals.
- Communicates Effectively: Developing and delivering multi-mode communications that clearly understand the different audiences unique needs.
Success
Factors - Cybersecurity risks are identified, assessed, and tracked through closure.
- Compliance obligations are met and audit findings are reduced year-over-year.
- Risk register and executive reporting are accurate and current.
- Third-party risk assessments are completed within defined service levels.
- Governance activities, policy reviews, and exception management processes operate effectively.
- Leadership receives timely and actionable risk intelligence to support business decisions. Our Commitment to Our People Across the globe, we are united by a singular Purpose: Sustainability is no small ambition. That's why everything we do is geared toward a sustainable future—for our generation and all those to come. Through groundbreaking innovations, HVACR technology and cold chain solutions, we are reducing carbon emissions and improving energy efficiency in spaces of all sizes, from residential to commercial to industrial. Our employees are our greatest strength. We believe that our culture of passion, openness, and collaboration empowers us to work toward the same goal - to make the world a better place. We invest in the end-to-end development of our people, beginning at onboarding and through senior leadership, so they can thrive personally and professionally. Versatile and competitive benefits plans offer the right options to meet your individual/family needs. We provide employees with flexible time off plans, including paid parental leave (maternal and paternal), vacation and holiday leave. Together, we have the opportunity – and the power – to continue to revolutionize the technology behind air conditioning, heating and refrigeration, and cultivate a better future. Learn more about us and how you can join our team! Our Commitment to Inclusion & Belonging At Copeland, we cultivate a strong sense of inclusion and belonging where individuals of all backgrounds, and with diverse perspectives, are embraced and treated fairly to enable a stronger workforce. Our employee resource groups play an important role in culture and community building at Copeland.
Equal Opportunity Employer Copeland is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, age, marital status, political affiliation, sexual orientation, gender identity, genetic information, disability or protected veteran status. We are committed to providing a workplace free of any discrimination or harassment.
📌 Senior Engineer (Pune)
🏢 Copeland Supply
📍 Pune