Experience – 7+ years
Responsibilities
- Hands on experience in Information Security and cybersecurity standards (PCI DSS, SWIFT CSP, ISO 27001:2022, ISO 27701, SOC2 etc).
- Develop and implement cybersecurity standards, procedures, and guidelines for multiple cybersecurity standards (PCI DSS, SWIFT CSP, ISO 27001:2022, ISO 27701, SOC2 etc).
- Analyse security requirements, perform risk assessments, and identify potential vulnerabilities within IT systems.
- Conduct gap analysis and risk assessments to identify threats and vulnerabilities based on NIST, ISO, PCI DSS, SWIFT frameworks.
- Analyse cardholder data flows (business and application data flows) and identify the risks to cardholder data, providing guidance to clients on PCI DSS awareness.
- Conduct regular PCI DSS audits to ensure secure payment transactions and adherence to PCI DSS Standard.
- Work independently or collaborate with teams to collect, analyse, consolidate evidence of client PCI DSS compliance; should have written or supported in writing AOC and ROC’s.
- Conduct current‑state assessment of data flows to identify sensitive datasets requiring obfuscation.
- Develop a comprehensive data obfuscation framework including governance model, workflows, and control points.
- Deliver documentation, playbooks, and knowledge transfer to internal stakeholders for long‑term sustainability.
- Provide guidance on tool selection and integration within existing data management and DevOps environments.
- Establish validation and monitoring controls to ensure data integrity and protection effectiveness.
- Understand and explain technical vulnerabilities.
- Intermediate knowledge of Active Directory, firewalls, routers, switches, SCCM, MacAfee security products, DLP, secure coding practices, and product security.
Must Have Skills
- Excellent communication and presentation skills.
- Able to effectively interact with various functions.
Good to have Skills / Certification Minimum
- PCI DSS QSA, PCIP, or PCI ISA, ISO27001:2022, ISO 27701, ISO 22301 Lead Auditor or implementor course.
- CISSP, CISA, CISM.
- ISO 22301.
Qualifications
- BE / BTech, MCA, MBA with specialization in Information Security.
- BE Computer Science, BCA, MCA, MBA – Information Technology, or specialization in Information Security.
Critical Thinking
Analysing information, problem‑solving, and making informed judgments.
Collaboration Skills
Working effectively with legal, IT, engineering, and business teams.
Compliance Frameworks
Deep knowledge of PCI DSS, SWIFT CSP, NIST CSF, ISO 27001, GDPR.