09 Oct
|
Staffing Services
|
Bengaluru
09 Oct
Staffing Services
Bengaluru
Role & responsibilities
Key responsibilities
1. Information Security Governance
- Design, implement, and maintain the Information Security Management System (ISMS) aligned to ISO/IEC 27001.
- Define and maintain security policies, standards, procedures, and guidelines.
- Support ISO 27001 certification, surveillance audits, and recertification cycles.
- Perform Statement of Applicability (SoA) creation, control mapping, and gap analysis.
- Drive risk treatment plans and track remediation activities.
2. AI Governance & Emerging Technology Compliance
- Implement and operationalize AI governance frameworks aligned to:
- ISO/IEC 42001 (AI Management System)
- NIST AI Risk Management Framework
- Responsible AI principles (fairness, explainability, transparency, accountability).
- Support creation of Model Cards, AI Risk Assessments, Data Lineage, and Human-in-the-Loop controls.
- Coordinate with engineering teams on AI lifecycle governance (design development deployment monitoring).
- Track regulatory readiness for EU AI Act and sector-specific AI regulations.
3. Risk Management & Cyber Risk Assessment
- Conduct enterprise, product, and project-level risk assessments.
- Perform threat modeling, risk scoring, and control effectiveness evaluations.
- Maintain risk registers, risk heatmaps, and executive dashboards.
- Support Third-Party Risk Management (TPRM) and vendor cybersecurity assessments.
- Lead business impact analysis (BIA) and support BCP / DR planning.
4. Data Privacy & Regulatory Compliance
- Implement and manage compliance with global data protection laws, including:
- GDPR
- India DPDP Act
- HIPAA (where applicable)
- Sector-specific privacy regulations (media, ad-tech, automotive, IoT).
- Support DPIAs, RoPA, consent management, DSAR handling, and breach response processes.
- Work closely with Legal, DPOs, and Product teams to embed privacy-by-design.
- Conduct privacy risk assessments for current systems and data flows.
5. Cybersecurity Frameworks & Standards Alignment
- Map and align organizational controls to frameworks such as:
- NIST CSF
- NIST SP 800-53
- CIS Controls
- ISO 22301 (Business Continuity)
- SOC 2 (where applicable)
- Translate framework requirements into practical, implementable controls for engineering teams.
- Support customer and regulator questionnaires, audits, and due-diligence requests.
6. Audit, Assurance & Compliance Reporting
- Act as a primary point of contact for internal audits, external audits, and regulator interactions.
- Prepare audit evidence, compliance reports, and executive summaries.
- Track audit findings, non-conformities, corrective and preventive actions (CAPA).
- Support customer compliance reviews and security assurance programs.
7. Stakeholder Management & Enablement
- Collaborate with:
- Engineering & DevOps teams
- Legal & Privacy
- Product Management
- Procurement & Vendor Management
- Senior leadership and board committees
- Conduct security awareness and compliance training for internal teams.
- Translate complex regulatory requirements into developer-friendly guidance.
📌 Opening For Cybersecurity GRC & Compliance (Media, Telco & Healthcare) (Bengaluru)
🏢 Staffing Services
📍 Bengaluru