Sr Subject Matter Expert (Support&Ops) (Noida)

Sr Subject Matter Expert (Support&Ops) (Noida)

05 Aug
|
HCL Technologies
|
Noida

05 Aug

HCL Technologies

Noida

Sr Subject Matter Expert (Support&Ops;)

Experience: 3 to 5 years

Location: Gautam Buddha Nagar, India

Skills: ISO 27001, SOC 2, NIST, GDPR, Service Now -IRM, OneTrust, Archer, cloud storage disaster recovery, risk management, compliance, audit, problem-solving, interpersonal skills, ISO 27001 Lead Auditor, CISA, CISM, CISSP, critical thinking, analytical skills

Job Summary
GRC (Governance, Risk, and Compliance) Analyst works with process owners, auditors, and stakeholders to analyze, monitor, and address risk management and compliance issues. Responsibilities include administering ISO 27001 and SOC 2 compliance programs, assisting with assessments, and ensuring adherence to SOC2, ISO 27001 standards. This role is crucial in protecting the organization’s reputation and ensuring regulatory compliance. By mitigating risks and preventing breaches, the GRC Analyst enhances IT security and strengthens operational resilience, delivering significant value through improved risk management and regulatory alignment.

Key Responsibilities
Typical duties and responsibilities
• Conduct risk assessments, validation testing, compliance reviews, and audits in line with ISO or NIST standards.
• Oversee and support SOC 2 and global ISO 27001 audit processes.
• Conduct Internal Audits – implementing and assessing ITGC controls.
• Drive the widespread implementation of ISO 27001 standards across the organization.
• Manage and monitor a central repository for audit evidence.
• Review and update security standards, policies, and practices to meet corporate demands.
• Share information with managers to avoid surprises, highlight problems, and ensure timely delivery.
• Develop and maintain a comprehensive GRC framework, ensuring alignment with industry best practices and regulatory requirements.
• Coordinate with cross-functional teams to identify and mitigate risks associated with IT and business processes.
• Provide expert guidance on regulatory changes and emerging security threats,



ensuring the organization remains compliant and secure.
• Conduct Information security Awareness sessions and assessments.

Skill Requirements
Required skills and experience
• Over 3-5 years of experience in Information Security with a specialized focus on risk management and compliance. This includes more than 3 years of hands-on experience with ISO 27001 and SOC 2 audits, involving tasks such as developing audit plans, identifying control gaps, and recommending effective remediation measures.
• Bachelor’s degree in Information Cybersecurity, Computer Science, or a related field.
• Strong understanding of regulatory requirements, including ISO 27001, SOC 2, NIST, and GDPR, with experience applying these standards in real-world scenarios.
• Familiarity with GRC tools, such as Service Now -IRM, OneTrust, or Archer, and experience with cloud storage disaster recovery processes.
• Proven experience in managing risk and compliance projects, including coordinating third-party audits, leading audit response initiatives, and developing audit plans. Responsibilities include identifying control gaps, recommending remediation measures, and managing the audit process.
• Excellent problem-solving skills and attention to detail, with the ability to analyze complex issues, develop effective solutions, and communicate findings.
• Solid interpersonal and communication skills, essential for collaborating with various stakeholders, presenting audit results, and negotiating remediation actions.

Other Requirements
Nice to have/preferred skills and experience (not required)
• ISO 27001 Lead Auditor, CISA, CISM, or CISSP, or working towards these certifications.
• Critical thinking and analytical skills. This includes evaluating risk factors, interpreting regulatory requirements, and making data-driven decisions to enhance compliance programs and mitigate potential issues.
• Proven ability to effectively convey complex information and regulatory requirements to both technical and non-technical stakeholders.
• Knowledge of data privacy regulations and best practices, such as GDPR and CCPA.

📌 Sr Subject Matter Expert (Support&Ops) (Noida)
🏢 HCL Technologies
📍 Noida

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: sr subject matter expert (support&ops) (noida) / noida

Subscribe to this job alert:

Get the latest job offers by email for: sr subject matter expert (support&ops) (noida) / noida