Lead the implementation of security initiatives and
- Develop, implement and maintain physical security programs and cyber security policies
- Ensure that effective tools and processes are in place to protect assets from the evolving threat landscape
- Work with cross functional teams to design processes and procedures for operational business units compliance
- Conduct organization wide training to ensure policy implementation
- Monitor and identify compliance risks, coordinate control improvements and check implementation status
- Direct the development and implementation of policies, procedures and controls to ensure that the organisations practices remain compliant to regulatory requirements of ISO 2700x, SOC2, GDPR etc
- Establish metrics and reporting frameworks to measure the efficiency and effectiveness of the security program while increasing the security program maturity level
- Manage periodic and regular internal and external risk assessments and audits
- Assist with remediation of control deficiencies identified during the audit process
Requirements
- Knowledge and understanding of relevant legal and regulatory requirements, such as ISO 2700x, SOC 2, HIPPA, GDPR, Privacy shield, data protection etc
- Knowledge of security issues, techniques and implications across the whole IT infrastructure
- Proficient in performing enterprise risk, business impact and vulnerability assessments, and defining risk mitigation strategies
- Strong understanding of business impact of security tools, technologies and policies
- Excellent verbal and written communication skills with the ability to communicate security concepts to both technical and non technical audience at all levels
- At least 3-5 years of work experience in enterprise security functions such as Security compliance framework, identify and access management, Cloud security, Vulnerability management, Firewalls, Antivirus, Penetration testing and other related functions
- Audit experience is a must
- Experience in drafting policies and standard operating procedures is required
- Experience conducting internal investigations, assessing risk at the enterprise level and monitoring / implementing controls is required
Benefits
Group Medical polices - INR 5,00,000 with Private
Equal Employment Opportunity
Maternity Leave
Skill Development
o 100% Sponsorship for certification
Work Life balance
Flexible work hours
Zero Leave tracking
Knowledge and understanding of relevant legal and regulatory requirements, such as ISO 2700x, SOC 2, HIPPA, GDPR, Privacy shield, data protection etc Knowledge of security issues, techniques and implications across the whole IT infrastructure Proficient in performing enterprise risk, business impact and vulnerability assessments, and defining risk mitigation strategies Strong understanding of business impact of security tools, technologies and policies Excellent verbal and written communication skills with the ability to communicate security concepts to both technical and non technical audience at all levels At least 3-5 years of work experience in enterprise security functions such as Security compliance framework, identify and access management, Cloud security, Vulnerability management, Firewalls, Antivirus, Penetration testing and other related functions Audit experience is a must Experience in drafting policies and standard operating procedures is required Experience conducting internal investigations, assessing risk at the enterprise level and monitoring / implementing controls is required