Get alerts for new jobs matching your selected skills, preferred locations, and experience range.
8.0 - 12.0 years
0 Lacs
Mumbai Metropolitan Region
Remote
Businesses are witnessing rapid digital acceleration. Making it imperative for them to maintain Cyber resiliency there by preparing for, responding to, and recovering from cyber threats. A cyber-resilient organization can ensure business acceleration. And to achieve this Cyber resiliency businesses seek expert guidance, best tools and services from trusted partners. Support Cisco account management as Cyber Security Sales Specialist Lead Cybersecurity engagement within aligned top enterprises and conglomerates Responsible for building Cisco security business pipeline & achieve the security annual targets from assigned enterprise accounts based on either Total control Value or incremental average contract value Identify new business opportunities by positioning solutions from the broad range of Cisco Secure solution addressing Secure Service Edge, Zero Trust Access, Application and Workload Security, SoC, Micro segmentation, Email Security, Multi Cloud Défense, Cloud-Native Application Protection Platform (CNAPP), Attack Surface Management and others Leverage Cisco strength in areas of digital transformation like network, application and compute. Work and build relationships with key decision-makers, especially Cybersecurity stakeholders in the account. Provide ongoing and accurate visibility / status of pipeline and forecast Prepare detailed account development plans and engagement strategies Who You Are 8-12 years of experience in techno-commercial roles within the cybersecurity domain. Knowledge of new and emerging technologies in Cybersecurity domain. At least 3 years of experience in selling SaaS and Subscription delivery models. Understanding of the cybersecurity selling cycle. Experience putting together comprehensive account planning. Track record of success in overachieving sales quotas. Proven and consistent hunting skills (both initial penetration and cross-selling) Comfortable in communicating a complex, technical proposition at an executive, corporate overview level, running first meetings with customers without a sales engineer. Understanding of NIST, CERTIN guidelines, mitre att&ck framework, OT Security. Industry certifications like CISSP, CSSP, CEH or Bachelor's Degree in Cybersecurity from institute of repute Good connects with Cybersecurity decision makers in regional enterprise accounts Good understanding of Cisco Security products. Understanding of engaging and driving channel partner Who You'll Work With Global Security Sales Organization – SE team Global Security Sales Organization – Hyper Sales Specialist & Engineers Cisco Account Manager Product Engineering BU across various Business Entities Cisco Account SE Teams Regional Channel Teams Cisco in Security As the threat landscape continues to expand and become more complex, at Cisco, we have been focusing on building a comprehensive portfolio that ensures end-to-end security for organizations of all sizes. We are continuing to invest in AI and leverage our impressive set of security offerings to protect everything that's connected to an organization, from apps and services to end users. This enables us to provide security that's better for users, easier for IT, and optimized for DevOps, making things safer for everyone. Through significant investments in cutting-edge advancements in artificial intelligence and machine learning, we are empowering security teams with simplified operations and heightened effectiveness. We've recently launched Cisco XDR, which is designed by SOC experts, for SOC experts, to simplify security operations. The introduction of the security service edge (SSE) solution by Cisco enhances hybrid work experiences and simplifies access across diverse locations, devices, and applications. This combines unique level of user simplicity and IT efficiency for frictionless access to all applications (not some) with modern security that delights users and frustrates attackers. Furthermore, Cisco is previewing the first generative AI capabilities within the Security Cloud, aiming to simplify security operations and increase efficiency. Moreover, new innovations across in Firewall, Multicloud, and Application Security, further deliver on Cisco's Security Cloud platform vision. Why Cisco #WeAreCisco. We are all unique, but collectively we bring our talents to work as a team, to develop innovative technology and power a more inclusive, digital future for everyone. How do we do it? Well, for starters – with people like you! Nearly every internet connection around the world touches Cisco. We’re the Internet’s optimists. Our technology makes sure the data traveling at light speed across connections does so securely, yet it’s not what we make but what we make happen which marks us out. We’re helping those who work in the health service to connect with patients and each other; schools, colleges, and universities to teach in even the most challenging of times. We’re helping businesses of all shapes and sizes to connect with their employees and customers in new ways, providing people with access to the digital skills they need and connecting the most remote parts of the world – whether through 5G, or otherwise. We tackle whatever challenges come our way. We have each other’s backs, we recognize our accomplishments, and