Job Description:
- Facilitate implementation of various standard regulatory and compliance requirements such as ISO27001 SSAE18 PCI DSS HIPAA etc
- as applicable to the engagement
- Support for responding to information security related request for information proposals RFI RFPs review master services agreements and any renewals or amendments for the engagement
- Analyze data generated during ongoing information processing activities to generate information security metrics that indicate the level of risk to the engagement
- Conduct periodic information security awareness sessions for the engagement
Key Responsibilities:
- The candidate shall have at least 6 7 years experience in Information Security Governance risk and compliance management with strong data and network security concepts
- The candidate shall have vast experience in the areas of Risk Management Governance Compliance Security policy and Metrics
- The candidate should possess excellent technical analytical troubleshooting and problem solving skills
- The candidate is expected to work as an individual contributor and shall have excellent communication and collaboration skills
- The candidate shall possess thorough understanding and have experience in implementation of ISO 27001 2013 SSAE 18 SOC 1 SOC 2 PCI DSS HIPAA other industry recommended standards and regulations
- The candidate shall have strong technical understanding of Information Security
Technical Requirements:
- Engineering Graduate or equivalent with 6 years of experience Post Graduate with 5 years of experience
- The candidate shall hold certifications like CISSP CISM CISA or ISO 27001 Lead Auditor
Additional Responsibilities:
- Self starter positive mentality and a go getter attitude mandatory
- Strong verbal and written communications skills mandatory including creative writing skills
- Strong people and negotiation skills mandatory
- Quick learner a researching mentality and ability to adapt to and meet demands of a quick changing environment
- Strategic thinking and project management skills
Preferred Skills:
Domain->Infrastructure-Information Security Management->ISO 27001 Audit,Implementation
Skills: Compliance, soc 1 , Iso 27001, Pci Dss, Hipaa, Cism, Governance, Cissp, Cisa, Security Policy, metrics, Risk Management
Experience: 6.00-8.00 Years
📌 Manager - Information Security (Pune)
🏢 Infosys
📍 Pune