Roles and Responsibilities
Greetings from GRM Technologies!!!
Providing support in IT and Cyber Risk Advisory services offered by GRM Technologies to its clients in the following domains-
Information regulatory compliance (ISO 27001, PCIDSS, RBI, SEBI, SOC1, SOC2, PCI DSS, HITRUST, GDPR)
- Information risk management
- Information security and information assurance
- Information technology controls for financial and other systems
- Identifying processes and technologies to maintain and enhance the security architecture
- Disaster recovery and business continuity management Information privacy
- Have a fair understanding of Business Continuity Planning and DR Drills
- Should have conducted Information Life Cycle management reviews in the past
- Conducting Infrastructure Vulnerability Assessment and Penetration Testing
- Conducting Web and Mobile Application Security Assessment
- Conducting Secure Code Review
- Conducting Architecture Review
Should have minimum 2-8 yrs. of experience into Cyber Security, including IT Risk, Cyber Risk & Compliance, IT Audit, Vendor Audit, VAPT, Application Security, Fraud Risk & Security.
- Knowledge of information security standards, principles and practices required
- Perform risk assessment, controls and documentation with expected standards (information technology/ business process)
- Conduct Infrastructure Vulnerability Assessment and Penetration Testing
- Conduct Web Application Security Assessment
- Conduct Mobile Application Security Assessment
- Conduct Source Code Review
- Perform SOX compliance audits, SOC 1 and SOC 2 audits, as well as testing and reporting
- Perform control testing pertaining to operating systems, data base (Windows, Unix, Oracle, MSSQL, DB2)
- Should be able to test basic and automated ERP ITGC controls (SAP, Oracle, etc.)
- Ability to draft BCP/ DR policy and carry out testing of plan and procedures would be preferable
- Ability to adapt to new scope areas and technologies
- Bring in vertical expertise in at least two verticals like BFSI, manufacturing, or more
- Ability to manage client communication and escalation
- Ability to make all attempts to guide the peers and self to improve client satisfaction scores
- Participate in proposal preparation
- Understanding of risk
- Appreciation for technological innovation
- Strong organization skills
- Curiosity and eagerness to learn
- Initiative to seek out opportunities and add value
- Tolerance for ambiguity and shifting priorities; appreciation of change.
- Should have certification on CCNA / CCNP / ITIL
- Exposure into ISO 27001 is mandate