Senior Information Security Compliance Lead

3 days ago


Bengaluru, Karnataka, India Whatfix Full time

We are seeking a highly skilled Senior Information Security Compliance Lead to join our team at Whatfix.

The estimated salary for this role is $120,000 - $180,000 per year, depending on location and experience.

Job Description:

As a Senior Information Security Compliance Lead, you will be responsible for managing all compliance related activities within the Whatfix platform and supporting other global compliance related initiatives.

You will coordinate internal and external assessments/audits, contribute to policy and standards updates, develop a compliance framework, and produce compliance reports, metrics, scorecards, and dashboards.

This position requires some technical background with appropriate security training/skills.

Responsibilities:
  • Lead, manage, and improve the security compliance program for Whatfix
  • Coordinate external audits and customer assessments of the Whatfix platform
  • Develop a compliance strategy in alignment with business requirements, objectives, and metrics
  • Translate legal, statutory, and contractual obligations into a cohesive collection of processes and provide stakeholders with compliance requirements and methodologies
  • Interface with management and partner with groups such as Engineering, Operations, and Customer Success on how to best improve security compliance and reduce risk
  • Use key business measurements to identify and drive process improvement opportunities for compliance and risk management
  • Review and update security policies and standards on a regular basis to address new threats, industry practices, requirements, and standards based on security and compliance requirements
  • Coordinate regular system and network audits, reviews, and tests to verify compliance with security policies and standards
  • Conduct and/or interpret network, system, and application audits/assessments and track through to remediation
  • Monitor internal and external security advisories that impact security, risk, and compliance requirements
  • Support the implementation of security controls and recommend areas for risk reduction
  • Support RFP and contractual agreements process in assessing security requirements from potential customers
  • Develop and enhance an information security, risk, and compliance management framework based on CobIT/Risk IT, NIST, ISO, and CSA CCM/STAR, FEDRAMP
  • Manage updates to the external and internal security portals
  • Assist and improve the security awareness program
  • Assist and improve governance activities
  • Evaluate suspected security breaches, work with subject matter experts, and recommend corrective actions
Requirements:
  • At least 6-8+ years of experience in information security, compliance, audit, and/or risk management
  • End-to-end security experience including web, application, network, OS, and database
  • Knowledge of security issues, trends, best practices
  • Familiarity with audit, business, and segregation of duties, risks, and controls
  • Ability to foresee and identify mitigation strategies for risks
  • Knowledge in at least 2 of security industry standards such as SSAE18/SOC2, ISO 27001, PCI-DSS, NIST, and CSA CCM/STAR, FEDRAMP mandatory
  • Working knowledge in one or more privacy laws such as GLBA, HIPAA, GDPR, CCPA is important
  • Excellent communication and presentation skills
  • Ability to communicate well up to line management and also motivate technical teams
  • Ability to work autonomously with flexibility and excellent judgment
  • Ability to work effectively under pressure to meet deadlines
  • Ability to solve problems quickly and automate processes
  • Ability to work cooperatively as part of a team
Education:
  • Bachelor's degree in computer science, information technology, or other related major required
  • ISO 27001 Internal Auditor
  • CISM/CISA


  • Bengaluru, Karnataka, India Gainwell Technologies LLC Full time

    Job SummaryGainwell Technologies LLC seeks an experienced Information Security Compliance Lead to ensure the seamless integration and effective utilization of its diverse product portfolio. The successful candidate will work closely with internal teams and external stakeholders to understand product functionalities, address concerns, and optimize solutions...


  • Bengaluru, Karnataka, India Gainwell Technologies LLC Full time

    Job SummaryGainwell Technologies LLC is seeking an experienced Information Security Compliance Lead to join our team. As a key member of our organization, you will play a pivotal role in ensuring the seamless integration and effective utilization of our diverse product portfolio.Key ResponsibilitiesAs an Information Security Compliance Lead, you...


  • Bengaluru, Karnataka, India KreditBee Full time

    Job Title: Senior Information Security Governance Expert - Risk and Regulatory ComplianceAbout the Role:KreditBee seeks an experienced Senior Information Security Governance Expert to lead our risk and regulatory compliance efforts.Develop and maintain information security policies, procedures, and frameworks to ensure compliance with regulatory...


  • Bengaluru, Karnataka, India MNR Solutions Full time

    We are seeking a skilled Information Security Risk and Compliance professional to contribute to the security and compliance of MNR Solutions in Bangalore or Chennai. The ideal candidate will have a strong background in information security, risk management, and compliance frameworks.This role will focus on identifying, assessing, and mitigating security...


  • Bengaluru, Karnataka, India Information Dynamics Full time

    We are seeking a highly skilled Information Security Risk Manager to join our team at Information Dynamics. In this role, you will be responsible for conducting risk assessments on Applications, Network & Systems according to Client policies, applicable Standards, legal & regulatory requirements. Your expertise in Control testing, Control assessment, and...


