Lead- Information security, Risk and Compliance

2 weeks ago


Bengaluru, India Whatfix Full time

Position Summary:

The Security Compliance Specialist is responsible for managing all compliance related activities within the Whatfix platform and supporting other global compliance related initiatives. Compliance activities will include coordinating internal and external assessments/audits, contributing to policy and standards updates, developing compliance framework and producing compliance reports, metrics, scorecards and dashboards. This position will require some technical background with appropriate security training/skills.

Responsibilities:

Lead, manage and improve security compliance program for Whatfix

Coordinate external audits and customer assessments of Whatfix platform

Develop compliance strategy in alignment with business requirements, objectives and metrics

Translate legal, statutory and contractual obligations into a cohesive collection of processes and provide the respective stakeholders with the compliance requirements and methodologies

Interface with management and partner with groups such as Engineering, operations and Customer Success on how to best improve security compliance and reduce risk

Use key business measurements to identify and drive process improvement opportunities for compliance and risk management

Review and update security policies and standards on a regular basis to address new threats, new industry practices, requirements and standards based on security and compliance requirements

Coordinate regular system and network audits, reviews, and tests to verify compliance with security policies and standards

Conduct and/or interpret network, system and application Audits/assessments and track through to remediation

Monitor internal and external security advisories that impact security, risk and compliance requirements

Support the implementation of security controls and recommend areas for risk reduction

Support RFP and contractual agreements process in assessing security requirements from potential customers

Develop and enhance an information security, risk & compliance management framework based on CobIT/Risk IT, NIST, ISO and CSA CCM/STAR, FEDRAMP

Manage updates to the external and internal security portals

Assist and improve security awareness program

Assist and improve governance activities

Evaluate suspected security breaches, work with subject matter experts, and recommend corrective actions

Skills and Experience Required:

At least 6-8+ years of experience in information security, compliance, audit and/or risk management

End-to-end security experience including web, application, network, OS and database

Knowledge of security issues, trends, best practices

Familiarity with audit, business and segregation of duties, risks, and controls

Ability to foresee and identify mitigation strategies for risks

Knowledge in at least 2 of security industry standards such as SSAE18/SOC2, ISO 27001, PCI-DSS, NIST and CSA CCM/STAR, FEDRAMP mandatory

Working knowledge in one or more privacy laws such as GLBA, HIPAA, GDPR, CCPA is important.

Excellent communication and presentation skills 

Ability to communicate well up to line management and also motivate technical teams

Ability to work autonomously with flexibility and excellent judgment 

Ability to work effectively under pressure to meet deadlines 

Ability to solve problems quickly and automate processes

Ability to work cooperatively as part of a team 

Education:

Bachelor's degree in computer science, information technology or other related major required

ISO 27001 Internal Auditor 

CISM/ CISA



  • Bengaluru, India Whatfix Full time

    Position Summary:The Security Compliance Specialist is responsible for managing all compliance related activities within the Whatfix platform and supporting other global compliance related initiatives. Compliance activities will include coordinating internal and external assessments/audits, contributing to policy and standards updates, developing compliance...

  • Compliance Manager

    2 months ago


    Bengaluru, India LeadSquared Full time

    Location:BangaloreReports to:Director - ITPosition Overview:As an Information Security Compliance Manager at LeadSquared, you will play a critical role in overseeing and maintaining our information security compliance program. The ideal candidate will have at least8years of hands-on experience in managing compliance with ISO 27001, SOC 2, and HIPAA...


  • Bengaluru, India Talent Ocean Full time

    Client : MNCPayroll: Third partyBudget : As per marketstandardsExperience : 36 YearsNP : Immediate to April joinersonlyLocation : BangaloreWFORisk Security &Compliance AnalystCertification : ISO 27001 LI CISSP / CISM / CISA IAMConsultant JobResponsibilities: Implementation of ISMSacross the organization working in European time zone driving thetopics and...


  • Bengaluru, India Mercedes-Benz Research and Development India Private Limited Full time

    **Aufgaben**: - Governance Risk and Compliance Experts - The main objectives of the Governance Risk & Compliance Lead are to lead the design, development, documentation and communication of governance, risk management and compliance related policies, standards, procedures and enablers in order to drive consistency in approach and output, centralized...


