07 Aug
|
iLink Digital
|
Pune
07 Aug
iLink Digital
Pune
Role & responsibilities
Key Responsibilities:
Security Compliance & Certification: Support security compliance functions, focusing on SOC2, NIST, and other relevant frameworks (e.g., ISO 27001).
NIST Risk Management: Lead and contribute to internal security risk assessments, ensuring compliance with NIST Cybersecurity Framework (CSF) and its controls (Identify, Protect, Detect, Respond, Recover).
Third-Party Risk Management: Collaborate with third-party vendors, conducting security risk assessments, managing vendor inventories, and ensuring adherence to NIST security standards for third-party engagements.
Security Incident Response: Work under the direction of the Landmark Security Lead to support incident response activities, leveraging NIST SP 800-61 guidance for handling security incidents.
Security Program Management: Oversee and manage various security-related programs, ensuring alignment with NISTs 800-53 or 800-171 standards for security control implementation and reporting.
Security Metrics & Reporting: Continuously monitor and report on security metrics (e.g., risk register updates, security posture assessments) based on NIST frameworks.
Continuous Security Monitoring: Ensure ongoing security monitoring, evaluating risks, and implementing mitigations in alignment with NIST standards and best practices.
Vendor & Asset Management: Update and maintain vendor inventory with security risk ratings, approvals, and NIST-based risk assessments.
Security Awareness & Training:
Develop and deliver end-user training guides and documentation, in accordance with NIST’s security awareness guidelines.
Security Awareness & Research: Stay informed on current security trends, attack vectors, and countermeasures, leveraging NIST publications (e.g., NIST 800-53, NIST SP 800-82) to stay ahead of emerging threats.
Requirements & Qualifications:
Educational Background: Bachelor’s degree in information technology, Cybersecurity, Risk Management, Computer Science, or equivalent experience.
Security Framework Experience: Hands-on experience with NIST standards, particularly NIST CSF, NIST 800-53, NIST 800-171, and NIST 800-61. Understanding of SOC2 and ISO 27001 also preferred.
Security Controls Knowledge: Familiarity with security controls like access control, encryption, authentication, auditing, data integrity, and physical security in the context of NIST guidelines.
Security Risk & Incident Management: Experience managing risk and incident management processes with a focus on NIST-based frameworks.
Vendor Management & Third-Party Risk: Strong understanding of managing third-party security risk, utilizing NIST controls and best practices.
Communication & Collaboration: Ability to collaborate with diverse teams, communicate security risks to all levels of the organization, and develop transparent and concise security documentation.
Continuous Learning: Proactively engage with industry trends, and apply lessons learned from NIST-based research to enhance security posture.
📌 GRC Lead - US Time Zone - 6 To 9 years (Pune)
🏢 iLink Digital
📍 Pune