About Company
BDO is a global network of professional services firms with a presence in over 166 countries, revenue of over USD 14 billion, and experience of over 60 years. It’s a leading service provider for the mid-markets with client service at its heart.BDO India Services Private Limited (or ‘BDO India’) is the India member firm of BDO International. BDO India offers strategic, operational, accounting and tax, and regulatory advisory & assistance for both domestic and international organizations across a range of industries. BDO India is led by more than 300+ Partners & Directors with a team of over 10,000 professionals operating across 14 cities and 20 offices. We expect to grow sizably in the coming 3-5 years, adding various dimensions to our business and multiplying and increasing the current team size multi-fold
Qualification
- Plan and establish organization-wide Information security Management System (ISMS) in accordance with ISO / IEC 27001 / NIST Cybersecurity Standard.
- Perform information security audit, Third Party Risk Management Audit, Vendor Audits at least annually or whenever significant changes have been made in IT systems / Infrastructure.
- Monitor and manage information security risks and highlight them to various stakeholder.
- Monitor information security measurement metrics and other key performance / risk indicators on regular basis
- Suggest controls for managing various information security risks and monitor those controls.
- Help in defining / documenting information security presentation to various stakeholders.
- Ensure information security assessments are done for new vendors before they are on-boarded.
- Ensure information security assessment is done for critical vendors on annual basis.
- Ensure vendor assessment report is rolled out and circulated to various stakeholders.
- Ensure closure of observations highlighted for the vendors.
- Ensure management presentation is prepared for all vendor assessments.
- Design and Issue alerts and advisories with respect to new vulnerabilities / threats to all concerned.
- Continuous monitoring of security incidents. Take remedial action to reduce the same.