Senior Cyber Risk Governance Analyst
2 days ago
Sr Cyber Governance Analyst
Job Summary:
Provide professional expertise and advise IT and senior leadership in matters relating to technology-related compliance with all applicable laws, regulations, industry standards and corporate compliance requirements. Assess changes in the regulatory, business and technology environment and recommend and implement or guide appropriate changes to IT policies, controls, and processes to address security and technology issues. Manage and coordinate IT audit activities by working with IT leaders, team members, external auditors, regulators, and other organizations that review and assess IT processes and controls. Lead and execute cybersecurity risk management activities include internal compliance and risk management activities as well as third-party vendor security oversight and response to customer security inquiries.
Responsibilities:
- Provide professional expertise and advise leadership in complying with all applicable laws, regulations, and accreditations, including Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry Data Security Standard (PCI-DSS), FedRAMP, HITRUST, ISO 27001, and EU General Data Protection Regulation (GDPR).
- Facilitate, oversee, and provide point of contact for all IT audits, assessments, and other reviews of processes and technology. Work with teams to coordinate schedules for activity. Work with IT teams to deliver requested evidence, documentation, conduct interviews, walk through processes, test controls, and negotiate issues. Manage and monitor development and execution of action plans by reviewing and evaluating reports for trends, working with leadership to prioritize findings, and track progress toward agreed upon timeframes. Ensure issues are appropriately documented, relevant, and understood.
- Perform IT risk and controls assurance assessments of internal and third-party technology-related processes and solutions, working with IT leaders, security architects, Procurement, and other subject matter experts.
- Perform recurring assessments of information security and technology functions to measure maturity against industry standard baselines, identifying improvement areas, registering risks, and assisting with action plans to move processes to a higher level of maturity.
- Develop and maintain operational metrics to ensure information security and technology risk and the performance of the IT risk and compliance program is measured sufficiently to enable success.
- Mentor and coach team members through risk assessments, including scoping of an assessment, resolving conflict, and prioritization of issues. Perform peer review of work product and deliverables.
- Continuously look to optimize processes, technology and capabilities through tactical and strategic development.
- Other duties as assigned.
Knowledge and Skills:
- Strong analytical skills;
- Demonstration of ability to solve problems using best practices and systematic approach
- Relationship builder; able to create and maintain a trusted network on all levels;
- Good communication, influencing and negotiating skills;
- Written and oral communication skills including the ability to communicate complex technical issues to non-technical staff;
- Project management and organizational skills;
- Tactful and diplomatic when engaging with all levels of management always maintaining a
professional demeanor.
Required Experience:
- 5-8 years direct experience with information security, IT controls assurance and IT audit facilitation
- Working knowledge of industry standards such as NIST Cybersecurity Framework, FedRAMP, NIST SP 800-53, ISO 27001, Sarbanes-Oxley, SOC1, SOC2, HIPAA, HITRUST and other similar frameworks.
Preferred Experience:
- Experience in cloud-based environments for production applications, including Amazon Web Services, Microsoft Azure, GCP or other large-scale cloud deployment.
- Understanding of attack vectors and methodologies.
- Ability to weigh business risks and enforce appropriate information security measures.
- CISSP, CISM, CISA, CCSA or equivalent certification preferred.
Proficient in the use of Microsoft Office (Excel and PowerPoint), Power BI and Power Automate.
-
Senior Cyber Security Analyst
4 weeks ago
Hyderabad, Telangana, India Antal International Full timeAs Cyber Security Analyst you will be required to work collaborate with our client IS Cyber Security teams to understand their cyber security systems architecture processes etc and recommend necessary changes implement enhanced Information Security systems either within organisation or at the client systems Roles Responsibilities ...
-
Senior Vendor Cyber Risk Analyst
3 weeks ago
Hyderabad, Telangana, India S&P Global Market Intelligence Full timeJob DescriptionThe Team:- As part of Vendor Risk Management, the Vendor Cyber Risk Management team manages the Supply Chain Cyber risks by performing risk assessments of third-party engagements to identify and reduce the risks posed by third parties. This is an extremely important role, considering the fact that large number of data breaches happen due to...
-
Cyber Security Senior Analyst
1 week ago
Hyderabad, Telangana, India Cigna Healthcare Full time ₹ 6,00,000 - ₹ 18,00,000 per yearCyber Security Senior Analyst, Incident Response Position Summary:Cigna Information Protection is looking for a Senior Analyst, Incident Response (IR). The Incident Response Senior Analyst is responsible for handling and coordinating lower severity cybersecurity incidents as part of a 24x7 operation. The IR Senior Analyst acts as a supporting role to the...
-
Lead – Cyber Risk Strategy and Oversight
6 days ago
Hyderabad, Telangana, India Alignity Solutions Full time ₹ 20,00,000 - ₹ 25,00,000 per yearDo you love a career where you Experience, Grow & Contribute at the same time, while earning at least 10% above the market? If so, we are excited to have bumped onto you.Learn how we are redefining the meaning of work, and be a part of the team raved by Clients, Job-seekers and Employees.Jobseeker Video Testimonials Employee Glassdoor ReviewsIf you are a...
-
Lead Governance Risk
1 day ago
Hyderabad, Telangana, India Providence Global Center Full time ₹ 20,00,000 - ₹ 25,00,000 per yearAbout ProvidenceProvidence, one of the US's largest not-for-profit healthcare systems, is committed to high quality, compassionate healthcare for all. Driven by the belief that health is a human right and the vision, 'Health for a better world', Providence and its 121,000 caregivers strive to provide everyone access to affordable quality care and...
-
Senior Information Security Analyst
4 weeks ago
Hyderabad, Telangana, India Transcend Full timeAbout us: Transcend Street Solutions ( ) is a global Fintech company headquartered in New Jersey, USA, with a global technology center in Hyderabad. We are on an exciting journey to help capital market participants improve financial performance, operational efficiency, and risk management. With game-changing technology solutions deployed at world-leading...
-
Third party risk
4 weeks ago
Hyderabad, Telangana, India MOURI Tech Full timeJob DescriptionTPRM Analyst 4 to 8 YearsRole Summary: Cyber Risk Analyst to support and strengthen our enterprise cyber risk management program. The ideal candidate will be responsible for conducting risk and criticality assessments, maintaining the risk register, tracking mitigation efforts, and generating actionable risk reports to support leadership...
-
Risk Analyst
22 hours ago
Hyderabad, Telangana, India ICE Data Services Full time ₹ 9,00,000 - ₹ 12,00,000 per yearThe Risk Oversight Department of ICE Clear Europe (ICEU) is the independent, second line of defense risk function that develops and manages the framework for identifying, assessing and reporting risks, and performs independent model validation. The department comprises an Enterprise Risk Management team, Model Risk Management team, Credit risk team, and a...
-
3 Days Left) Senior Information Security Analyst
4 weeks ago
Hyderabad, Telangana, India Transcend Full timeAbout us:Transcend Street Solutions (www.transcendstreet.com) is a global Fintech company headquartered in New Jersey, USA, with a global technology center in Hyderabad. We are on an exciting journey to help capital market participants improve financial performance, operational efficiency, and risk management.With game-changing technology solutions deployed...
-
Cyber and 3rd party risk manager
4 weeks ago
Hyderabad, Telangana, India Amgen Inc Full timeJob DescriptionDescriptionThe Cyber and 3rd Party Risk Manager will be responsible for identifying, assessing, and mitigating cyber risks associated with third-party vendors, ensuring compliance with security policies and regulations.Responsibilities- Identify, assess, and manage cyber risks associated with third-party vendors.- Develop and implement risk...