
Search by job, company or skills
Lead Security Audits and Certifications will report to the Head of Security Assurance. The Lead will be responsible for day-to-day operations related to ISMS (Information Security Management System), external audits, internal audits, and user awareness program. The person will also be responsible for documenting and updating policies, procedures, security baselines to meet security requirements of our clients. Support business continuity program, certification audits and group internal audits. Perform the planning, assessment, testing and validation of audits covering IT governance, systems infrastructure, information security, application controls, and operational activities. Responsibilities include conducting security audits for the IT infrastructure, network, cloud infrastructure and applications. Prepare and maintain an audit calendar to perform audits and communicate the same to the required stakeholder. Responsible for reviewing, maintaining, and updating security policies, procedures, and standards/baselines. Support all accreditation programs such as ISO27001, ISAE 3402 Type II, SOC2 Type 2, PCI-DSS and others as may be needed. Work with different stakeholders including external auditors, business leaders, DPO, Legal, HR, and CIO teams to understand all critical security requirements. Drive security compliance monitoring. Risk assessment for information security and cyber risks Adoption of global frameworks such as NIST Cyber Security and CIS etc. Work with internal Marketing team and external vendors for developing security awareness programs. Perform Phishing simulation tests using tools such as KnowBe4, Cofense, etc. Support Business Continuity program including BC Plans, Crisis Management etc. Perform internal security audits. Manage certifications such as ISO 27001, SOC etc. Perform security audits on application and IT infrastructure including but not limited to network, operating systems (Windows and Linux), databases, access control, Firewalls, IDS/IPS, Web Application Firewalls, Proxies, Cloud infrastructure (Azure and Amazon), Web servers, data center, Email infrastructure, VPN infrastructure, routers, backups, Disaster Recovery, Endpoint Security. Perform security
Job ID: 105663707