Conduct Internal Audit
Conduct Risk Assessment
Conduct Third Party Risk Assessment
Assist in ISO27001 implementation for new business units and help in maintaining existing certification
Conduct RoPA and DPIA
Manage DLP rules
Conduct random audit on any security domain to ensure all controls are in place
Follow up with relevant stakeholders for closure of audit observations
Monitor activities as per security plan for all the locations.
Conduct Risk Assessment as per ISO 27001 standard
Data recovery- Random check of backup and restoration testing related controls.
Monitor and ensure information security awareness training done for all employees and contracted employees.
Create multiple phishing and other security awareness campaigns
Facilitate user access review and monitor ISMS metrics
Monitor compliance and inform management regarding the same
Assist in Data Governance related projects
Create Data Registers
Random check of implemented controls mentioned in information security policy and accompanying standards, procedures and guidance
Knowledge of NIST, CSA framework, PCI DSS and other standards
Knowledge of privacy controls
Assist in policy and procedure review
Work with internal stakeholders to develop relationships to help promote and improve information security