Information Security lead(security controls, risk assessment

4 weeks ago


bangalore, India Paradise Placement Consultancy Full time

Job Description:

Job Title: Infosec Lead Department: IT
Level/Designation Manager/Sr. Manager Position Type: Full Time Job Overview
This role is responsible for implementing processes such as GRC to automate and continuously monitor the information security controls, risks, etc. Evaluates the firm to ensure compliance with security standards and
relevance with industry security norms.
ROLE AND RESPONSIBILITIES Provide a bullet point list of the responsibilities and duties of this job. Implements security controls, risk assessment framework, and program that align to regulatory requirements, ensuring documented and sustainable compliance that aligns with business objectives. Implements processes, such as GRC (governance, risk and compliance), to automate and continuously monitor information security controls, exceptions, risks, testing. Develops reporting metrics, dashboards, and evidence artifacts. Evaluates risks and develops security standards, procedures, and controls to manage risks. Improves firm’s security positioning through process improvement, policy, automation, and the continuous evolution of capabilities. Defines and documents business process responsibilities and ownership of the controls in GRC tool. Schedules regular assessments and testing of effectiveness and efficiency of controls and creates GRC reports. Updates security controls and provides support to all stakeholders on security controls covering internal assessments, regulations, protecting personal and client data assets. Performs and investigates internal and external information security risk and exceptions assessments. Assess incidents, vulnerability management, scans, patching status, secure baselines, penetration test result, phishing, and social engineering tests and attacks. Documents and reports control failures and gaps to stakeholders. Provides remediation guidance and prepares management reports to track remediation activities. Assists other staff in the management and oversight of security program functions. Trains, guides, and acts as a resource on security assessment functions to other departments within the firm. Remains current on best practices and technological advancements and acts as the firm’s resource for security assessment and regulatory compliance. QUALIFICATIONS AND EDUCATION REQUIREMENTS
Provide a bullet point list of the qualifications that are necessary for someone at this position. • EDUCATION LEVEL
BE/ Btech / MCA/ Graduation in computer science or similar stream
• EXPERIENCE
 10-12 years relevant experience
? Knowledge of –
1. Applicable information security certification, management, governance, and compliance principles, practices, laws, rules, and regulations
2. Information technology systems and processes, network infrastructure, data architecture, data processes, and protocols
3. Cyber and cloud security standard frameworks, architecture, design, operations, controls, technology, solutions, and service orchestration
4. Information systems auditing, monitoring, controlling, and assessment process
5. Risk assessment, Incident response and management methodology.
• SPECIFIC SKILLS-
Developing and implementing enterprise governance, risk, and compliance strategy and solutions
Researching and locating information related to internal and external organizations using online and other sources
Security project management and planning while maintaining confidentiality
Working with diverse academic and cultural ethnic backgrounds of retainer, staff, consultant, third party providers
• PERSONAL CHARACTERISTICS-
Work independently and prioritize multiple tasks and adapt to needed changes
Effectively communicate technical issues to diverse audiences, both in writing and verbally
Apply a risk-based approach to planning, executing, and reporting on audit engagements and auditing process
Evaluate and update and/or revise program materials. Handle sensitive and confidential matters, situations, and data. Understand and follow broad and complex instructions
Interact positively with users, firm management, vendor, and regulatory agencies in order to enhance effectiveness and to promote quality service
Comprehend technical language and to confer, analyze and write in an objective, lucid manner.
Remain calm under high pressure/difficult situations.
• CERTIFICATIONS
CISA, CISM, ISO 27001 certification, desired • LICENSES
None

Key Skills :

Management Governance Security Controls Risk Assessment Security Lead Risk Assessment Framework Implementation Of Security Controls Grc
  • Risk Assessments

    1 week ago


    bangalore, India CrossRoad Solution Full time

    As a part of the Operational Risk Governance Group (ORGG) Process Risk Self-Assessment (PRSA) Program within Global Risk & Compliance, you will contribute to developing and maintaining a global  internal control framework and governing standards,  capabilities, and risk assessment methodologies. Within the second line of defense, you provide effective...

  • Risk Assessments

    1 week ago


    bangalore, India CrossRoad Solution Full time

    As a part of the Operational Risk Governance Group (ORGG) Process Risk Self-Assessment (PRSA) Program within Global Risk & Compliance, you will contribute to developing and maintaining a global internal control framework and governing standards, capabilities, and risk assessment methodologies. Within the second line of defense, you provide effective...


  • bangalore, India IT Full time

    Job Overview :We are looking for an experienced IT Security Analyst with a strong background in vendor risk assessments, gap assessments, and information security audits. The ideal candidate will have at least 4 years of IT security experience and possess excellent communication skills. This role requires a proactive approach to identifying and mitigating...


  • Bangalore, Karnataka, India IT Full time

    Job Overview :We are looking for an experienced IT Security Analyst with a strong background in vendor risk assessments, gap assessments, and information security audits. The ideal candidate will have at least 4 years of IT security experience and possess excellent communication skills. This role requires a proactive approach to identifying and mitigating...


  • Bangalore, India IT Full time

    Job Overview :We are looking for an experienced IT Security Analyst with a strong background in vendor risk assessments, gap assessments, and information security audits. The ideal candidate will have at least 4 years of IT security experience and possess excellent communication skills. This role requires a proactive approach to identifying and mitigating...

