Sr Subject Matter Expert (Support&Ops)

Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity · Risk Management

In short

A Senior Subject Matter Expert (Support&Ops) is sought with 7-8 years of experience in information security, third-party risk management, and auditing. The role requires a Bachelor's degree in computer science or a related field, and industry certifications such as CISA, CISM, CISSP, or CRISC are preferred.

Responsibilities

  • Manage Third-Party Risk Management (TPRM) governance.
  • Evaluate third-party cybersecurity controls and ensure compliance with organizational standards and industry best practices.
  • Track and monitor due diligence reviews, communicating status to management and stakeholders.
  • Articulate risks and potential options for remediation or compensating controls.
  • Perform inherent risk assessments.
  • Conduct security assessments to identify security gaps in current systems.
  • Perform new and recurring third-party security risk assessments, develop mitigation plans, and manage remediation tracking.
  • Understand GDPR, LGPD, and other privacy requirements.
  • Provide advisory and consulting to clients on enterprise risk management trends and challenges.
  • Design and develop information security policies, standards, and guidelines.
  • Implement security controls, risk assessment frameworks, and programs aligned with regulatory requirements.
  • Design/modify contract security language and clauses.
  • Coordinate and negotiate security clauses with Procurement and Suppliers.
  • Work with client and technical teams on change requests for risk or control implementation and governance processes.
  • Participate in internal and external regulatory and IT security audits.
  • Understand IT risks and define audit and governance mechanisms for assets, processes, and physical security.

Requirements

  • 7-8 years of progressive, responsible, and diversified experience in Information security consulting, Third-Party risk management, and auditing.
  • Bachelor's degree in computer science, information systems, or equivalent.
  • Certified in industry-accepted certifications such as CISA, CISM, CISSP, CRISC.
  • GRC professional with good understanding of industry frameworks and standards.
  • In-depth experience on Third-Party Risk Management.
  • In-depth understanding of review process of current system security measure by performing security assessments to identify security gaps.
  • In-depth understand of GDPR, LGPD and other privacy requirements.
  • Knowledgeable in various regulations like SOX, HIPPA, GDPR, GLBA, FISMA and standards like PCI DSS, SOC (service organization’s controls), ISO 31000.
  • Strong business and communication skills.
  • Experience in driving meetings with stakeholders.
  • Experience in design and development of information security policies, standards, and guidelines.
  • Experience on SIG (shared assessments), ISO 27001, NIST framework, SOC 1, SOC2, ISO 27001 and HIPAA.
  • Sound experience around implementation of security controls, risk assessment framework, and program that align to regulatory requirements.
  • Experience on GRC platforms.

Desired Qualifications

  • Good written and communication skills.
  • Experience in driving meetings with stakeholders.
  • Provide advisory and consulting to client on new trends and challenges in enterprise risk management area.
  • Experience in design and development of information security policies, standards, and guidelines.
  • Work with the client & technical teams for change request on any risk or control implementation as well as governance process.
  • Participate in internal as well as external regulatory as well as IT security audits.
  • Understand IT Risks and define audit & governance mechanisms for assets, processes & physical security.

Benefits

  • Supercharge your potential.
  • Find your career.
  • Find your spark.
  • A place that knows that helping its customers stay on top starts by putting its people first.

Skills

Third-Party Risk ManagementInformation securityGRCGDPRSOXHIPAAGLBAFISMAPCI DSSSOCISO 31000ISO 27001NISTSIGLGPD
#Information Security#Risk Management#Auditing#GRC#Cybersecurity#Compliance#Third-Party Risk Management#TPRM#Governance#Data Privacy#SOX#HIPAA#PCI DSS#ISO 27001#NIST#SIG#IT Risk#Audit
HCLTech Logo

About HCLTech

Supercharging progress through technology and innovation

HCLTech is a global technology company, home to 219,000+ people across 54 countries, delivering industry-leading capabilities centered around digital, engineering and cloud, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending September 2022 totaled $12.1 billion. To learn how we can supercharge progress for…

HCLTech Logo

Company

HCLTech

Job Posted

2 days ago

Employment Type

Full Time

Work mode

On Site

Experience Level

Senior

Locations

Noida, India

Qualification

Bachelor

Applicants

Be an early applicant