4+ IT governance Jobs in India
Apply to 4+ IT governance Jobs on CutShort.io. Find your next job, effortlessly. Browse IT governance Jobs and apply today!
Job Title: Technical Architect Security
Location: Work From Home
Department: Security
Reports to: Associate Director - Technology
Job Type: Full-Time
Website: https://deliverysolutions.co/
Delivery Solutions is a Retail eCommerce OXM Platform that provides retailers with out-of-the-box solutions to power Same-Day Delivery, Curbside, In-Store Pickup, Shipping, and post-purchase experiences. We are trusted with some of the biggest names in multiple verticals of retail like Sephora, AT&T, Footlocker, Michael's, Office Depot, GameStop, Total Wine, Sally Beauty, Abercrombie & Fitch Co. Belk, Loblaw, Vineyard Vines etc.
Our SAAS-based solution is highly flexible and interacts seamlessly with E-commerce properties, OMS, WMS, and POS systems for a highly scalable experience and a delighted customer base.
Delivery Solutions is a wholly-owned subsidiary of UPS | We are a certified Great Places To Work Company
Job Overview: As a Technical Architect of security, you will be responsible for leading and managing our Information Security Operations team. You will safeguard our organization's information assets by developing, implementing, and maintaining security processes and protocols. Ensure compliance with relevant laws, regulations, and industry standards (e.g., ISO, SOC2, HIPAA, GDPR) i.e. monitor changes in compliance regulations, adjust policies and procedures as necessary, and oversee the development and implementation of privacy policies and procedures to protect personal data. This role demands a blend of technical expertise and leadership skills to ensure the security and integrity of our systems, networks, and data.
Key Responsibilities:
Technical Responsibilities:
Policy Development and Enforcement
- Develop, implement, and enforce comprehensive security and privacy policies.
- Regularly review and update policies to reflect evolving threats and regulatory requirements.
- Audit adherence to these policies across the organization
Security Operations Centre:
- Oversee the daily operations of the information security team, ensuring that all security policies, procedures, and protocols are effectively implemented and maintained.
- Lead the development and implementation of security measures, including firewalls, intrusion detection systems, and encryption protocols.
Incident Response:
- Manage and respond to security incidents, providing timely and effective resolution.
- Conduct thorough investigations of security breaches and take appropriate corrective actions.
Vulnerability Management:
- Conduct regular security assessments and vulnerability scans to identify potential threats.
- Recommend remediation strategies to address identified vulnerabilities.
Compliance and Audits:
- Develop policies based on industry best practices and implement the policies defined.
- Ensure compliance with relevant laws, regulations, and industry standards (e.g., ISO, SOC2, HIPAA, GDPR).
- Coordinate and support internal and external security audits.
Privacy:
- Be updated on the privacy laws where the company and customers operate
- Ensure the company’s processing activities comply with privacy laws
Functional Responsibilities:
Strategic Planning and Development:
- Collaborate with senior management to develop and implement the overall information security strategy.
- Identify and prioritize security initiatives and projects based on risk assessment and business impact.
Team Leadership and Development:
- Resource management, planning and execution, and stakeholder communication.
- Planning execution of various projects in the domain of security and privacy
- Lead, mentor, and develop a team of security professionals, fostering a culture of continuous improvement and professional growth.
- Conduct performance evaluations and provide constructive feedback to team members.
Cross-Department Collaboration:
- Work closely with IT, legal, marketing, and other departments to ensure cohesive security practices across the organization.
- Serve as a key advisor to the Associate Directors and other executives on security and privacy matters.
- Coordination and provide updates to Delivery Solutions' parent organization on security initiatives.
Risk Management:
- Identify, assess, and mitigate information security risks.
- Develop and maintain a risk management program that aligns with the organization’s objectives.
Security Awareness and Training:
- Develop and deliver security awareness training programs to educate employees on security best practices and emerging threats.
- Promote a security-conscious culture throughout the organization.
Qualifications:
- Education: Bachelor’s degree in Computer Science, Information Security, or a related field. Master’s degree or professional certifications (CISSP, CISM, etc.) preferred.
- Experience: Minimum of 7-10 years of experience in information security, governance, and audit processes, with at least 3-5 years in a management or leadership role. Have worked as an auditor for ISO / SOC2 and other frameworks
- Technical Skills: Experience in setting up a framework and conducting privacy and security audits.Conducting training and awareness, proficiency in security technologies and tools (e.g., SIEM, IDS/IPS, firewalls, endpoint protection), strong understanding of network security, cryptography, and risk management frameworks.
- Functional Skills: Strong leadership and team management skills, excellent communication and interpersonal abilities, experience in strategic planning and project management.
- Personal Attributes: Strong analytical and problem-solving skills, high ethical standards, ability to work under pressure and manage multiple priorities.
