Security Risk and Regulatory Tech Compliance

KreditBee

Bengaluru

On-site

INR 1,000,000 - 1,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading company is seeking an InfoSec Governance and Compliance specialist to manage their security frameworks and ensure adherence to regulatory standards. With a focus on cloud security involving AWS and GCP, the ideal candidate will have 4-6 years of experience with a background in engineering. Responsibilities include developing policies, training staff, and monitoring compliance with industry standards and regulations.

Qualifications

  • 4-6 years of experience in establishing & managing InfoSec Governance.
  • Knowledge of ISO27001 and regulatory guidelines.
  • Experience in cloud security, especially AWS & GCP.

Responsibilities

  • Ensure compliance with regulatory requirements.
  • Develop InfoSec policies and training programs.
  • Monitor and track compliance processes.

Skills

Regulatory compliance
InfoSec Policy development
Cloud Security
Compliance Management
Analytical skills
Communication skills
Security metrics establishment

Education

Bachelor of Engineering/Computer Science

Job description

Roles and Responsibilities:

  • Ensure Compliance with the Regulatory requirements w.r.t the Information and Cyber Security requirements - RBI, UIDAI, CIC, etc.
  • Identify and develop the InfoSec Policy, Processes, and Procedures to incorporate the industry benchmarks / best practices and the latest trends.
  • To identify, track, monitor & ensure compliance with InfoSec Policy, Regulatory, Legal & Audit requirements.
  • To develop & manage InfoSec Training & awareness.
  • Work with respective stakeholders to ensure that the Policy/Procedures, regulatory, legal & audit requirements for Information and cyber security are understood and implemented on a continual basis.
  • Monitor & track the compliance to all relevant processes/practices to ensure that they are followed as desired.
  • Liaison with internal and external Security Audits and assessments – VAPT, GDPR/ISO 27001 compliance.
  • Establish continual improvement processes to mitigate identified gaps & improve overall maturityto provide adequate assurance.
  • Establish security metrics based on agreed KGIs/KPIs to monitor & track compliance.
  • Escalate deviations and violations on time.
  • Remain updated with the latest security trends and related regulatory & legal requirements.
  • To maintain the required security posture for cloud security, primarily AWS & GCP
  • To maintain & improve code security & DevopsSec practices
  • To maintain & improve the endpoint security, by bringing in DLP and data classification practices.
  • To review and improve email, apps & network security.
  • To run periodic phishing campaigns.
  • To respond third-party risk assessment questionnaire
  • Perform Independent Internal Audit and assessment in line with Regulatory requirements - RBI, UIDAI, CIC, V-CIP, DLG, etc.

Key Skills and Qualifications

  • Bachelor of Engineering/Computer Science or equivalent from a recognized University
  • The ability to interact efficiently with peers and customers is required.
  • 4-6 years with relevant experience in establishing & managing InfoSec Governance and compliance.
  • Should have sound knowledge & experience in developing Enterprise Frameworks, Policies, and Processes by adopting Industry Best Practices and standards like ISO27001, and Regulatory Guidelines.
  • Should have strong analytical and communication skills.
  • Should have sound knowledge, experience & understanding of Compliance Management.
  • Should have the ability to develop and effectively measure, and present Dashboard/reports with or without GRC tools.
  • Should have experience in developing InfoSec awareness programs and rendering InfoSec awareness sessions.
  • An individual with 2-3 years of IT experience in Cloud Security would be preferred.
  • Candidates with professional security certificates like CISA, CISM, and ISO27001 Lead Auditor would be preferred.
  • A good understanding of cloud security, AWS, and GCP is a must to have.
  • A good understanding of the Data Privacy Framework - GDPR, India Data Privacy Act, etc.
Note: Looking for Immediate Joiner/30 days
Work Mode: Work at office only(No Hybrid/WFH)
Experience: 1- 6 years
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Analyst-(Risk and Regulatory Tech Complainance)
Senior Information Security Analyst-(Risk and Regulatory Tech Complainance)

KreditBee • Bengaluru

On-site
INR 800,000 - 1,500,000
Cloud Security and GRC Engineer (Compliance/ Security Architecture)
Cloud Security and GRC Engineer (Compliance/ Security Architecture)

PeopleGene • Pune District

On-site
INR 1,000,000 - 1,500,000
Cyber Security Specialist
Cyber Security Specialist

Getinz Techno Services • Bengaluru

On-site
INR 2,500,000 - 4,200,000
IT Compliance Lead
IT Compliance Lead

Mobileum • Bengaluru

Hybrid
INR 2,500,000 - 4,000,000
AVP Information Security
AVP Information Security

JITO • Mumbai

On-site
INR 4,500,000 - 7,000,000
AVP Information Security
AVP Information Security

Jain International Trade Organisation - India • Mumbai

On-site
INR 3,000,000 - 4,500,000
Module Lead Information Security
Module Lead Information Security

IDfy • Mumbai

On-site
INR 4,000,000 - 7,000,000
Cybersecurity Specialist – Governance, Risk & Compliance (GRC)
Cybersecurity Specialist – Governance, Risk & Compliance (GRC)

TalaKunchi Networks Pvt Ltd • Mumbai

On-site
INR 800,000 - 1,200,000
Opportunity to shape InfoSec practices
Work on cutting-edge cybersecurity initiatives
Be part of a forward-thinking team
Cloud Security Professional
Cloud Security Professional

Golden Opportunities • Bengaluru, Chennai District

On-site
INR 1,500,000 - 2,800,000
Health insurance
Retirement benefits
Paid time off
Security Architect
Security Architect

Skillventory • Mumbai

On-site
INR 4,000,000 - 7,000,000