  • Information Security

    4 weeks ago


    bangalore, India Nityo Infotech Full time

    Auditing , Communication , English , Hiring , Interviewing , Leadership , Management , Newsletters , Risk Management , Risk Assessment , Testing , Ability , Activities , Adaptability , Address , Administrative , Analysis , Annual , Assessment , Associates , Auditing , Author , Availability , Awareness , Bangalore , Basis , Blogs , Bulletins , Business , CISA...


  • bangalore, India IntraEdge Full time

    Amex: Event Manager - Information Security - Bengaluru (Upendra)Information Security Managers know security is a top priority for our business, our partners, and customers. As cyber-attacks increase and compliance is rigorously implemented, they strive to stay ahead of what’s next to protect our brand and future. The IT Risk Assessment & Operational Risk...

  • Information Security

    4 weeks ago


    bangalore, India Nityo Infotech Full time

    Auditing , Communication , English , Management , Risk Management , Training , Testing , Ability , Activities , Adaptability , Administrative , Application , Application Security , Auditing , Awareness , Business , Business Continuity , Business Continuity Planning , CISA , CISSP , Certifications , Change , Client , Cloud , Cloud Security , Communication ,...


  • Bangalore, Karnataka, India Navi Full time

    Job description :About the role :Navi is looking for an Associate Information Security to be part of the information security program at the Group Level ensuring cybersecurity compliance to the requirements put forth by regulators - RBI, IRDAI & SEBI.Key responsibilities :As Navi operates in the regulatory space, this role requires interpreting and helping...


  • Bangalore, India Navi Full time

    Job description :About the role :Navi is looking for an Associate Information Security to be part of the information security program at the Group Level ensuring cybersecurity compliance to the requirements put forth by regulators - RBI, IRDAI & SEBI.Key responsibilities :As Navi operates in the regulatory space, this role requires interpreting and helping...

  • Compliance Manager

    3 weeks ago


    bangalore, India LeadSquared Full time

    Location: BangaloreReports to: Director - ITPosition Overview: As an Information Security Compliance Manager at LeadSquared, you will play a critical role in overseeing and maintaining our information security compliance program. The ideal candidate will have at least 8 years of hands-on experience in managing compliance with ISO 27001, SOC 2, and HIPAA...


  • Bangalore City, India Movate Full time

    Hello NetworkWe are at Movate Technologies, Looking for an Information Security ManagerJob Title: Information Security ManagerExperience: 8+ yearsLocation: Bangalore/Hyderabad/ChennaiWork from OfficeNo.Of Positions: 2Top 5 Skill SetHands-on experience with security technologiesExperience in Information security and business continuity internal auditsStrong...


  • Bangalore, India One Degree North HR Services Full time

    Job Description Profile : Information Security Consultant. Experience : 6+ years. Location : Banglore. Essential Skills : - Security incident investigation, Infosec Controls Physical, Admin, Technical, Security Report Writing, Security. - Engineering, Network Security, Security Process Flow, Verbal & written Communication. Desirable Skills : -...


  • Bangalore, Karnataka, India Connectio IT Pvt Ltd Full time

    Role & Responsibilities: - Lead the development, implementation, and maintenance of the company's ISMS based on the ISO 27001 framework.- Conduct regular risk assessments to identify and prioritize security threats and vulnerabilities.- Develop and implement security policies, procedures, and standards to mitigate identified risks.- Manage and maintain...


  • Bangalore, India Connectio IT Pvt Ltd Full time

    Role & Responsibilities: - Lead the development, implementation, and maintenance of the company's ISMS based on the ISO 27001 framework.- Conduct regular risk assessments to identify and prioritize security threats and vulnerabilities.- Develop and implement security policies, procedures, and standards to mitigate identified risks.- Manage and maintain...


  • bangalore, India Connectio IT Pvt Ltd Full time

    Role & Responsibilities: - Lead the development, implementation, and maintenance of the company's ISMS based on the ISO 27001 framework.- Conduct regular risk assessments to identify and prioritize security threats and vulnerabilities.- Develop and implement security policies, procedures, and standards to mitigate identified risks.- Manage and maintain the...


  • bangalore, India Société Générale Assurances Full time

    Information & Cyber Security Lead Expert Permanent contract|Bangalore|Risks Information & Cyber Security Lead Expert Bangalore, India Permanent contract Risks Responsibilities · Support Risk Management and Supervision team (RMS) in charge of assessing the risk profile and the effectiveness of the information security...


  • bangalore, India Rubrik Full time

    Job Summary Information Security - Who We Are The Information Security (InfoSec) organization advances the overall state of security at Rubrik through critical initiatives and coordination of large security projects. Information Security builds technologies, tools, and processes to better enable teams at Rubrik to develop secure software and...


  • bangalore, India PHH Mortgage Full time

    POSITION SUMMARY:   Team Lead, Information Security This position will give an opportunity to work for Information Security Governance on information systems, processes and technologies within the organization. This is a global role engaging stakeholders (at all levels) across geographies like India, Philippines and US This position will...


  • bangalore, India Unacademy Full time

    Headquartered in Bengaluru, Unacademy is Indiaʼs largest learning platform that brings expert educators together with millions of students in need of quality education. With a growing network of thousands of registered educators and Millions of learners, Unacademy is changing the way India learns. With a mission to democratize education, Unacademy has been...