11 Sep
|
Cognizant
|
Bengaluru
11 Sep
Cognizant
Bengaluru
Purpose of the Role:
- Lead application team and support control owners in the design and implementation of ITGCs for the new SIEM monitoring solution and its underlying Azure services to ensure SOX-compliance
- Ensure that the monitoring solution appropriately addresses key SOX risks by enabling effective, evidence-based monitoring of in-scope activities, and the timely notification and escalation to monitoring teams
- Provide subject-matter expertise on IT SOX risks, control design, and evidence requirements to help embed sustainable controls within the solution and associated proc
- Support GRC SOX team in integrating the new solution into the wider SOX control framework, including scoping, testing and remediation activities
Key Responsibilities:
- Leading application teams and control owners in identifying SOX-relevant risks and defining corresponding ITGCs for the solution and underlying services
- Working with application teams and control owners to define SOX-relevant use cases for in-scope activities (e.g. interface monitoring for transfer of data, privileged access, sensitive operations, change management) and ensuring appropriate, auditable evidence is captured
- Driving the design and documentation of end-to-end SOX controls (design, operation, evidence, ownership) covering:
- Monitoring of in-scope critical events and activities
- Notification and escalation workflows to monitoring teams
- Partnering with monitoring teams to ensure that alert handling, investigation and closure processes are designed and operated in a SOX-compliant manner
- Developing and maintaining a robust understanding of Tech processes, risks and controls relevant to security monitoring, including Microsoft Azure solutions and services
- Supporting Tech control owners in developing robust remediation plans, tracking remediation progress, and confirming successful remediation of identified issues
Mandatory Requirements:
- Experience in ITGC SOX controls implementation
- Experience of SIEM monitoring and alerting of security events
- Proven capability in risk management and internal controls
- Experience applying critical thinking to understand IT SOX risks and working with Tech teams to design and implement appropriate IT controls
- Proven experience working and influencing cross-functionally
- Strong and clear communication skills verbal and written
- Ability to multitask and work to deadlines
Optional / nice to have Requirements:
- Experience of Azure Cloud, data lakes, and other SaaS solutions
- Experience with security monitoring of privileged operations
- ISO27001, CISA, CRISC, CISM or similar certification
- Microsoft Azure certifications focused on security or administration (e.g. AZ-500, AZ-104, SC-200)
📌 GRC SOX (Bengaluru)
🏢 Cognizant
📍 Bengaluru