05 Aug
|
HCL Technologies
|
Lucknow
05 Aug
HCL Technologies
Lucknow
Subject Matter Expert (Support&Ops;)
Experience: 7 to 8 years
Location: Lucknow, India
Skills: CISA, CISM, CISSP, CRISC, GRC, SOX, HIPPA, GDPR, GLBA, FISMA, PCI DSS, SOC, ISO 31000, Third-Party Risk Management, SIG, ISO 27001, NIST framework, SOC 1, SOC2, HIPAA
Job Summary
Security professional with at least 7-8 years of progressive, responsible, and diversified experience in Information security consulting, Third-Party risk management and auditing
• Must have Bachelor’s degree in computer science, information systems or equivalent
• Certified in industry accepted certifications such as CISA, CISM, CISSP, CRISC
• GRC professional with good understanding of industry frameworks and standards
• In-depth understanding of review process of current system security measure by performing security assessments to identify security gaps
• Knowledgeable in various regulations like SOX, HIPPA, GDPR, GLBA, FISMA and standards like PCI DSS, SOC (service organization’s controls), ISO 31000
• In-depth experience on Third-Party Risk Management
• Evaluating third party's cybersecurity control and ensuring they comply with organizations standards and industry best practices
• Track and monitor the status of each due diligence review and communicate the status with management and key stakeholders on a regular basis
• Articulate risks and potential options for remediation or compensating controls
• Understand inherent risk assessment
• Perform new and recurring third party security risk assessments, develop mitigation plans, and work with internal stakeholders to assign remediation-tracking responsibility
• In-depth understand of GDPR, LGPD and other privacy requirements
• Strong business and communication skills
• Experience in driving meetings with stakeholders
• Provide advisory and consulting to client on new trends and challenges in enterprise risk management
• Experience in design and development of information security policies, standards, and guidelines
• Experience on SIG (shared assessments), ISO 27001, NIST framework, SOC 1, SOC2, ISO 27001 and HIPAA
• Has sound experience around implementation of security controls, risk assessment framework, and program that align to regulatory requirements, ensuring documented and sustainable compliance that aligns and advances customer business objectives
• Design / modify Contract security language / security clauses
• Co-ordinate and negotiate security clauses with Procurement team and Supplier
• Experience on GRC platforms
• Work with the client & technical teams for change request on any risk or control implementation as well as governance process
• Participate in internal as well as external regulatory as well as IT security audits.
• Understand IT Risks and define audit & governance mechanisms for assets, processes & physical security
Key Responsibilities
Security professional with at least 7-8 years of progressive, responsible, and diversified experience in Information security consulting, Third-Party risk management and auditing
• Must have Bachelor’s degree in computer science, information systems or equivalent
• Certified in industry accepted certifications such as CISA, CISM, CISSP, CRISC
• GRC professional with good understanding of industry frameworks and standards
• In-depth understanding of review process of current system security measure by performing security assessments to identify security gaps
• Knowledgeable in various regulations like SOX, HIPPA, GDPR, GLBA, FISMA and standards like PCI DSS, SOC (service organization’s controls), ISO 31000
• In-depth experience on Third-Party Risk Management
• Evaluating third party's cybersecurity control and ensuring they comply with organizations standards and industry best practices
• Track and monitor the status of each due diligence review and communicate the status with management and key stakeholders on a regular basis
• Articulate risks and potential options for remediation or compensating controls
• Understand inherent risk assessment
• Perform new and recurring third party security risk assessments, develop mitigation plans, and work with internal stakeholders to assign remediation-tracking responsibility
• In-depth understand of GDPR, LGPD and other privacy requirements
• Strong business and communication skills
• Experience in driving meetings with stakeholders
• Provide advisory and consulting to client on recent trends and challenges in enterprise risk management
• Experience in design and development of information security policies, standards, and guidelines
• Experience on SIG (shared assessments), ISO 27001, NIST framework, SOC 1, SOC2, ISO 27001 and HIPAA
• Has sound experience around implementation of security controls, risk assessment framework, and program that align to regulatory requirements, ensuring documented and sustainable compliance that aligns and advances customer business objectives
• Design / modify Contract security language / security clauses
• Co-ordinate and negotiate security clauses with Procurement team and Supplier
• Experience on GRC platforms
• Work with the client & technical teams for change request on any risk or control implementation as well as governance process
• Participate in internal as well as external regulatory as well as IT security audits.
• Understand IT Risks and define audit & governance mechanisms for assets, processes & physical security
Skill Requirements
GRC
Other Requirements
GRC
📌 Subject Matter Expert (Support&Ops) (Lucknow)
🏢 HCL Technologies
📍 Lucknow