we grow together. We celebrate and support one another – from big and small things in life to big career moments. And giving back is in our DNA (we get 10 days off each year to do just that). We know that powering an inclusive future starts with us. Because without diversity and a dedication to equality, there is no moving forward. Our 30 Inclusive Communities, that bring people together around commonalities or passions, are leading the way. Together we’re committed to learning, listening, caring for our communities, whilst supporting the most vulnerable with a collective effort to make this world a better place either with technology, or through our actions. So, you have colorful hair? Don’t care. Tattoos? Show off your ink. Like polka dots? That’s cool. Pop culture geek? Many of us are. Passion for technology and world changing? Be you, with us! #WeAreCisco Show more Show less
Posted 2 weeks ago
3.0 - 6.0 years
0 Lacs
Gurugram, Haryana, India
On-site
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. Risk Consulting - Protect Tech – Senior (IT audit – General skills) Key Responsibilities Your key responsibilities will include: Consistently deliver quality client services. Drive high-quality work products within expected timeframes and on budget. Monitor progress manage risk and ensure key stakeholders are kept informed about progress and expected outcomes. Foster relationships with client personnel to analyse, evaluate, and enhance information systems to develop and improve security at procedural and technology levels. Use knowledge of the current IT environment and industry trends to identify engagement and client service issues and communicate this information to the engagement team and client management through written correspondence and verbal presentations. Stay abreast of current business and industry trends relevant to the client's business. Demonstrate deep technical capabilities and professional knowledge. Demonstrate ability to quickly assimilate to new knowledge. Skills And Attributes For Success You will leverage your proven track record of IT Audit experience and strong personal skills, to effectively deliver quality results in the assessment, design, and support implementation of controls, security and IT risk solutions. To qualify for the role, you must have A bachelor’s or master’s degree and approximately 3-6 years of related work experience At least 2-4 years of experience in IT Risk and Compliance Design IT Risk Controls framework such as IT SOX Implementation and Testing of internal controls such as IT general controls, IT application controls, IPE related controls, interface controls etc. Identify control gaps, weaknesses and areas of improvements. Conducting IT internal control reviews, and review of SOC1 or SOC2 reports Knowledge of IT risk, information security or cyber security frameworks such as COSO, COBIT, ISO, NIST etc. IT Compliance and regulatory assessments – IT Risk and Controls assessment with exposure of any of the technologies such as SAP, Oracle, Workday, MS Dynamics or emerging technologies such as Cloud, RPA, AI/ML IT Infrastructure and Architecture risk assessments including data quality and data migration reviews, data privacy reviews, OS DB reviews etc. Strong exposure working in client facing roles, collaborate with cross functional teams including internal audits, IT security and business stakeholders to assess control effectiveness and facilitate remediation activities. Excellent communication, documentation and report writing skills. Good to have relevant industry certifications such as CISA, CISM, CISSP, CRISC, CCSK, ISO 27001, and others (as relevant) EY | Building a better working world EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today. Show more Show less
Posted 2 weeks ago
3.0 - 6.0 years
0 Lacs
Kolkata, West Bengal, India
On-site
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. Risk Consulting - Protect Tech – Senior (IT audit – General skills) Key Responsibilities Your key responsibilities will include: Consistently deliver quality client services. Drive high-quality work products within expected timeframes and on budget. Monitor progress manage risk and ensure key stakeholders are kept informed about progress and expected outcomes. Foster relationships with client personnel to analyse, evaluate, and enhance information systems to develop and improve security at procedural and technology levels. Use knowledge of the current IT environment and industry trends to identify engagement and client service issues and communicate this information to the engagement team and client management through written correspondence and verbal presentations. Stay abreast of current business and industry trends relevant to the client's business. Demonstrate deep technical capabilities and professional knowledge. Demonstrate ability to quickly assimilate to new knowledge. Skills And Attributes For Success You will leverage your proven track record of IT Audit experience and strong personal skills, to effectively deliver quality results in the assessment, design, and support implementation of controls, security and IT risk solutions. To qualify for the role, you must have A bachelor’s or master’s degree and approximately 3-6 years of related work experience At least 2-4 years of experience in IT Risk and Compliance Design IT Risk Controls framework such as IT SOX Implementation and Testing