Cybersecurity GRC Consultant(PCI DSS)

Atos SE

Mumbai

On-site

INR 1,500,000 - 2,200,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Atos SE is seeking a senior information security professional with 7+ years of experience to lead the development and implementation of security standards across multiple frameworks. The role involves risk assessments, PCI DSS audits, and guiding clients on data protection and compliance.

You will work with cross-functional teams to ensure secure designs and effective data governance, including data obfuscation strategies.

Qualifications

  • Must have strong communication and presentation skills.
  • Ability to interact with multiple functions and stakeholders.
  • Experience in information security governance and risk management.

Responsibilities

  • Hands-on in information security and cybersecurity standards such as PCI DSS, SWIFT CSP, ISO 27001:2022, ISO 27701, SOC2.
  • Develop and implement cybersecurity standards, procedures, and guidelines for multiple frameworks.
  • Analyze security requirements, perform risk assessments, and identify vulnerabilities in IT systems.
  • Conduct gap analyses and risk assessments based on NIST, ISO, PCI DSS, SWIFT.
  • Lead PCI DSS audits to ensure secure payments and adherence to standards.
  • Collect, analyze, and consolidate evidence of client PCI DSS compliance (AOC/ROC documentation).
  • Assess data flows to identify sensitive datasets and ensure data obfuscation where needed.
  • Develop a data obfuscation framework with governance, workflows, and controls.
  • Deliver documentation, playbooks, and knowledge transfer to internal stakeholders.
  • Advise on tool selection and integration within data management and DevOps environments.
  • Establish validation and monitoring controls for data integrity and protection.
  • Explain technical vulnerabilities and mitigation strategies.
  • Maintain knowledge of AD, firewalls, routers, switches, SCCM, McAfee, DLP, secure coding, and product security.

Job description

Experience – 7+ years
Responsibilities
  • Hands on experience in Information Security and cybersecurity standards (PCI DSS, SWIFT CSP, ISO 27001:2022, ISO 27701, SOC2 etc).
  • Develop and implement cybersecurity standards, procedures, and guidelines for multiple cybersecurity standards (PCI DSS, SWIFT CSP, ISO 27001:2022, ISO 27701, SOC2 etc).
  • Analyse security requirements, perform risk assessments, and identify potential vulnerabilities within IT systems.
  • Conduct gap analysis and risk assessments to identify threats and vulnerabilities based on NIST, ISO, PCI DSS, SWIFT frameworks.
  • Analyse cardholder data flows (business and application data flows) and identify the risks to cardholder data, providing guidance to clients on PCI DSS awareness.
  • Conduct regular PCI DSS audits to ensure secure payment transactions and adherence to PCI DSS Standard.
  • Work independently or collaborate with teams to collect, analyse, consolidate evidence of client PCI DSS compliance; should have written or supported in writing AOC and ROC’s.
  • Conduct current‑state assessment of data flows to identify sensitive datasets requiring obfuscation.
  • Develop a comprehensive data obfuscation framework including governance model, workflows, and control points.
  • Deliver documentation, playbooks, and knowledge transfer to internal stakeholders for long‑term sustainability.
  • Provide guidance on tool selection and integration within existing data management and DevOps environments.
  • Establish validation and monitoring controls to ensure data integrity and protection effectiveness.
  • Understand and explain technical vulnerabilities.
  • Intermediate knowledge of Active Directory, firewalls, routers, switches, SCCM, MacAfee security products, DLP, secure coding practices, and product security.
Must Have Skills
  • Excellent communication and presentation skills.
  • Able to effectively interact with various functions.
Good to have Skills / Certification Minimum
  • PCI DSS QSA, PCIP, or PCI ISA, ISO27001:2022, ISO 27701, ISO 22301 Lead Auditor or implementor course.
  • CISSP, CISA, CISM.
  • ISO 22301.
Qualifications
  • BE / BTech, MCA, MBA with specialization in Information Security.
  • BE Computer Science, BCA, MCA, MBA – Information Technology, or specialization in Information Security.
Critical Thinking

Analysing information, problem‑solving, and making informed judgments.

Collaboration Skills

Working effectively with legal, IT, engineering, and business teams.

Compliance Frameworks

Deep knowledge of PCI DSS, SWIFT CSP, NIST CSF, ISO 27001, GDPR.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity GRC Consultant PCI DSS
Cybersecurity GRC Consultant PCI DSS

Atos Information Technology GmbH • Navi Mumbai

On-site
INR 1,800,000 - 3,000,000
Compliance Executive
Compliance Executive

Plutos One • Dadri

On-site
INR 1,200,000 - 1,800,000
Senior Security GRC Analyst
Senior Security GRC Analyst

Kite • Gurugram District

On-site
INR 1,500,000 - 2,300,000
Infosec GRC Associate II
Infosec GRC Associate II

Zeta • Bengaluru

On-site
INR 800,000 - 1,200,000
Lead GRC
Lead GRC

Ashley Global Capability Center • Chennai District

On-site
INR 1,200,000 - 1,800,000
Technical Lead
Technical Lead

The Hartford India • Hyderabad

On-site
INR 1,500,000 - 2,000,000
Competitive salary
Comprehensive benefits
Continuous learning opportunities
+1
Information Risk Manager
Information Risk Manager

Kotak Mahindra Bank • Mumbai

On-site
INR 2,000,000 - 4,000,000
Cyber Security Manager
Cyber Security Manager

Altimetrik • Bengaluru

Hybrid
INR 1,800,000 - 2,600,000
Senior GRC Analyst
Senior GRC Analyst

3M HEALTHCARE • Hyderabad

On-site
INR 1,500,000 - 2,200,000
PCI DSS Auditor
PCI DSS Auditor

Keka Technologies • Bengaluru

On-site
INR 1,500,000 - 2,300,000