Information Security Analyst – Security Certifications
In-person · Bengaluru, KA, IN... more
In-person · Bengaluru, KA, IN... more
Job Description
Job Title: Information Security Analyst – Security Certifications
REPORTING TO : Manager, Information Security
REPORTING LOCATION : Katowice, Poland
WORKING LOCATION : India
ROLE & OBJECTIVES:
- Role would focus on the attestations and certifications for relevant Eurofins functions as well as in providing guidance & supporting customer questionnaires.
- Support External Audits (SOC 2 – Type1/Type 2 , ISO 27001, and other IT Audits based on NIST Cybersecurity) for relevant functions/region wise.
- Define/review test of procedures/controls basis on the organization defined policies & procedures for relevant certifications.
- Execute the tests of the defined controls (ITGC – IT General Controls, Technical controls, Physical Controls, etc) as part of TOD (Test of Design) and TOE (Test of effectiveness).
- Manage reporting phase of the testing and ensure clarity of the reported findings.
- Explain details of findings to the Management stakeholders.
- Follow up on the reported findings for its remediation.
- Monitor the compliance via available GRC tools / dashboards and ensure gaps are mitigated by collaborating with other stakeholders.
- Well versed with ITIL Standardized Process to monitor the Service Now requests.
QUALIFICATIONS AND EXPERIENCE REQUIRED:
Minimum of 3 -9 years of professional experience in the field of Governance, Risk and Compliance or IT Audits.
Required
- Knowledge of technical security concepts related to IT General Controls (ITGC Controls) – Identity & Access Management, Physical Security, Incident Management, Business Continuity & Disaster recovery, Change Management, Logging & Monitoring Data Management, Asset Management and Risk Management etc.
- Knowledge in any of these two framework/standard SOC 2- Type1/Type2, ITIL/ITSM, ISO/IEC 27001,NIST Cyber Security.
- Additional Knowledge in regulations like GDPR or SWIFT Attestation.
- Excellent Fluency in English (Verbal and Written).
Appreciated
- Any security related certifications like: ISO27001, CISA, CISSP is an added advantage.
- Experience with a MNC company and/ or Big 4 accounting firm experience is an added advantage.