of internal controls such as IT general controls, IT application controls, IPE related controls, interface controls etc. Identify control gaps, weaknesses and areas of improvements. Conducting IT internal control reviews, and review of SOC1 or SOC2 reports Knowledge of IT risk, information security or cyber security frameworks such as COSO, COBIT, ISO, NIST etc. IT Compliance and regulatory assessments – IT Risk and Controls assessment with exposure of any of the technologies such as SAP, Oracle, Workday, MS Dynamics or emerging technologies such as Cloud, RPA, AI/ML IT Infrastructure and Architecture risk assessments including data quality and data migration reviews, data privacy reviews, OS DB reviews etc. Strong exposure working in client facing roles, collaborate with cross functional teams including internal audits, IT security and business stakeholders to assess control effectiveness and facilitate remediation activities. Excellent communication, documentation and report writing skills. Good to have relevant industry certifications such as CISA, CISM, CISSP, CRISC, CCSK, ISO 27001, and others (as relevant) EY | Building a better working world EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today. Show more Show less
Posted 2 weeks ago
8.0 - 12.0 years
0 Lacs
Mumbai Metropolitan Region
Remote
What You'll Do Businesses are witnessing rapid digital acceleration. Making it imperative for them to maintain Cyber resiliency there by preparing for, responding to, and recovering from cyber threats. A cyber-resilient organization can ensure business acceleration. And to achieve this Cyber resiliency businesses seek expert mentorship, best tools and services from trusted partners. Support Cisco account management as Cyber Security Sales Specialist Lead Cybersecurity engagement within aligned top enterprises and conglomerates Responsible for building Cisco security business pipeline & achieve the security annual targets from assigned enterprise accounts based on either Total control Value or incremental average contract value Identify new business opportunities by positioning solutions from the broad range of Cisco Secure solution addressing Secure Service Edge, Zero Trust Access, Application and Workload Security, SoC, Micro segmentation, Email Security, Multi Cloud Défense, Cloud-Native Application Protection Platform (CNAPP), Attack Surface Management and others Leverage Cisco strength in areas of digital transformation like network, application and compute. Work and build relationships with key decision-makers, especially Cybersecurity collaborators in the account. Provide ongoing and accurate visibility / status of pipeline and forecast Prepare detailed account development plans and engagement strategies Who You Are 8-12 years of experience in techno-commercial roles within the cybersecurity domain. Knowledge of new and emerging technologies in Cybersecurity domain. At least 3 years of experience in selling SaaS and Subscription delivery models. Understanding of the cybersecurity selling cycle. Experience putting together comprehensive account planning. Track record of success in overachieving sales quotas. Proven and consistent hunting skills (both initial penetration and cross-selling) Comfortable in communicating a sophisticated, technical proposition at an executive, corporate overview level, running first meetings with customers without a sales engineer. Understanding of NIST, CERTIN guidelines, mitre att&ck framework, OT Security. Industry certifications like CISSP, CSSP, CEH or Bachelor's Degree in Cybersecurity from institute of repute Good connects with Cybersecurity decision makers in regional enterprise accounts Good understanding of Cisco Security products. Understanding of engaging and driving channel partner Who You'll Work With Global Security Sales Organization – SE team Global Security Sales Organization – Hyper Sales Specialist & Engineers Cisco Account Manager Product Engineering BU across various Business Entities Cisco Account SE Teams Regional Channel Teams Cisco in Security As the threat landscape continues to expand and become more sophisticated, at Cisco, we have been focusing on building a comprehensive portfolio that ensures end-to-end security for organizations of all sizes. We are continuing to invest in AI and demonstrate our impressive set of security offerings to protect everything that's connected to an organization, from apps and services to end users. This enables us to provide security that's better for users, easier for IT, and optimized for DevOps, making things safer for everyone. Through significant investments in cutting-edge advancements in artificial intelligence and machine learning, we are empowering security teams with simplified operations and heightened efficiency. We've recently launched Cisco XDR, which is designed by SOC experts, for SOC experts, to simplify security operations. The introduction of the security service edge (SSE) solution by Cisco improves hybrid work experiences and simplifies access across diverse locations, devices, and applications. This combines unique level of user simplicity and IT efficiency for frictionless access to all applications (not some) with modern security that delights users and frustrates attackers. Furthermore, Cisco is previewing the first generative AI capabilities within the Security Cloud, aiming to simplify security operations and increase