Lead Engineer - Cyber Security
Mphasis · IT Services & Consulting
- Pune, India
- On-site
- Posted today
- Cybersecurity
About the job
Job Description
Role Security Compliance Auditor
Location: Pune or Bangalore, India
Who are we looking for
Information Security compliance auditor are responsible for ensuring that the process, technology and business solutions are compliance with companys standards. Compliance auditor will be required to engage with internal and external stakeholders to achieve the goals of the company's security organization and business.
The role reports into the Cyber Operations Manager
Position Summary
Experience 8 plus on Compliance & Risk Management
Deep knowledge of Governance and audit
Experience with implementation of corrective action programs
Good Understanding of IT security policy, procedure, design, and implementation
In depth Knowledge on frameworks including ITIL, ISO27002, SOX, PCI DSS, GDPR and COBIT 5.
Deliver Managed Security Services in compliance with PCI DSS and framework compliance to COBIT 5
Undertake risk classifications and registration in line with the core business principles and policies
Conduct Technical and process compliance internal Audits
Perform evidence gathering to validate compliance as required by Client, and report audit findings
Participate in IT security and process maturity audits as required by Client
Maintain documentation required for security assessments, audits and internal control and control testing.
Security-related Incident handling
Assist client to define Security requirements based upon Business needs and update their Information Security Policy
Inform stakeholders immediately if becomes aware of any vulnerability or weakness in the Services or any Security breach, and recommends a possible solution or mitigation
Comply with data and records management, and electronic records and data archiving as per IT Security policies and processes for company
Knowledge, Skills and Experience:
Extensive technical information security experience, including, but not limited to:
Cloud Security
ISO 9001
ISO 27001, ISO 27002, ISO 27701
COBIT 5
ITIL
GDPR UK DPA 2018
Extensive knowledge and understanding of security controls and business process
Able to work effectively in a team and across multi-functional teams
Strong understanding of leading frameworks and standards
Expert knowledge of security principles and technologies
Excellent written and oral communication skills at all levels, strong communicator and ability to articulate and communicate complex IT-related business issues to senior staff
CISSP, CISA, ISO27001 Lead Auditor, Iso 9001 Lead Auditor certified
Good understanding of Risk Management and risk methodologies
Bachelor's degree in computer science, MIS, Engineering or related field preferred, or demonstrable equivalent commercial experience, including any relevant security qualifications
Automotive and retail industry experience an asset