  • Bengaluru, Karnataka, India Flipkart Full time

    About the Team:The Governance, Risk & Compliance team is a central part of the Information Security department, with primary responsibility to provide robust metrics, data-driven insights, and effective technologies for information security risk management. We aim to provide a structured approach to align information security with business objectives, while...


  • Bengaluru, Karnataka, India Information Dynamics Full time

    As a key member of the Information Dynamics team, you will play a vital role in ensuring the security and integrity of our IT systems and data. Your primary responsibility will be to conduct risk assessments on applications, networks, and systems to identify potential vulnerabilities and develop strategies to mitigate them.You will work closely with clients...


  • Bengaluru, Karnataka, India State Street Full time

    Job Overview:The ideal candidate will support the overall corporate information security compliance with State Street internal policies, external regulatory requirements, and client needs.As a key member of the Policy & Governance team, the individual will maintain the enterprise information security policies and processes required to ensure information...


  • Bengaluru, Karnataka, India Traceable AI Full time

    About this role:The Information Security Compliance Specialist plays a crucial part in maintaining the organization's security and compliance through effective governance, risk management, and compliance frameworks at Traceable AI.This position involves monitoring internal controls to maintain appropriate information access levels and security clearances....


  • Bengaluru, Karnataka, India Flipkart Full time

    About the TeamThe Governance, Risk, and Compliance (GRC) team is a crucial part of Flipkart's Information Security department. Their primary responsibility is to provide robust metrics, data-driven insights, and effective technologies for information security risk management. The team aims to align information security with business objectives, while...


  • Bengaluru, Karnataka, India American Express Full time

    About the RoleWe are seeking a highly skilled Senior Information Security Analyst to lead our data access security efforts. As a member of our Information Security team, you will be responsible for architecting and implementing data access security controls to protect our organization's data estate.Key ResponsibilitiesAuthor and maintain security policies,...


  • Bengaluru, Karnataka, India Gainwell Technologies LLC Full time

    Job SummaryGainwell Technologies LLC seeks a skilled Information Security Compliance Specialist to ensure the effective utilization of our diverse product portfolio. This role will work closely with internal teams and external stakeholders to understand product functionalities, address concerns, and optimize solutions across various domains.Key...


  • Bengaluru, Karnataka, India SAP Full time

    Key Responsibilities:SAP is seeking a seasoned security compliance professional to lead the coordination of customer security audits and assessments.The ideal candidate will have a strong background in risk and compliance management, with 10+ years of experience in program or project management specific to risk, compliance, and security.Key responsibilities...


  • Bengaluru, Karnataka, India Lipton Teas & Infusions. Full time

    Job Title: Senior Information Security and Risk Manager - FMCGAbout the Role:We are seeking an experienced Senior Information Security and Risk Manager to join our team at Lipton Teas & Infusions. The successful candidate will be responsible for delivering compliance to internal and external standards, frameworks, and attestations.Key...


  • Bengaluru, Karnataka, India Altisource Full time

    At Altisource, we are seeking a highly skilled Senior Information Security Analyst to join our team.About the RoleThis is a full-time position with a salary of $85,000 - $110,000 per year, depending on experience.Job DescriptionWe are looking for an experienced Information Security Analyst to play a key role in monitoring and reviewing compliance to...


  • Bengaluru, Karnataka, India SAP Full time

    Job OverviewSAP is a global leader in enterprise software, with over 400,000 customers worldwide. We are seeking an Information Security and Compliance Expert to join our team.About the RoleWe are looking for a highly skilled expert in security design, implementation, and auditing of SAP systems. The ideal candidate will have experience in customizing,...


  • Bengaluru, Karnataka, India WELLS FARGO BANK Full time

    About this RoleWe are seeking a Senior Information Security Analyst to join our team at Wells Fargo Bank.In this role, you will provide information security consultation to improve awareness and compliance with Enterprise Information Security policy, processes and standards.Key Responsibilities:Perform remediation of security assessment review issues,...


  • Bengaluru, Karnataka, India KreditBee Full time

    Job SummaryKreditBee is seeking a highly skilled Information Security Analyst to join our team. As an Information Security Analyst, you will be responsible for ensuring compliance with regulatory requirements, identifying and developing InfoSec policies, and monitoring compliance with InfoSec policies and regulatory requirements.Key ResponsibilitiesEnsure...


  • Bengaluru, Karnataka, India TERRALOGIC Full time

    Overview:Terralogic is seeking a seasoned Senior Information Security Auditor to join our team of experts in GRC Consulting.Total Experience:5 yearsJob Skills:Proven expertise in IT Security and Infrastructure audits.Ability to conduct ISMS audits independently.Must have audited a minimum of 3 clients and implemented a minimum of 2 clients.Knowledge of...


  • Bengaluru, Karnataka, India Computacenter Full time

    Computacenter is a global IT services business with a unique vendor-independent, infrastructure-focused perspective on the market.As an experienced ISMS Security Analyst, you will play a pivotal role in maintaining and enhancing the Information Security Management System (ISMS) of our organization.Key ResponsibilitiesEnsure the security and confidentiality...