efficiency. Moreover, new innovations across in Firewall, Multicloud, and Application Security, further deliver on Cisco's Security Cloud platform vision. Why Cisco #WeAreCisco. We are all unique, but collectively we bring our talents to work as a team, to develop innovative technology and power a more inclusive, digital future for everyone. How do we do it? Well, for starters – with people like you! Nearly every internet connection around the world touches Cisco. We’re the Internet’s optimists. Our technology makes sure the data traveling at light speed across connections does so securely, yet it’s not what we make but what we make happen which marks us out. We’re helping those who work in the health service to connect with patients and each other; schools, colleges, and universities to teach in even the most challenging of times. We’re helping businesses of all shapes and sizes to connect with their employees and customers in new ways, providing people with access to the digital skills they need and connecting the most remote parts of the world – whether through 5G, or otherwise. We tackle whatever challenges come our way. We have each other’s backs, we recognize our accomplishments, and we grow together. We celebrate and support one another – from big and small things in life to big career moments. And giving back is in our DNA (we get 10 days off each year to do just that). We know that powering an inclusive future starts with us. Because without diversity and a dedication to equality, there is no moving forward. Our 30 Inclusive Communities, that bring people together around commonalities or passions, are leading the way. Together we’re committed to learning, listening, caring for our communities, whilst supporting the most vulnerable with a collective effort to make this world a better place either with technology, or through our actions. So, you have colorful hair? Don’t care. Tattoos? Show off your ink. Like polka dots? That’s cool. Pop culture geek? Many of us are. Passion for technology and world changing? Be you, with us! #WeAreCisco Show more Show less
Posted 2 weeks ago
3.0 - 5.0 years
0 Lacs
Mumbai Metropolitan Region
On-site
Responsibilities: As part of the Risk Advisory team deliver on engagements pertaining to information security, cyber security, risk management and privacy for our customers across the globe Responsible for managing and delivering on accounts in accordance with CyRAACS quality guidelines & methodologies. Execute the engagement requirements, prepare reports and schedules that will be delivered to clients and other parties Work effectively as a team member, sharing responsibility, providing support, maintaining communication and updating senior team members on progress Develop and maintain productive working relationships with client personnel Prepare status updates and prepare management presentations etc. Actively contribute to improving operational efficiency on projects & internal initiatives. Assist in creating innovative insights for clients, adapt methods & practices to fit operational team needs to contribute to thought leadership documents and develop new methodologies. Understand and follow workplace policies and procedures Flexible to travel to client location for the project delivery Desired skills: 3-5 years experience (preferably in consulting environment) Strong knowledge of cyber / information security concepts, risk and controls concepts Strong knowledge of any standards such as ISO 27001/2, ISO 22301, ISO 27018, PCI DSS, NIST standards on Cyber Security, HITRUST, etc. Good knowledge of IT risk and control / audit environment Good understanding of IT Management Frameworks such as COBIT, ITIL and regulations such as RBI Guidelines, PCI Compliance, GDPR, HIPAA] etc. Knowledge of vulnerability management A good understanding of IT data center operations and a variety of technology platforms Excellent business communication skills, proficient in reporting and documentation Ability to deliver work within tight timescales, to budget and to a high quality Demonstrate attention to detail ISO 27001 Lead Auditor and Lead Implementer preferred. Conceptual knowledge of domains in CISSP, CISA, CISM etc. Show more Show less
Posted 2 weeks ago
3.0 - 6.0 years
0 Lacs
Kanayannur, Kerala, India
On-site
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. Risk Consulting - Protect Tech – Senior (IT audit – General skills) Key Responsibilities Your key responsibilities will include: Consistently deliver quality client services. Drive high-quality work products within expected timeframes and on budget. Monitor progress manage risk and ensure key stakeholders are kept informed about progress and expected outcomes. Foster relationships with client personnel to analyse, evaluate, and enhance information systems to develop and improve security at procedural and technology levels. Use knowledge of the current IT environment and industry trends to identify engagement and client service issues and communicate this information to the engagement team and client management through written correspondence and verbal presentations. Stay abreast of current business and industry trends relevant to the client's business. Demonstrate deep technical capabilities and professional knowledge. Demonstrate ability to quickly assimilate to new knowledge. Skills And Attributes For Success You will leverage your proven track record of IT