This is a permanent, full-time role, as an individual contributor in a team of 5.
Responsibilities
- Define, enhance and demonstrate company’s point of view and delivery towards our approach of cybersecurity-focused services
- Guide the end-users on Governance, Risk and Compliance aspects of Security Management
- Work with various teams within Client to fulfill security requirements to establish compliance and document risks
- Participate in Project activities and guide Project teams to remediate new and outstanding issues
- Support Auditors and Audits in providing relevant details necessary to show Compliance statuses
- Participate in overall security governance programs and provide quality of service to ensure security standards
- Participate in design activities and provide various solutions to ensure security is not compromised at various phases of the program lifecycle
- Recommend and provide templates where possible for end users to assist in minimising the security risks
- Responsible for procedures and controls to assure compliance with applicable regulatory and legal requirements, and good business practices
- Establish and oversee formal risk analysis and self-assessment programs for various Information Services processes
- Ensure compliance with Banking Regulatory Compliance (BFSI), HIPAA, PCI and the NC Identify Theft law
- Establish and oversee a formal vulnerability and testing program
- Manage to remediate new and outstanding issues; track security-related issues
- Maintain expertise on security trends through training, research and development in order to mitigate exposures
- Manage, coach, lead and develop a small/mid-staff GRC personnel
Requirements
- Bachelor's degree in computer engineering
- At least 10 years of experience as Principal Consultant, with at least 5 years as a Consultant in Cybersecurity
- Hands-on experience in GRC implementation
- Understanding of cybersecurity concepts and risks
- Knowledge on CIS security standards and guidelines in guiding the team for establishing compliance
- Knowledge and understanding of the attack vectors to provide solutions during design phase to the programs on minimising them with appropriate security controls
- Strong familiarity with industry frameworks such as ISO standards, GDPR, NIST, PCI, DSS, CISO
Preferred Requirements
- CISA certified
- CISSP certified
- CRISC certified