Creating and maintaining a technology compliance report
Supporting team in evaluating the IT threat landscape, devising cyber security policy and controls to reduce risk, leading auditing, and compliance initiatives.
Supporting developing cyber resiliency so that the organization can rapidly recover from hacking, security incidents, or infringements.
Understanding of the various Legal and Regulatory Requirement and implementation of the seguide lines to ensure that the organization complies to these guidelines on an ongoing basis.
Periodic review of the information security policies, configuration, documents and keeping them updated and relevant to the environment
Contributing to a variety of security policy domains associated with compliance, governance, risk management, incident management and additional domains.
This job role is responsible for overall supporting the activities of Information Security and reporting the risks and Closure of the audit comments in a timely manner.
This job role requires to provide weekly/monthly reports on the updates /Closure of the audit Points.Other Related Projects being undertaken and the overall Progress Dashboards to CISO and Top Mgmt.
Security Policy Development: Create, implement, and update security policies, standards, and procedures to ensure the protection of the organization's information assets.
Risk Assessment and Management: Identify potential security risks, conduct regular risk assessments, and develop strategies to mitigate these risks.
Incident Response: Develop and implement an incident response plan, and respond quickly to security breaches, incidents, and threats to minimize impact and recover data.
Security Monitoring: Continuously monitor networks, systems, and applications for suspicious activities or security breaches using various security tools and technologies.
Access Control: Manage and enforce access control policies to ensure that only authorized users have access to sensitive information and systems.
Conduct regular security training sessions for employees to raise awareness about security best practices and potential threats.
Vulnerability Management: Identify and address vulnerabilities in the organization's systems and applications through regular security scans, patch management, and updates.
Data Protection: Implement measures to protect sensitive data from unauthorized access, disclosure, alteration, and destruction. Use encryption, data masking, and secure data storage practices.
Security Architecture and Design: Design and implement secure network architectures, systems, and applications to protect the organization's information assets.
Reporting: Provide regular reports on security status, incidents, and compliance to senior management and other stakeholders.
Collaboration and Communication:
Team Collaboration: Working closely with other IT and security teams to ensure acoordinated approach to cybersecurity.
Reporting: Providing regular reports on security incidents, threats, and over all security posture to management and other stakeholders.
Ensure that the organization complies with relevant regulatory requirements, industry standards, and internal policies. Prepare for and assist with security audits.
Cloud Security:
Knowledge of securing cloud environments(e.g.,AWS, Azure ,Google Cloud).
Understanding of cloud security best practices and tools.
Governance, Risk & Compliance:
Understanding of regulatory requirements (SEBI, RBI, CERT-IN, NCIIPC) and industry standards like GDPR, HIPAA, PCI DSS, and ISO 27001.
Requirements
Preferred Skills:
Technical Skills:
Hand on experience in Security solutions: End Point Security (PIM, EDR/XDR, FIM, NAC, IRM etc...), Data Security (DAM, DLP, Data Classification etc...) and Network Security (Secure Web Gateway, WAF, Firewall, IPS/IDS, LB etc...)
Network Security: Understanding of firewalls ,VPNs ,IDS/IPS ,and other network security technologies.
System Security: Knowledge of securing operating systems(Windows, Linux, macOS) and ensuring regular updates and patch management.
Application Security: Familiarity with secure coding practices, application vulnerability assessments, and penetration testing.
Encryption: Proficiency in encryption methods and toolsfor data protection.
Security Monitoring: Experience with SIEM (Security Information and Event Management) tools and other monitoring systems.
Certifications and Education:
Education:A bachelor’sdegreeincomputerscience,InformationSecurity,Cybersecurity,or related field.
Certifications like CISSP ,CISM, CEH, Comp TIA security+, CISA,ISO27001,ISO22301,CISSP would be an added advantage
Analytical and Problem-Solving Skills:
Critical Thinking: Ability to assess situations and make informed decisions quickly and efficiently.
Attention to Detail: Meticulous attention to detail in analysing data and identifying anomalies.
Risk Assessment: Understanding of risk assessment methodologies to prioritize and address potential threats.
Communication Skills:
Report Writing :Capability to document incidents ,create detailed reports, and communicate findings clearly.
Collaboration: Effective communication and collaboration with team members and other departments.
Training and Awareness: Ability to conduct training sessions and promote cyber security awareness with in the organization.
Soft Skills:
Adaptability: Ability to adapt to new threats and technologies in the ever-evolving cyber security landscape.
Stress Management: Maintaining composure and effectiveness under pressure during security incidents.
Continuous Learning: Willingness to stay updated with the latest trends ,threats, and best practices in cybersecurity.
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in India.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip