Job Description
The candidate will be responsible for supporting remote desktop assessments and assisting with Tier 1 and Tier 2 vendor risk assessments, onboarding, and due diligence reviews. The role involves identifying and documenting observations and findings during assessments.
Educational Qualifications
- Minimum of a bachelor's degree from a reputable university.
- 3–6 years of relevant experience.
Job Requirements
Strong experience in Information Security Governance, Privacy, Compliance, and Security Assessments, with a focus on IT and IS risk assessments and program reviews.In-depth understanding of ISO 27001, NIST 800-53, and PCI DSS standards.Hands-on experience in performing vendor or third-party security assessments and interacting directly with onshore engagements and clients.Knowledge of Business Continuity Planning (BCP) and Disaster Recovery (DR) implementation and review.Ability to perform remote and gap assessments against regulatory requirements and provide actionable remediation recommendations.Skilled in independently writing detailed assessment reports based on discussions during remote reviews.Capable of performing second-level quality reviews of reports prepared by peers or junior resources.Profile
Experience in Information Security Governance, Privacy, Compliance, and Security Assessments, focusing on IT and IS risk assessments and program reviews.Familiarity with and demonstrated experience assessing against standards such as : ISO 27001, SOC2 Type2, PCI-DSS, etc.Domains including Risk Assessment, Security Policy, Organization of Information Security, Asset Management, HR Security, Physical and Environmental Security, Communications and Operations Management, Access Control, IS Acquisition, Development and Maintenance, IS Incident Management, Business Continuity Management, and Compliance.Broad understanding of Information Security trends, services, and disciplines, and experience applying them in dynamic environments.Additional Qualifications
Preferred certifications : CISA, CISM, CISSP, CRISC, CIPP, ISO 27001 Lead Auditor / Implementer.Skills
GRC Risk – Third-Party Risk Management (TPRM)Location
Pune & BangaloreSkills Required
Pci Dss, privacy compliance , Security Assessments, Iso 27001, quality reviews , information security governance