- Update and improve security policies & procedures.
- Perform user access reviews.
- Perform third-party risk management reviews and other forms of risk management.
- Conduct or assist with compliance audits.
- Foster continuous improvements that enhance overall security & compliance.
- Assist with the production of security program metrics.
Governance
- Update security policies and procedures to enhance security & compliance, meet evolving customer and partner requirements, meet evolving regulatory mandates, and address IT risk areas.
- Audit and improve compliance with Comscores policies.
- Assist with gathering operational statistics in support of program metrics.
Access Reviews
- Support Comscore’s user access review process and tool.
- Reliably perform user access reviews to ensure positive audit outcomes.
- Improve access controls and the access management process.
Risk Management
- Contribute to the Comscore Risk Register process to identify, document, treat, or escalate risk areas.
- Leverage Comscore’s vendor risk management tool to conduct third party risk management security reviews.
- Update vendor questionnaires to address new risk areas.
Compliance
- Monitor user activity, internal processes, and infrastructure for compliance with Comscore policies.
- Develop security controls to improve compliance.
- Contribute to security awareness training.
- Collaborate with external auditors and the Internal Audit team to support ISO 27001/27701 and Sarbanes Oxley (SOX) audits.
Qualifications/Experience
Educational Qualifications
- Bachelor's degree in information systems or equivalent work experience.
- Industry Certifications (e.g. CISA).
Technical Competency
- Knowledge of information security principles,
including access control and risk management.
- Experience performing access reviews and using access review tools. Familiarity with Conductor One is preferred.
- Knowledge of GRC tools. Familiarity with Drata is a plus.
- Experience in developing, documenting and maintaining security and compliance policies and procedures.
- Experience with information security management frameworks, such as ISO 27001, NIST, GDPR, CCPA, or other privacy regulations.
- Prior audit experience. Familiarity with ISO 27001 and ISO 27701 preferred.
- Experience in developing, documenting and maintaining security procedures.
- Experience coordinating BC/DR projects and knowledge of common DR practices.
- Experience with ticketing systems (familiarity with Jira preferred).
- Experience with Windows and Linux operating systems.
- Experience with cloud service providers (AWS preferred).
- Experience with Active Directory.
- Experience with Power Shell.
- Experience with Identity and Access Management and Privilege Access Management tools.
Occupational Personality
- Ability to follow established procedures reliably and with attention to detail.
- Ability to work well under minimal supervision.
- Solid written and verbal communication skills.
- Strong analytical and problem-solving skills.
- Continuous improvement mindset.
- Ability to document procedures.
- Strong team-oriented interpersonal skills.
- Strong customer/client focus, with the ability to manage expectations appropriately, provide a superior customer/client experience and build long-term relationships.
- Ability to interface effectively with a broad range of people and roles, including senior leadership and technical personnel.
- Ability to work under stress and handle multiple high-pressure situations simultaneously.
- Ability to work in meetings during US hours as needed (Pacific and Eastern Time)
📌 Security Compliance Analyst (Pune)
🏢 Comscore Technologies
📍 Pune
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.