24 Sep
|
Sodexo
|
Gurugram
Deliver two core security assurance functions within the hub: ensure that security requirements are embedded into projects and solutions from inception through to delivery (Security by Design), and manage the end-to-end information security risk assessment lifecycle for hub-scope third-party suppliers (Third Party Risk Management). Act as the primary operational assurance interface between the hub and the Group GRC function.
Responsibilities:
Hub-scope third-party supplier population
Operates within globally standardised frameworks — Group Security by Design framework and TPRM process — defined by the Group GRC function
Follow-the-sun assurance model alongside two peer hub roles (Americas, Asia, Europe)
Scope covers hub-based projects, initiatives, and supplier relationships across all business segments within the hub geography
Maintain consistent security assessment quality across a diverse project pipeline — ranging from infrastructure changes to business application deployments — where project teams have differing levels of security maturity
Balance thoroughness of TPRM assessment with hub operational pace and procurement timelines
Influence project owners, business stakeholders, and vendors to act on security findings without direct authority
Manage end-to-end TPRM accountability at hub level while feeding outcomes into the global risk picture owned by HQ GRC
Navigate regional regulatory context (data protection, sector-specific obligations) that affects both assessment tracks
Intake assessment
1. Review projects and initiatives at inception to identify information security requirements, risks, and applicable controls
2.
Conduct structured security intake assessments using the Group Security by Design framework; document outputs and agree requirements with project teams
3. Ensure security requirements are formally captured in project scope and tracked as delivery obligations
Delivery assurance
1. Assess delivered solutions against the agreed security requirements and Group security architecture baseline prior to go-live
2. Document findings, assign risk ratings, and agree remediation or acceptance decisions with the project owner and Hub Security Lead
3. Maintain a hub-level register of Security by Design assessments, findings, and closure status; report into Group GRC on the defined cadence
Third Party Risk Management
1. Manage the end-to-end TPRM assessment lifecycle for hub-scope suppliers: initial scoping, questionnaire issuance, response review, risk scoring, findings documentation, remediation tracking, and formal sign-off
2. Operate within the global TPRM platform and process framework defined by HQ GRC; maintain data quality and completeness for the hub supplier population
3. Conduct risk-based prioritisation of the hub supplier population to determine assessment frequency and depth
4. Engage hub-based business units and procurement teams to ensure third-party assurance is embedded in sourcing and contract renewal activity
5.
Escalate significant supplier risk findings to the Hub Security Lead and Head of GRC; track remediation to closure
6. Contribute hub TPRM outcomes to the global consolidated third-party risk picture owned by HQ GRC
7. All hub projects above the agreed risk threshold receive a Security by Design intake assessment before design is locked
8. Security by Design delivery assurance completed and documented before go-live for all in-scope projects
9. Hub-scope third-party suppliers assessed, risk-scored, and tracked end-to-end within agreed timescales
10. Significant findings (Security by Design and TPRM) escalated and remediation tracked to closure
11. Hub assessment registers accurate, current, and submitted to Group GRC on cadence
Required Skills:
1. 5-10 years of experience as a Compliance Officer
2. Practical experience conducting security assessments in a project or solution delivery context
3. Experience managing third-party supplier security assessments end-to-end
4. Working knowledge of security architecture principles sufficient to assess solutions against a defined baseline
5. Familiarity with TPRM platforms and risk scoring methodologies
6. Ability to engage and influence project owners, procurement teams, and vendors without direct authority
7. Desirable certifications: CISA, CRISC, ISO27001 LI, ISO27001 LA, CISSP (Associate)
8. Professional proficiency in English (working language); additional hub language an advantage
9. Rigorous, organised, with strong written documentation discipline
10. Analytical and problem-solving capabilities
11. Rigorous management of results
12. Business consulting (influencing without authority)
13. Innovation and Change
14. Learning Development
📌 Cyber Security Compliance Officer (Gurugram)
🏢 Sodexo
📍 Gurugram