Search by job, company or skills

Aditya Birla Group

Associate GRC Manager

Save
new job description bg glownew job description bg glownew job description bg svg
  • Posted 6 hours ago
  • Be among the first 10 applicants
Early Applicant

Job Description

Job Description

Key Result Areas

Supporting Actions

Regulatory & Compliance Audits for Payments

  1. Lead and coordinate paymentindustry regulatory audits such as RBI, NPCI, PCIDSS, , CERTIN, etc.
  2. Manage endtoend audit activities including audit calendar management, documentation preparation, evidence collection, and stakeholder coordination.
  3. Track audit observations/findings and ensure timely closure with respective control owners.

Regulatory compliances

  1. Identify all regulatory compliance requirements.
  2. Review and update the policies to ensure identified regulatory requirements are drafted in policies.
  3. Conduct the assessments to ensure implemented controls are meeting to regulatory compliances.

Data Loss Prevention (DLP) & Proxy Governance

  1. Review, implement, and maintain DLP and Proxy policies across the organization.
  2. Perform DLP and Proxy exception reviews, ensuring justification, approval, and tracking.
  3. Conduct ongoing monitoring and analysis of High and Medium severity DLP incidents.
  4. Collaborate with IT/security teams to finetune policies and reduce false positives.

Control Validation & Compliance Monitoring

  1. Perform control validation to ensure compliance with internal policies, procedures, and regulatory guidelines.
  2. Execute periodic checks on access management, data protection controls, endpoint security, and network controls.
  3. Document deviations and drive corrective action plans with respective teams.

Conduct Third-Party risk assessments

  1. Understand the business requirement from proposed solution, connect with the vendor and functional/data/IT SPOCs to understand the architecture of the proposed solution's integration and data movement
  2. Conduct the InfoSec/cyber risk assessment to identify InfoSec/cyber related risks and regulatory requirement's compliance
  3. Submit the risk assessment report to concern stakeholders with highlighting residual InfoSec/cyber risks and provide mitigation recommendation for the same
  4. Track with businesses to ensure that recommendations are accepted and implemented and if it is not then risk is accepted for the same
  5. Track Open vendor's risks at ABC level and along with recommended controls to mitigate the risk
  6. Present risk to concern team and ABCD CISO senior management for their knowledge and support
  7. Review the MSA/NDA and making sure that the required Information Security clauses such as Information Security and Data Protection, Data Purging requirements, Right to Audit clause, SLA, Penalty etc., are prepared

More Info

Job Type:
Role:
Employment Type:

Job ID: 146376183