Information Security lead(security controls, risk assessment

2 weeks ago


bangalore, India Paradise Placement Consultancy Full time

Job Description:

Job Title: Infosec Lead Department: IT
Level/Designation Manager/Sr. Manager Position Type: Full Time Job Overview
This role is responsible for implementing processes such as GRC to automate and continuously monitor the information security controls, risks, etc. Evaluates the firm to ensure compliance with security standards and
relevance with industry security norms.
ROLE AND RESPONSIBILITIES Provide a bullet point list of the responsibilities and duties of this job. Implements security controls, risk assessment framework, and program that align to regulatory requirements, ensuring documented and sustainable compliance that aligns with business objectives. Implements processes, such as GRC (governance, risk and compliance), to automate and continuously monitor information security controls, exceptions, risks, testing. Develops reporting metrics, dashboards, and evidence artifacts. Evaluates risks and develops security standards, procedures, and controls to manage risks. Improves firm’s security positioning through process improvement, policy, automation, and the continuous evolution of capabilities. Defines and documents business process responsibilities and ownership of the controls in GRC tool. Schedules regular assessments and testing of effectiveness and efficiency of controls and creates GRC reports. Updates security controls and provides support to all stakeholders on security controls covering internal assessments, regulations, protecting personal and client data assets. Performs and investigates internal and external information security risk and exceptions assessments. Assess incidents, vulnerability management, scans, patching status, secure baselines, penetration test result, phishing, and social engineering tests and attacks. Documents and reports control failures and gaps to stakeholders. Provides remediation guidance and prepares management reports to track remediation activities. Assists other staff in the management and oversight of security program functions. Trains, guides, and acts as a resource on security assessment functions to other departments within the firm. Remains current on best practices and technological advancements and acts as the firm’s resource for security assessment and regulatory compliance. QUALIFICATIONS AND EDUCATION REQUIREMENTS
Provide a bullet point list of the qualifications that are necessary for someone at this position. • EDUCATION LEVEL
BE/ Btech / MCA/ Graduation in computer science or similar stream
• EXPERIENCE
 10-12 years relevant experience
? Knowledge of –
1. Applicable information security certification, management, governance, and compliance principles, practices, laws, rules, and regulations
2. Information technology systems and processes, network infrastructure, data architecture, data processes, and protocols
3. Cyber and cloud security standard frameworks, architecture, design, operations, controls, technology, solutions, and service orchestration
4. Information systems auditing, monitoring, controlling, and assessment process
5. Risk assessment, Incident response and management methodology.
• SPECIFIC SKILLS-
Developing and implementing enterprise governance, risk, and compliance strategy and solutions
Researching and locating information related to internal and external organizations using online and other sources
Security project management and planning while maintaining confidentiality
Working with diverse academic and cultural ethnic backgrounds of retainer, staff, consultant, third party providers
• PERSONAL CHARACTERISTICS-
Work independently and prioritize multiple tasks and adapt to needed changes
Effectively communicate technical issues to diverse audiences, both in writing and verbally
Apply a risk-based approach to planning, executing, and reporting on audit engagements and auditing process
Evaluate and update and/or revise program materials. Handle sensitive and confidential matters, situations, and data. Understand and follow broad and complex instructions
Interact positively with users, firm management, vendor, and regulatory agencies in order to enhance effectiveness and to promote quality service
Comprehend technical language and to confer, analyze and write in an objective, lucid manner.
Remain calm under high pressure/difficult situations.
• CERTIFICATIONS
CISA, CISM, ISO 27001 certification, desired • LICENSES
None

Key Skills :

Management Governance Security Controls Risk Assessment Security Lead Risk Assessment Framework Implementation Of Security Controls Grc

  • bangalore, India Paradise Placement Consultancy Full time

    Job Description: Job Title: Infosec Lead Department: IT Level/Designation Manager/Sr. Manager Position Type: Full Time Job Overview This role is responsible for implementing processes such as GRC to automate and continuously monitor the information security controls, risks, etc. Evaluates the firm to ensure compliance with security...


  • bangalore, India AMEX Full time

    You Lead the Way. Weve Got Your Back. With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, youll learn and grow as we help you create a...


  • bangalore, India American Express Full time

    You Lead the Way. We’ve Got Your Back. With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, you’ll learn and grow as we help you...