Audit experience and strong personal skills, to effectively deliver quality results in the assessment, design, and support implementation of controls, security and IT risk solutions. To qualify for the role, you must have A bachelor’s or master’s degree and approximately 3-6 years of related work experience At least 2-4 years of experience in IT Risk and Compliance Design IT Risk Controls framework such as IT SOX Implementation and Testing of internal controls such as IT general controls, IT application controls, IPE related controls, interface controls etc. Identify control gaps, weaknesses and areas of improvements. Conducting IT internal control reviews, and review of SOC1 or SOC2 reports Knowledge of IT risk, information security or cyber security frameworks such as COSO, COBIT, ISO, NIST etc. IT Compliance and regulatory assessments – IT Risk and Controls assessment with exposure of any of the technologies such as SAP, Oracle, Workday, MS Dynamics or emerging technologies such as Cloud, RPA, AI/ML IT Infrastructure and Architecture risk assessments including data quality and data migration reviews, data privacy reviews, OS DB reviews etc. Strong exposure working in client facing roles, collaborate with cross functional teams including internal audits, IT security and business stakeholders to assess control effectiveness and facilitate remediation activities. Excellent communication, documentation and report writing skills. Good to have relevant industry certifications such as CISA, CISM, CISSP, CRISC, CCSK, ISO 27001, and others (as relevant) EY | Building a better working world EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today. Show more Show less
Posted 2 weeks ago
7.0 years
0 Lacs
Hyderabad, Telangana, India
On-site
Job Title : Data Center Technical Support Analyst Start date -Immediate Please share profile asap. Location -Pan india -Hybrid Experience Required : 7 to 15 Year(s) CTC Range : 5 to 19 LPA Shift: 24/7 Work Mode: Hybrid Full time with Varite Openings: 2 Company Name: VARITE INDIA PRIVATE LIMITED About The Client: A global IT services and consulting company, multinational information technology (IT), headquartered in Tokyo, Japan. The Client offers a wide array of IT services, including application development, infrastructure management, and business process outsourcing. Their consulting services span business and technology, while their digital solutions focus on transformation and user experience design. It excels in data and intelligence services, emphasizing analytics, AI, and machine learning. Additionally, their cybersecurity, cloud, and application services round out a comprehensive portfolio designed to meet the diverse needs of businesses worldwide. About The Job: Role : Data Center Technical Support Analyst Experience : 7+ Years of relevant experience Location : Any NTT Data Location Shift Timing : 24 * 7 Rotational Shift Essential Job Functions: MUST HAVE Required Skills • 7+ years of designing application architectures that include incorporating industry standards such as MITA 3.5, HIPAA, NIST, and other applicable standards required • Excellent knowledge of systems software / hardware, networks and operating systems. • Exceptional knowledge of processes and tools utilized for system management, problem reporting, change management and support tools. • Must have knowledge of one or more of the following products: IBM Decision Center, IBM Decision Server, Software AG webMethods, Broadcom/Software AG API Gateway. • knowledge in one or more of the following products: Dell Nutanix, Dell VxRail, VMware ESXi/vCenter/NSX/SRM, Microsoft Windows Server, RedHat Enterprise Linux, MS SQL Server, Nagios, NewRelic APM/Infrastructure/Browser, Octopus Deploy, Puppet, Splunk, Veracode. Qualifications: referred Skills • Prior Experience supporting on-prem Data Center and cloud for State and/or Federal agencies. (Government projects) Role Summary: Provides ongoing systems administration support including installation, customization, maintenance and troubleshooting of hardware / software systems. Provides technical support and advises on the use of programming tools, database systems and networks. Provides support to address the availability and reliability issues on systems (Windows/Unix/Mainframe) across multiple locations. Evaluates and integrates new operating system versions, drivers and hardware. Operational responsibilities include remediation of daily incident tickets, system compliance responsibilities, system run enhancement testing and staging, policy / procedure enhancements and adherence, client contact coordination and operational recommendations. Monitors and tunes the system to achieve optimum performance levels in standalone and multi-tiered environments. Implements appropriate levels of system security. Prescribes system backup / disaster recovery procedures and directs recovery operations in the event of destruction of all or part of the operating system or other system components. Ensures 24x7 after-hour support. Responsibilities: • Researches, evaluates, and recommends software packages in support of system architecture needs. • Defines specifications and requirements for software package modification and customizations. • Plans, coordinates, and manages installation, maintenance, and modification of software packages. • Participates in software package performance, troubleshooting, and problem