Manager - Risk & Compliance
Job Description:
- Develop, implement and monitor a strategic, comprehensive enterprise Information Security and IT risk management program
- Implement , maintain and manage various security compliance and best practises, ISO27001, PCI DSS , ITGC, SOC 2 , GDPR etc
- Ensure Information Security monitoring tools and systems in place for critical infrastructure and end points to proactively identify security issues and address them using incident management processes.
- Improve the overall security posture and cyber resilience through effective training
- Conduct periodic internal audits
- Carry out periodic risk assessment / management
- SPOC for security compliance
- Provide management reports
- Conduct Management review meetings
- Create necessary policy and procedure documents to meet various compliance needs
- Design and lead business continuity and DR program
- Manage and maintain security review /audit charter
- Conduct security awareness sessions
- Liaison with product vendors, conduct POC and generate report
- Be aware of new tools that help in improving efficiency when it comes to compliance and recommend best practices
- Be on top of evolving compliance needs in cyber security space especially around guidance by regulators in India , Europe and US market
Skills:
- Individuals with a minimum of 5 years experience in managing Information Security preferably in a SaaS based product company
- An excellent understanding of best practice within Information Security and risk management including standards such as ISO/IEC 27001, PCI DSS, DATA privacy, ITGC, GDPR etc.
- Having experience of implementing compliance best practices in SaaS based companies and guided the team in acquiring PCI and SOC2 certification.
- An excellent understanding of legislation and regulations that impact information Security
- A good practical knowledge of security technologies and wider business solutions including AWS technologies.
- Certifications (CISA,CISM,CISSP) preferred
- Good communication and presentation skill
- Understanding of Security products