LyondellBasell | Application Controls Security Principal

7 days ago


india LyondellBasell Full time

Basic Function:

An Application Controls Principal plays a vital role in managing the complex organization, execution, and optimization of the organization's SAP and non-SAP security controls.

An Application Controls Principal must lead a team that has primary responsibility for end-to-end controls monitoring, validation, quality assurance, and improvement activities. In addition to the Application Controls Principal leading a dedicated IT Operations-based team, this role must act as a primary point of contact for all IT controls activities and be accountable to the Internal Controls, Governance/Risk/Compliance, Audit departments, and Senior Leadership.

This role will develop long-term strategies in partnership with Control Owners for controls execution and prioritize the team’s activities to ensure zero deficiencies in internal and external testing scenarios. This role will have ultimate responsibility for the remediation of areas of risk and is responsible for communicating status of IT controls, audit findings, remediation efforts, and long-term plans to senior leadership on a recurring basis.

This role requires intensive collaboration to ensure successful execution of all continuous and periodic control activities.


Roles & Responsibilities:

  • Accountable for the IT controls program direction and influence, including overarching IT controls approach (defining controls, rewriting as necessary, launching renewed IT controls execution, etc.).
  • Accountable for aligning non-SAP and SAP controls approach, harmonizing control automations, process efficiencies, and overall controls simplicity.
  • Accountable for all IT controls activities including monitoring, validation, quality assurance, and improvement activities.Champion adoption of comprehensive application security processes, procedures, and guidelines, ensuring adherence to security best practices.
  • Oversee the development of systems and integrations to drive greater automation and remove areas of human error.
  • Act as Subject Matter Expert on all IT controls with internal and external auditors during IT audits.
  • Regularly assess the program for effectiveness – continuously monitor defined metrics and indicators and quickly adapt to changing requirements.
  • Operationalize team activities to be able to scale with changing IT controls requirements (additional SOx-relevant applications, systems, etc.).
  • Prepare regular reports on team outcomes and initiatives for senior leadership or enterprise-wide distribution.
  • Review existing processes and product architectures for IT control security design gaps and vulnerabilities and consult with product teams and cyber security to remediate or mitigate cyber risk.
  • Provide strategic oversight to remediations proposed, influencing the technical direction of IT controls improvements.
  • Provide strategic leadership and creative thinking to help various technical delivery teams through the project lifecycle.
  • Manage a team of resources who proactively monitor IT security controls (data validation, authorization, encryption, audit logging, etc.) for key applications (on-premises and cloud-based) to identify weaknesses and potential vulnerabilities.
  • Organize competing priorities amongst security alerts and application security control deficiencies, recommending and implementing corrective actions.


Qualifications:

  • Bachelor's degree in Information Technology, Computer Science, or a related field (preferred).
  • 7+ years of experience in IT security controls analysis, IT audit, or a similar role.
  • Expert knowledge of IT security controls and best practices (data validation, authorization, encryption, audit logging, etc.).
  • Proven experience in identifying, analyzing, and remediating non-SAP control deficiencies.
  • In-depth understanding of security concepts, including authorization, segregation of duties, and user access review management
  • Experience with tools such as ServiceNow or security tools and technologies used for control monitoring and analysis
  • Understanding of cloud security concepts and technologies and on-prem technologies
  • SOX knowledge, in addition to experience of implementing/auditing against US SOx IT framework control.
  • 3 years of experience supporting software security governance and compliance activities, i.e. metrics, assessments, audits, exercises, risk frameworks, and maturity models
  • Experience leading a team of resources and prioritizing complex activities and outcomes
  • Identity and Access Management exposure
  • Application Security Principles and Best Practices exposure
  • Security Tools and Technologies exposure
  • Application cloud and on prem logic and data layer architecture, inc SQL, Oracle and Azure.


Desired Skills:

  • Experience with security automation tools and scripting languages (e.g., Python, PowerShell).
  • Experience with SharePoint and project management tools.
  • Familiarity with GAAP and financial reporting.


Soft Skills

  • Prioritization of complex activities
  • Process improvement mindset
  • Clear and effective communication, verbal and written
  • Effective leadership and coordination
  • Detailed and systematic thinking
  • Detailed troubleshooting skills
  • Issue resolution and risk mitigation
  • Commitment to follow standards


  • india LyondellBasell Full time

    Basic Function: An Application Controls Principal plays a vital role in managing the complex organization, execution, and optimization of the organization's SAP and non-SAP security controls. An Application Controls Principal must lead a team that has primary responsibility for end-to-end controls monitoring, validation, quality assurance, and improvement...


  • india LyondellBasell Full time

    Basic Function:An Controls Specialist plays a vital role in safeguarding the organization's IT infrastructure by ensuring the effectiveness of security controls. Ensure efficiency and monitor the IT security controls (Data Validation, Authorization Controls, Data Encryption, Audit Logging and Monitoring etc) of our applications (on prem and cloud based),...


  • india LyondellBasell Full time

    Basic Function: An Controls Specialist plays a vital role in safeguarding the organization's IT infrastructure by ensuring the effectiveness of security controls. Ensure efficiency and monitor the IT security controls (Data Validation, Authorization Controls, Data Encryption, Audit Logging and Monitoring etc) of our applications (on prem and cloud based),...


  • india LyondellBasell Full time

    Basic Function: As one of the key members of the site management team, HR Officer is expected to provide advice to local management teams of the manufacturing site on people decisions, facilitate change management, talent development, and performance management processes, partner with the site manager in leading employee communications at local site level,...


  • india Elger Controls Full time

    Company Description Elger Controls India Pvt Ltd, located in Coimbatore, specializes in manufacturing electric and pneumatic actuators and accessories for valves and dampers. The company is known for its expertise in valve and damper automation, providing tailored solutions for various applications. Elger Controls offers a wide range of Electric and...


  • india Elger Controls Full time

    Company DescriptionElger Controls India Pvt Ltd, located in Coimbatore, specializes in manufacturing electric and pneumatic actuators and accessories for valves and dampers. The company is known for its expertise in valve and damper automation, providing tailored solutions for various applications. Elger Controls offers a wide range of Electric and Pneumatic...


  • Pune, Maharashtra, India Johnson Controls Full time

    What you will doOpen Blue Edge Computing Platform group is playing a key part in realizing the promise of our digital transformation initiative – Open Blue. This group focuses on technologies like edge computing, smart solutions and running ML Model at the edge with constrained resources in the most optimized way.Principal Platform Engineer position will...


  • india RSI Security Full time

    Location: 100% Remote Type: Contractor - Part Time, Project based Pay: Based on experience, education, geographic location, and market rates. Travel: None *** Please ensure you read through the entire job posting and you also understand the work model, expectations, requirements, location, and qualification requirements for this role. *** About Us: RSI...


  • india RSI Security Full time

    Location: 100% RemoteType: Contractor - Part Time, Project basedPay: Based on experience, education, geographic location, and market rates.Travel: None*** Please ensure you read through the entire job posting and you also understand the work model, expectations, requirements, location, and qualification requirements for this role. ***About Us:RSI Security is...

  • Principal Engineer/SME

    2 months ago


    Pune, Maharashtra, India Johnson Controls Full time

    Build your best future with the Johnson Controls teamAs a global leader in smart, healthy and sustainable buildings, our mission is to reimagine the performance of buildings to serve people, places and the planet. Join a winning team that enables you to build your best future! Our teams are uniquely positioned to support a multitude of industries across the...


  • India KMM Technologies, Inc. Full time

    KMM Technologies, Inc. is a rapidly growing company seeking a highly skilled Principal Cybersecurity Architect to join its team.As a Principal Cybersecurity Architect at KMM Technologies, Inc., you will play a key role in designing and implementing secure solutions for our applications.The estimated salary for this position ranges from $120,000 to $180,000...


  • India Sutherland Full time

    Title: Principal Cybersecurity Architect & Security Engineering Leader Level: AVP Location: India preferably Chennai, Mumbai or Hyderabad based (Also open to Remote/Hybrid working) Reports to: Global Head of Information Security, Privacy and Business Continuity Position Summary: Job Description: The Principal Cybersecurity Architect &...


  • Mumbai, Maharashtra, India Johnson Controls Full time

    Build your best future with the Johnson Controls teamAs a global leader in smart, healthy and sustainable buildings, our mission is to reimagine the performance of buildings to serve people, places and the planet. Join a winning team that enables you to build your best future! Our teams are uniquely positioned to support a multitude of industries across the...


  • india TAC Security Full time

    As a Full Stack Developer specializing in security products, you will play a key role in the development and enhancement of our cybersecurity solutions. Based in Aerocity Delhi, India, you will work closely with cross-functional teams to design, develop, and maintain secure and scalable software applications. Your expertise in full stack development,...


  • India MAX Security Full time

    About MAX SecurityMAX Security is a leading global risk management organization with operations in 160 countries. Our team of experts provides Fortune 500 organizations with tailored security solutions to enable business continuity in challenging environments.Job SummaryWe are seeking an experienced Global Security Operations Specialist to join our 24/7...


  • India Sutherland Full time

    Title: Principal Cybersecurity Architect & Security Engineering LeaderLevel: AVPLocation: India preferably Chennai, Mumbai or Hyderabad based (Also open to Remote/Hybrid working) Reports to: Global Head of Information Security, Privacy and Business Continuity Position Summary:Job Description:The Principal Cybersecurity Architect & Security Engineering Leader...


  • India MAX Security Full time

    Company Profile:Max is Global Risk Management organization based out in Tel Aviv, Israel and its APAC HQ is based out of Mumbai. Led by veterans from Israeli Military Special Forces, Intelligence, Cyber and Secret Services we operate in 160 countries across the globe. We have capabilities in every continent across the world and carry the experience of 25 +...


  • India MAX Security Full time

    Company Profile: Max is Global Risk Management organization based out in Tel Aviv, Israel and its APAC HQ is based out of Mumbai. Led by veterans from Israeli Military Special Forces, Intelligence, Cyber and Secret Services we operate in 160 countries across the globe. We have capabilities in every continent across the world and carry the experience of...


  • India MAX Security Full time

    Company Profile: Max is Global Risk Management organization based out in Tel Aviv, Israel and its APAC HQ is based out of Mumbai. Led by veterans from Israeli Military Special Forces, Intelligence, Cyber and Secret Services we operate in 160 countries across the globe. We have capabilities in every continent across the world and carry the experience of 25...


  • India Claranet India Full time

    About The Role Our consultants work on everything from client projects to development work and training, dealing with large corporate penetration tests to gaining credit for published advisories. Technical excellence and customer service are key to our work, you will be passionate about finding vulnerabilities while being happy liaising with customers. Our...