01 Oct
|
NESCO
|
Goregaon
Cyber Security / Information Security & Compliance
Role & responsibilities :Support ISO 27001 and SOC 2 compliance activities and audits.
Conduct IT and Information Security Risk Assessments and identify potential security risks.
Perform Third-Party Risk Management (TPRM) and vendor security assessments.
Conduct vendor security reviews and track remediation of identified risks.
Develop and maintain information security policies, procedures, standards, and compliance documentation.
Assist with internal and external security audits.
Monitor compliance with information security controls and regulatory requirements.
Identify security gaps and recommend appropriate risk mitigation measures.
Support incident response and documentation of security incidents.
Maintain compliance records, evidence, risk registers, and audit documentation.
Work with IT, HR, Operations, Legal, and other cross-functional teams to strengthen the organizations security posture.
Support continuous improvement of the organization's cybersecurity and compliance framework.
Preferred candidate profile
Knowledge of Information Security and Cyber Security fundamentals.
Understanding of ISO 27001 and SOC 2.
Knowledge of GRC (Governance, Risk & Compliance).
Understanding of IT Risk Assessment and Risk Management.
Knowledge of Third-Party/Vendor Risk Management (TPRM).
Familiarity with security audits and compliance documentation.
Good analytical and documentation skills.
Strong communication and stakeholder-management skills.
Positive knowledge of MS Excel, Word and PowerPoint.
Preferred Certifications
ISO 27001 Lead Auditor / Lead Implementer
ISO 27001 Foundation
CISA / CISM / CISSP
CompTIA Security+
Other relevant Cyber Security/GRC certifications
Qualification
Bachelors degree in Cyber Security, Information Technology, Computer Science, Information Security, or a related field.
📌 IT Engineer (Goregaon)
🏢 NESCO
📍 Goregaon