Product services company
o Tools:
CrowdStrike Falcon Sensor - Or similar AV engine
Cisco Umbrella Web Filtering – Or similar Web Proxy Filter
Cisco FTD Intrusion Prevention – Or similar IPS/IDS
O365 Email Protection (Spam, Phishing) - Or similar
Phish Insight (Phishing Campaigns) - Or similar phish campaign technology
Nessus Professional – Or similar vulnerability scanning tool
Cisco NGFW – Or similar FW technology
o Technologies:
Cloud (AWS IaaS, O365 SaaS),
On Premis (Windows 90%, Linux 10%)
o Processes:
Computer security incident response
Security reviews and assessments
Vulnerability management Penetration tests
Manage Level 3 security incidents and requests
Ensures compliance with corporate policies and procedures
Research new ways to improve existing technical security controls
Project SME and Lead for security related projects
Conduct Risk assessments and assist in remediation activities
Assist in internal and external audit activities
Required Experience and Skills:
Bachelor's degree in Information Security, Computer Science or Engineering
Minimum of 3 years in security engineering
Knowledge in cloud ecosystems security - Amazon AWS, Microsoft O365
Ability to work well in an international team (US or EU time zone)
English spoken and written on at least B2 level
Understanding of security monitoring and identification concepts
Assessing and understanding the impact, severity and urgency of issues
Cybersecurity Certifications an advantage but not essential: CEH, C|HFI, CISSP, CISA, CISM
Expertise across a variety of security products including those listed in requirements above
- Designation:- Business Head-IT
- Work experience:- 4-5yrs
- Location:- GIFT CITY, Gandhinagar
- Qualification:- BE (Computer Science / IT) / MCA / MSc (CAIT) or higher, MBA (Full Time) preferably from the reputed institute
- Age Limit:- Around 45 – 55 Years.
- Job Timing:- 9:30am to 5:30pm
- Language Known:- English, Hindi, Gujarati
- Required Gender Male/Female:- Male
- Do we Entertain any relocation Prospects? Yes, Have to relocate on own expense
- Transportation Facility:- Yes
- Duration:- Mini. 2yrs contract
- Current strength of Company (In Nos.):- 180
Min. work experience:-
- Around 18-25 years in the field of IT, of which at least 5 years should have been in a senior managerial position with profit center responsibilities.
- Should be well versed with strategy building for IT as Business like e-Governance, e-procurement.
- DSC-PKI will be added advantage.
- Experience in evolving area like Artificial Intelligence, Machine learning, block chain etc. preferable.
- This position is for business development of IT division and not for serving exclusively captive requirement of Company.
Skill-Sets:-
- Thorough understanding of the profitable business generation in the field of IT
- Good analytical & conceptual skills, as well as team leader
- Thorough understanding of various applicable statutory / regulatory requirement related to IT business
- Good networking Skills
- In depth experience in the domain of e-Governance, software, e-procurement. Preferable experience of PKI.
Role& Responsibilities:-
- To lead organization and exploring various business opportunities and generate the profitable revenue from the various IT business streams.
- To analyse the risks and implement the best management practice to mitigate / transfer.
- To envisage the business needs and mobilise the adequate resources, so as to deliver the solutions / systems.
- To co-ordinate with Top Management for various matters.
- To manage the day-to-day all business affairs of the IT Business Division.
- To articulate the cost effective business solutions / models and convert the leads into the business.
- Any other job / activities assigned by the Company as deemed fit.
A Predictive analytics organization with well funded
What The Role Is
We are looking for an GRC Operations Officer based in Chennai. This is a new role within the growing IT Compliance function, where you will be responsible for handling audits, implementation of information security policies etc,. The successful candidate will be comfortable working with the team on implementing frameworks and providing support for internal and external stakeholders. Reporting to the IT Compliance Officer for our Chennai team, this role is integral to the successful growth of the team as well as wider company performance.
What You’ll Do
- Contribute and assist with continuous improvement of company policies, practices, and procedures
- Review, modify and maintain existing practices and policies to reflect our operations and values within specific industry-standard frameworks like ISO and NIST, among others
- Provide support for internal and third-party audits
- Respond to due diligence and TPRM requests from customers and other interested parties.
- Support internal staff with GRC-related questions and topics
- Develop, maintain and execute awareness programs
- Be a local representative of the company’s GRC group and manage the physical security requirements for the location
- Work independently and prioritize multiple tasks and adapt to needed changes
- Effectively communicate risks to diverse audiences, both in writing and verbally
- Apply a risk-based approach to planning, executing, and reporting on audit engagements and auditing process;
What You’ll Bring
- 2-5 years IT Security, IT risk, IT auditing, and/or IT Compliance experience within a technology company, accounting firm, or others.
- Bachelor's degree or equivalent work experience working in compliance/GRC team.
- Exceptional organisational skills and attention to details.
- Knowledge of applicable domestic and internationally recognized information security management, governance, and compliance principles, practices, laws, rules and regulations;
- Information systems auditing, monitoring, controlling, and assessment process.
Perks & Benefits:
- Competitive base salary
- Equity - every employee is a stakeholder in our enormous upside
- A tech-first company culture driven by entrepreneurial thinking and talent
- A great team working in unison towards the same mission
- Transparency is what our product is built on—and so is our culture
- Generous health insurance benefits for employees and their dependents
- Parental leave.
- Flexible work schedule and work-from-home options
- Flexible PTO