  • bangalore, India RSA Security Full time

    RSA - Application Security Engineer Location: Remote India RSA offers mission-driven security solutions that provide organizations with a unified approach to managing digital risk that hinges on integrated visibility, automated insights and coordinated actions. RSA solutions are designed to effectively detect and respond to advanced attacks;...


  • bangalore, India RSA Security Full time

    RSA - Application Security Engineer Location: Remote India RSA offers mission-driven security solutions that provide organizations with a unified approach to managing digital risk that hinges on integrated visibility, automated insights and coordinated actions. RSA solutions are designed to effectively detect and respond to advanced attacks;...


  • bangalore, India Take-Two Interactive Software Full time

    About the Position Job Title:  Information Security Risk Analyst Who We Are: Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and commercially...


  • bangalore, India Take-Two Interactive Software Full time

    About the Position Job Title:  Information Security Risk Analyst Who We Are: Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and commercially...


  • bangalore, India Take-Two Interactive Software Full time

    About the Position Job Title:  Information Security Risk Analyst Who We Are: Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and commercially...


  • bangalore, India Take-Two Interactive Software Full time

    About the Position Job Title:  Information Security Risk Analyst Who We Are: Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and commercially...


  • bangalore, India IT Full time

    Job Overview :We are looking for an experienced IT Security Analyst with a strong background in vendor risk assessments, gap assessments, and information security audits. The ideal candidate will have at least 4 years of IT security experience and possess excellent communication skills. This role requires a proactive approach to identifying and mitigating...


  • bangalore, India IT Full time

    Job Overview :We are looking for an experienced IT Security Analyst with a strong background in vendor risk assessments, gap assessments, and information security audits. The ideal candidate will have at least 4 years of IT security experience and possess excellent communication skills. This role requires a proactive approach to identifying and mitigating...


  • Bangalore, India IT Full time

    Job Overview :We are looking for an experienced IT Security Analyst with a strong background in vendor risk assessments, gap assessments, and information security audits. The ideal candidate will have at least 4 years of IT security experience and possess excellent communication skills. This role requires a proactive approach to identifying and mitigating...


  • Bangalore, Karnataka, India IT Full time

    Job Overview :We are looking for an experienced IT Security Analyst with a strong background in vendor risk assessments, gap assessments, and information security audits. The ideal candidate will have at least 4 years of IT security experience and possess excellent communication skills. This role requires a proactive approach to identifying and mitigating...


  • Bangalore, Karnataka, India IT Full time

    Job Overview :We are looking for an experienced IT Security Analyst with a strong background in vendor risk assessments, gap assessments, and information security audits. The ideal candidate will have at least 4 years of IT security experience and possess excellent communication skills. This role requires a proactive approach to identifying and mitigating...


  • Bangalore, India IT Full time

    Job Overview :We are looking for an experienced IT Security Analyst with a strong background in vendor risk assessments, gap assessments, and information security audits. The ideal candidate will have at least 4 years of IT security experience and possess excellent communication skills. This role requires a proactive approach to identifying and mitigating...


  • Bangalore, India Jwalpa Tech Services Full time

    Direct Responsibilities : - Prioritize and schedule security control assessments performed by application security team.- Use the collected information from different security assessments following application security criticality/profile (GSF, ASCR controls) to remediate non-compliance.- Use the collected information from different security tests/audits...


  • bangalore, India Whatfix Full time

    Position Summary: The Security Compliance Specialist is responsible for managing all compliance related activities within the Whatfix platform and supporting other global compliance related initiatives. Compliance activities will include coordinating internal and external assessments/audits, contributing to policy and standards updates, developing...


  • bangalore, India Whatfix Full time

    Position Summary: The Security Compliance Specialist is responsible for managing all compliance related activities within the Whatfix platform and supporting other global compliance related initiatives. Compliance activities will include coordinating internal and external assessments/audits, contributing to policy and standards updates, developing...


  • bangalore, India Take-Two Interactive Software Full time

    About the Position Job Title: Team Lead- Information Security Risk Management Who We Are: Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and...


  • bangalore, India Take-Two Interactive Software Full time

    About the Position Job Title: Team Lead- Information Security Risk Management Who We Are: Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and...