Cyber Security Compliance Analyst

Carmeuse

Bengaluru

On-site

INR 2,500,000 - 4,000,000

Full time

5 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Carmeuse seeks an experienced IT Security Compliance professional to manage regulatory obligations, audit support, and governance across global security controls. This role focuses on GDPR, NIS2, SAP security audits, SWIFT, and GITC, ensuring secure, auditable processes and evidence packs.

English communication and a strong audit mindset are essential. Ideal candidates have 8+ years in IT/cyber security, a CISA certification, and familiarity with vulnerability management, access controls, and

Qualifications

  • Bachelor's degree in engineering/technology in Information Security, Computer Science, IT or a related field
  • 8+ years of IT or cyber security experience with hands-on compliance, audit support and reporting
  • Working knowledge of GDPR, NIS2, SAP security audits, SWIFT, GITC; CISA certification mandatory
  • ISO 27001 or CIPM is a plus, English language proficiency

Responsibilities

  • Maintain and improve compliance control set, evidence, and documentation for regulatory and audit obligations
  • Manage application change controls and SDLC
  • Oversee security hardening, vulnerability patching of OS and databases
  • Manage user access permissions and reviews, including privileged access
  • Conduct security logs monitoring, audit trails, and access governance
  • Coordinate vulnerability management and remediation tracking across teams
  • Prepare monthly/quarterly/annual compliance and awareness reports
  • Support internal and external audits and coordinate control owners
  • Maintain security governance documentation and related reports

Skills

GRC & audit reporting
Regulatory knowledge
English proficiency
Communication skills
Problem solving

Education

Bachelor's degree in IT/CS/Engineering

Tools

KnowBe4

Job description

Job Description
Key Responsibilities
  • Maintain and continuously improve the compliance control set, the supporting evidence and the documentation required by regulatory and audit obligations (GDPR,NIS2, SAP security audits, SWIFT and GITC), covering:
  • Ø Application change management and software development life cycle controls
  • Ø Security hardening and vulnerability patching of operating systems and databases
  • Ø IT user access permissions and periodic user access reviews
  • Ø General user access – security audit logs, monitoring evidence and review
  • Ø Privileged user access (ie Firefighter usage) and privileged activity review
  • Ø Governance and review of operating systems and databases privileged access
  • Ø Password policies and baseline identity controls (SSO/MFA principles)
  • Ø Software compliance and security – web vulnerability management
  • Ø SWIFT Customer Security Programme (CSP) compliance
  • Ø Track training completion and phishing click/report rates, and propose improvements to campaign content, targeting and follow-up
  • Ø Operate the global security awareness and vulnerability management follow-up processes, driving measurable improvement in employee behaviour and remediation performance
  • Ø Ensure that Carmeuse's regulatory and audit compliance controls are secure and auditable, in line with the established security, audit and regulatory requirements (GDPR, NIS2, SAP security audits, SWIFT and GITC)
  • Run the day-to-day operation of the global security awareness programme: plan and launch phishing simulations and training campaigns, follow up completion, and report on results
  • Collaborate with the SAP Basis Security & Authorization team to review and report SoD violations
  • Coordinate the global vulnerability management process: consolidate scan results, prioritise on risk, track remediation with infrastructure, application and OT owners,and escalated overdue or high-risk items
  • Prepare the monthly, quarterly and annual compliance, vulnerability and awareness reports for the Global Security & Compliance Manager and for Carmeuse IT leadership
  • Support internal and external audits (including GITC): prepare evidence packs, coordinate control owners, support walkthroughs, and track findings through to closure
  • Maintain the security governance documentation (policies, standards, procedures, control narratives and the exception register) and participate in ITSC and cyber security team meetings
  • Maintain the compliance documentation, metrics and reporting used by the Global Security & Compliance Manager and by IT leadership
Key performance indicators :

Compliance and audit findings closed on time; vulnerability remediation performance against the agreed SLAs (critical / high); security awareness results (training completion rate, phishing simulation click and report rates); timeliness and quality of the compliance evidence, metrics and reporting.

Required
  • Bachelor’s degree in engineering / technology in Information Security, Computer Science, IT or a related field
  • At least 8 years of experience in IT or cyber security, with hands‑on exposure to compliance, audit support and reporting (a GRC or internal audit background is an advantage)
  • Working knowledge of regulatory and audit frameworks (GDPR, NIS2, SAP security audits, SWIFT,GITC);
  • Mandatory certification: CISA
  • ISO 27001 or CIPM are a plus
  • Language: English (written & spoken)
  • Cyber security governance, control frameworks and audit evidence expectations
  • Regulatory and industry compliance topics: GDPR, NIS2, SAP security audits and SWIFT
  • compliance
  • User access, Segregation of Duties and identity and access fundamentals (SSO/MFA principles)
  • Vulnerability management principles (risk-based prioritisation, remediation lifecycle, reporting)
  • and security awareness platforms such as KnowBe4
Skills
  • Problem solving, with attention to detail in controls, evidence and documentation
  • Written and oral communication skills – able to explain technical topics to non-technical stakeholders
  • Organization & planning – able to track many actions through to closure and hold a reporting cadence
  • Microsoft desktop applications (Excel, Word, PowerPoint) and compliance reporting/dashboarding
  • Cross-functional collaboration with IT, OT, Legal & Privacy and business owners; pragmatic and outcome-focused
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Compliance Analyst
Compliance Analyst

Carmeuse Lime & Stone Inc • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Cybersecurity & Compliance Advisor
Cybersecurity & Compliance Advisor

Siemens Mobility • Gurugram District

On-site
INR 2,500,000 - 4,000,000
Software Engineer/ IT Support Engineer
Software Engineer/ IT Support Engineer

MS Clinical Research • Karnataka

On-site
INR 900,000 - 1,300,000
Compliance Analyst
Compliance Analyst

Acura Solutions • Ernakulam

On-site
INR 700,000 - 1,100,000
Lead Compliance Specialist
Lead Compliance Specialist

TAC Security • Chandigarh

On-site
INR 2,600,000 - 3,200,000
Cyber Security Consultant
Cyber Security Consultant

PwC India • Chennai District

On-site
INR 1,000,000 - 1,500,000
Cyber Security Manager
Cyber Security Manager

Altimetrik • Bengaluru

Hybrid
INR 1,800,000 - 2,600,000
Information Security Analyst
Information Security Analyst

Xceedance • Gurugram District

On-site
INR 800,000 - 1,200,000
Senior Manager – Digital, Cyber Security (GRC)
Senior Manager – Digital, Cyber Security (GRC)

Tata Consumer Products • Bengaluru

On-site
INR 1,500,000 - 1,900,000
Senior IT Audit & Compliance Specialist
Senior IT Audit & Compliance Specialist

NXP • Bengaluru

On-site
INR 2,000,000 - 3,500,000