resolution. • Provides coordination with software vendors. • Provide requirements and advises for software packages to end users, administrators and technical support personnel for hardware and network design, documentation, troubleshooting, and technical training. • Participates in establishing departmental policy with regard to data definition, data relationships, database design, database implementation, database operation, database security, and data accessibility. • Perform database planning, administration, data standards, database security, and database documentation for software packages. • Reviews the feasibility and advisability of proposed additions and modifications to the database. • Install and customize software and hardware in order to manage, monitor, and otherwise support an enterprise system. • Performs monitoring of network, hardware, and storage capacity, through the implementation of an inventory management system. • Designs and implements integrations of software packages. • Consults with software vendors to evaluate software and hardware for enterprise network management. • Defines and manages the configuration of data on network software and hardware components. • Monitor all attached devices in a complex LAN environment, such as workstations, servers, bridges, and multi-station access units, including analyzing performance, diagnosing performance problems, and performing load balancing. • Understands large scale multi-tenant software products supporting multiple government agencies. • Understands large scale software integrations of multiple software products. How to Apply: Interested candidates are invited to submit their resume using the apply online button on this job post. About VARITE: VARITE is a global staffing and IT consulting company providing technical consulting and team augmentation services to Fortune 500 Companies in USA, UK, CANADA and INDIA. VARITE is currently a primary and direct vendor to the leading corporations in the verticals of Networking, Cloud Infrastructure, Hardware and Software, Digital Marketing and Media Solutions, Clinical Diagnostics, Utilities, Gaming and Entertainment, and Financial Services. Equal Opportunity Employer: VARITE is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, marital status, veteran status, or disability status. Unlock Rewards: Refer Candidates and Earn. If you're not available or interested in this opportunity, please pass this along to anyone in your network who might be a good fit and interested in our open positions. VARITE offers a Candidate Referral program, where you'll receive a one-time referral bonus based on the following scale if the referred candidate completes a three-month assignment with VARITE. Exp Req - Referral Bonus 0 - 2 Yrs. - INR 5,000 2 - 6 Yrs. - INR 7,500 6 + Yrs. - INR 10,000 Show more Show less
Posted 2 weeks ago
3.0 - 6.0 years
0 Lacs
Trivandrum, Kerala, India
On-site
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. Risk Consulting - Protect Tech – Senior (IT audit – General skills) Key Responsibilities Your key responsibilities will include: Consistently deliver quality client services. Drive high-quality work products within expected timeframes and on budget. Monitor progress manage risk and ensure key stakeholders are kept informed about progress and expected outcomes. Foster relationships with client personnel to analyse, evaluate, and enhance information systems to develop and improve security at procedural and technology levels. Use knowledge of the current IT environment and industry trends to identify engagement and client service issues and communicate this information to the engagement team and client management through written correspondence and verbal presentations. Stay abreast of current business and industry trends relevant to the client's business. Demonstrate deep technical capabilities and professional knowledge. Demonstrate ability to quickly assimilate to new knowledge. Skills And Attributes For Success You will leverage your proven track record of IT Audit experience and strong personal skills, to effectively deliver quality results in the assessment, design, and support implementation of controls, security and IT risk solutions. To qualify for the role, you must have A bachelor’s or master’s degree and approximately 3-6 years of related work experience At least 2-4 years of experience in IT Risk and Compliance Design IT Risk Controls framework such as IT SOX Implementation and Testing of internal controls such as IT general controls, IT application controls, IPE related controls, interface controls etc. Identify control gaps, weaknesses and areas of improvements. Conducting IT internal control reviews, and review of SOC1 or SOC2 reports Knowledge of IT risk, information security or cyber security frameworks such as COSO, COBIT, ISO, NIST etc. IT Compliance and regulatory assessments – IT Risk and Controls assessment with exposure of any of the technologies such as SAP, Oracle, Workday, MS Dynamics or emerging technologies such as Cloud, RPA, AI/ML IT Infrastructure and Architecture risk assessments including data quality and data migration reviews, data privacy reviews, OS DB reviews etc. Strong exposure working in client facing roles, collaborate with cross functional teams including internal audits, IT security and business stakeholders to assess control effectiveness and facilitate remediation activities. Excellent communication, documentation and report writing skills. Good to have relevant industry certifications such as CISA, CISM, CISSP, CRISC, CCSK, ISO 27001, and others (as relevant) EY | Building a better working world EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today. Show more Show less
