05 Aug
|
HCL Technologies
|
Gurugram
05 Aug
HCL Technologies
Gurugram
Senior Analyst - Billing/Invoicing Lead to cash
Experience: 3 to Not Available years
Location: Gurugram, India
Skills: cybersecurity, risk assessment, vendor management, ISO 27001, NIST, SOC 2, GDPR, cloud security, AWS, Azure, GCP, CISSP, CISA, CISM, CRISC
Job Summary
We are seeking a highly skilled Vendor Security Assessment Engineer to evaluate and ensure the security posture of third-party vendors, partners, and suppliers. This role involves assessing vendor compliance with security policies, industry standards, and regulatory requirements. The ideal candidate will have a solid background in cybersecurity, risk assessment, and vendor management.
Key Responsibilities
• Conduct security assessments of third-party vendors, identifying risks and recommending mitigations.
• Evaluate vendor compliance with security frameworks such as ISO 27001, NIST, SOC 2, GDPR, and other relevant regulations.
• Review penetration testing reports, cloud configuration reports, and report findings.
• Perform security due diligence and risk analysis for vendor onboarding and ongoing vendor relationships.
• Collaborate with internal teams, including procurement, legal, and IT security, to ensure security requirements are met.
• Develop and maintain security assessment questionnaires and methodologies.
• Monitor vendor security incidents and work with vendors to resolve security gaps.
• Provide recommendations for vendor risk remediation and track progress.
• Maintain documentation of security assessment results and provide regular reports to management.
• Stay up to date with emerging security threats and industry best practices.
Skill Requirements
• Bachelor’s degree in Computer Science, Information Security, or a related field.
• 3+ years of experience in security risk assessment, vendor risk management, or cybersecurity.
• Strong understanding of security frameworks and regulatory compliance requirements.
• Ability to analyze security policies, architecture, and controls of third-party vendors.
• Excellent communication and interpersonal skills.
• Relevant security certifications (e.g., CISSP, CISA, CISM, CRISC, or equivalent) are a plus.
Other Requirements
• Experience working in a cloud security environment (AWS, Azure, GCP).
• Familiarity with third-party risk management tools and platforms.
• Knowledge of data privacy laws and secure data handling practices.
• Experience in contract review from a security and compliance perspective.
📌 Senior Analyst Billing/Invoicing Lead to cash (Gurugram)
🏢 HCL Technologies
📍 Gurugram