  • Bengaluru, India Take-Two Interactive Software Full time

    About the PositionJob Title:Information Security Risk AnalystWho We Are:Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and commercially successful entertainment...


  • Bengaluru, India Take-Two Interactive Software Full time

    About the PositionJob Title: Team Lead- Information Security Risk ManagementWho We Are:Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and commercially successful...


  • Bengaluru, India Take-Two Interactive Software Full time

    About the Position Job Title: Team Lead- Information Security Risk Management Who We Are: Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and...


  • Bengaluru, India Take-Two Interactive Software Full time

    About the Position Job Title: Team Lead- Information Security Risk Management Who We Are: Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and...


  • Bengaluru, India Take-Two Interactive Software Full time

    About the Position Job Title:  Information Security Risk Analyst Who We Are: Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and commercially...


  • Bengaluru, India Take-Two Interactive Software Full time

    About the Position Job Title:  Information Security Risk Analyst Who We Are: Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and commercially...


  • Bengaluru, India Take-Two Interactive Software Full time

    About the Position Job Title:  Information Security Risk Analyst Who We Are: Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and commercially...


  • Bengaluru, India Take-Two Interactive Software Full time

    About the Position Job Title:  Information Security Risk Analyst Who We Are: Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and commercially...


  • Bengaluru, India Take-Two Interactive Full time

    Job Title: Information Security Risk AnalystWho We Are:Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and commercially successful entertainment experiences,...


  • Bengaluru, India Take-Two Interactive Full time

    Job Title: Information Security Risk AnalystWho We Are:Take-Two Interactive Software, Inc. is a leading developer, publisher, and marketer of interactive entertainment for consumers around the globe. For more than 25 years, our development teams have created some of the most critically acclaimed and commercially successful entertainment experiences,...

  • Information Security

    4 weeks ago


    Bengaluru, India LeadSquared Full time

    Location: Bangalore Reports to: Director - IT Position Overview: As an Information Security Compliance Manager at LeadSquared, you will play a critical role in overseeing and maintaining our information security compliance program. The ideal candidate will have at least 8 years of hands-on experience in managing compliance with ISO 27001, SOC 2, and...


  • Bengaluru, India Tredence Inc. Full time

    About TredenceTredence is a data science and AI engineering company focused on solving the last-mile problem in analytics. We define ‘last mile’ as the gap between insight creation and value realization. Tredence is now 2000+ employees strong with offices in Foster City, Chicago, London, Toronto, and Bangalore, Chennai, Pune, Kolkata, Gurgaon serving...


  • Bengaluru, India Tredence Inc. Full time

    About TredenceTredence is a data science and AI engineering company focused on solving the last-mile problem in analytics. We define ‘last mile’ as the gap between insight creation and value realization. Tredence is now 2000+ employees strong with offices in Foster City, Chicago, London, Toronto, and Bangalore, Chennai, Pune, Kolkata, Gurgaon serving...


  • Bengaluru, India CRED Full time

    **what is CRED?** CRED is an exclusive community for India’s most trustworthy and creditworthy individuals, where the members are rewarded for good financial behavior. CRED was born out of a need to bring back the focus on a long lost virtue, one of trust, the idea being to create a community centered around this virtue. a community that constantly...


  • Bengaluru, India WELLS FARGO BANK Full time

    About Wells Faro:Wells Fargo India enables global talent capabilities for Wells Fargo Bank NA., by supporting business lines and staff functions across Technology, Operations, Risk, Audit, Process Excellence, Automation and Product, Analytics and Modeling. We are operating in Hyderabad, Bengaluru and Chennai locations.Department Overview:Wells Fargo views...


  • Bengaluru, India Tredence Inc. Full time

    About Tredence Tredence is a data science and AI engineering company focused on solving the last-mile problem in analytics. We define ‘last mile’ as the gap between insight creation and value realization. Tredence is now 2000+ employees strong with offices in Foster City, Chicago, London, Toronto, and Bangalore, Chennai, Pune, Kolkata, Gurgaon serving...