Infosec GRC Associate II

Zeta

Bengaluru

On-site

INR 800,000 - 1,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading technology firm in India is seeking a Sr. Associate for its Information Security Process and Compliance Team. The role involves assessing IT architecture for PCI compliance and developing Vendor Risk Management programs. Candidates should have 3-5 years of experience in information security and hold a relevant bachelor's degree. Strong understanding of PCI DSS auditing and excellent communication skills are essential. The company promotes diversity and is committed to an inclusive work environment.

Qualifications

  • 3 – 5 years of experience in information security and compliance.
  • Hands-on experience with PCI DSS and various audits.
  • Strong communication skills, both written and verbal.

Responsibilities

  • Assess IT architecture for PCI control compliance.
  • Conduct gap analysis against PCI DSS standards.
  • Develop Vendor Risk Management programs.
  • Facilitate Client Due Diligence and RFP responses.

Skills

Technology risk assessment frameworks
PCI DSS compliance
Experience in banking/payment sector
ISMS, SSAE 18, ISO 27001
CISA, CISM, CISSP certifications
Vendor risk assessment
Technical documentation

Education

Bachelor of Technology (BE/B.Tech), M.Tech or ME in Computer Science, MCA or equivalent

Job description

The Role:
This role is part of the Information Security Process and Compliance Team of Zeta. The Sr. Associate of InfoSec Audit and compliance is responsible for preparing and supporting PCI DSS, ISO 27001 and SOC external Audits. Actively participate, strengthen and improve Internal Audit process and provide assurance on internal technology and process compliance. Collaborate with the Cloud and Product security team to drive risk and compliance goals.
Responsibilities
  • Work with internal and external stakeholders to assess the IT architecture or proposed IT architecture solutions to identify the risk areas with regards to PCI controls.
  • Assess the network architecture and review the firewall rulesets, network devices/appliances to see if they are aligned with the PCI control requirements and recommend compensatory controls where necessary.
  • Execute operational activities to support audit and compliance activities including technical validation processes.
  • Conduct PCI DSS scoping engagements, gap analysis and assessments related to securing the Cardholder Data Environment.
  • Effectively multi‑task on multiple assignments and deliverables.
  • Actively accepts individual and team responsibilities to meet commitments. Takes responsibility for own performance and actions and demonstrates responsibility and teamwork towards overall team/department goals.
  • Discuss the SOP document with all relevant stakeholders – right from process owner to the BU functional heads. Thorough understanding of SOC reports (SOC2, Type 1, 2), ISMS reports and ability to relate the IT General Controls, IT Application Controls, Cyber Controls to the SOC framework.
  • Develop and maintain Vendor Risk Management / Third Party Risk Management Program including Vendor Onboarding Audit, Periodic Vendor Assessment, and maintain TPRM database.
  • Review and implement controls and policies as per RBI and other regulatory requirements. Maintain ISMS framework, evaluate effectiveness of implemented controls and provide recommendations for improvement.
  • Facilitate Client Due Diligence in collaboration with Business.
  • Develop and maintain Enterprise Risk Assessment framework.
  • Perform internal assessment against various standards to ensure the established policies are being followed and prepare internal reports.
  • Contract review and providing responses to client Request for Proposal (RFP).
Skills
  • Good understanding of technology risk assessment frameworks and application risk assessment.
  • Good understanding and hands‑on experience on PCI DSS standard and various PCI compliance.
  • Experience of working in the banking or payment sector is preferred.
  • Hands‑on experience with various audits and standards such as ISMS, SSAE 18, ISO 27001, ISO 31000, ISO 22301, CSA Star, NIST risk framework, PCI DSS, PCI 3DS, PCI PA‑DSS/SSF, PCI S3, etc.
  • Good to have information security certifications like CISA, CISM, CISSP, etc.
  • Experience of vendor risk assessment and responding to client Request for Proposal (RFP).
  • Excellent written and oral communication and penchant for technical documentation.
Experience and Qualifications
  • 3 – 5 years of experience in information security and compliance in medium to large‑sized companies.
  • Bachelor of Technology (BE/B.Tech), M.Tech or ME in Computer Science, MCA or equivalent.

Zeta is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We encourage applicants from all backgrounds, cultures, and communities to apply and believe that a diverse workforce is key to our success.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Infosec Grc Associate Ii
Infosec Grc Associate Ii

Zeta • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Cybersecurity GRC Consultant(PCI DSS)
Cybersecurity GRC Consultant(PCI DSS)

Atos SE • Mumbai

On-site
INR 1,500,000 - 2,200,000
Corporate Risk and Compliance - Associate II
Corporate Risk and Compliance - Associate II

Zeta • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Diversity and inclusivity initiatives
Professional development opportunities
Senior Security GRC Analyst
Senior Security GRC Analyst

Kite • Gurugram District

On-site
INR 1,500,000 - 2,300,000
PCI-DSS Consultant
PCI-DSS Consultant

Riskpro India Ventures • Bengaluru

On-site
INR 1,000,000 - 1,500,000
PCI DSS Auditor
PCI DSS Auditor

Keka Technologies • Bengaluru

On-site
INR 1,500,000 - 2,300,000
Technical Lead
Technical Lead

The Hartford India • Hyderabad

On-site
INR 1,500,000 - 2,000,000
Competitive salary
Comprehensive benefits
Continuous learning opportunities
+1
Security Compliance Analyst
Security Compliance Analyst

Captalent Hr • Indore District, Gurugram District, Mumbai

Hybrid
INR 1,800,000 - 2,800,000
Infosec Analyst
Infosec Analyst

super.money • Bengaluru

On-site
INR 900,000 - 1,500,000
Competitive compensation
Shape GRC for a top UPI company in I
PCI DSS Auditor
PCI DSS Auditor

Sisainfosec • Bengaluru

On-site
INR 900,000 - 1,500,000