Posted 2 weeks ago
0.0 - 2.0 years
3 - 7 Lacs
Navi Mumbai
Work from Office
Title We are hiring a full-time Information Security Analyst who is technical, dedicated to learning new things, security-minded, has strong initiative, and is able to manage projects autonomously. The Information Security team defends the company’s digital infrastructure by designing, implementing, and improving the company’s cybersecurity architecture. This is a critical role responsible for protecting infrastructure, cloud, edge devices, and data against unauthorized use, modification, exfiltration, or damage. If you’re excited to be part of a fast-growing, then Medpace is a great place to grow your career. Overview Medpace is a full-service clinical contract research organization (CRO). We provide Phase I-IV clinical development services to the biotechnology, pharmaceutical and medical device industries. Our mission is to accelerate the global development of safe and effective medical therapeutics through its scientific and disciplined approach. We leverage local regulatory and therapeutic expertise across all major areas including oncology, cardiology, metabolic disease, endocrinology, central nervous system, anti-viral and anti-infective. Headquartered in Cincinnati, Ohio, employing more than 5,000 people across 40+ countries. Responsibilities Engineer security solutions without oversight while collaborating with multiple internal departments and vendors; Analyze security systems and seek continuous improvements; Research vulnerabilities, perform vulnerability scanning and alleviate threats; Mature security best practices and policies internal to the organization; Develop new processes while cross-training coworkers and assisting employees on security-related matters; Provide security awareness training and testing for employees to verify proper security protocols are being adhered to; Performing cyber security incident triage, reviewing logs, and performing remediation activities; and Review and reduce inappropriate/overprovisioned access to drive least privileged access. Qualifications Minimum of bachelor's degree, preferably in Cybersecurity or Information Technology’ Prior Internship/co-op experience within Information Security; Understanding of security best practices and how to implement them at a business-wide level; Experience with managing, configuring, and deploying enterprise-grade security solutions in some of the following: SIEM Privileged Access Management/Identity Access Endpoint Detection & Response Cloud based architecture such as Azure/AWS Active Directory Exceptional communication skills; and Fundamental scripting skills, such as PowerShell/Python. Nice to have: Experience with vulnerability assessment tools such as Nessus and Tenable; Experience with enterprise web proxy solutions, web filters, and VPN such as Zscaler; Experience with governing Windows environment including GPO; Previous employment or experience in a highly regulated industry such as healthcare, financial, or defense experience with standards such as ISO, NIST, HIPPA, and/or SOC2; and Auditing and policy-writing experience. People. Purpose. Passion. Make a Difference Tomorrow. Join Us Today. The work we’ve done over the past 30+ years has positively impacted the lives of countless patients and families who face hundreds of diseases across all key therapeutic areas. The work we do today will improve the lives of people living with illness and disease in the future. Medpace Perks Flexible work environment Competitive compensation and benefits package Competitive PTO packages Structured career paths with opportunities for professional growth Company-sponsored employee appreciation events Employee health and wellness initiatives Awards Recognized by Forbes as one of America's Most Successful Midsize Companies in 2021, 2022, 2023 and 2024 Continually recognized with CRO Leadership Awards from Life Science Leader magazine based on expertise, quality, capabilities, reliability, and compatibility What to Expect Next A Medpace team member will review your qualifications and, if interested, you will be contacted with details for next steps. EO/AA Employer M/F/Disability/Vets
Posted 2 weeks ago
5.0 - 10.0 years
15 - 27 Lacs
Pune
Hybrid
Hi Everyone, I am on lookout for Specialist S&I NIST for a leading product based MNC in Kharadi, Pune. Kindly refer below JD and share your resume on pallavi.ag@peoplefy.com Job Description Summary:- Experience with Audit, Compliance and Regulatory for IT landscape Strong IT Security experience Good understanding with Security principles and Security Frameworks NIST and ISO 27001 experience for 5 years Developed and implemented NIST and/or ISO frameworks within IT Security Landscape
Posted 2 weeks ago
2.0 - 7.0 years
10 - 15 Lacs
Mumbai
Remote
Responsibilities: Participate in development and implementation of product specifications in conjunction with Product Management. Pay attention to feasibility, system/feature integration and performance expectations. Work with stakeholders in the company (E.g. Product Management, Architects, Engineers; but not limited to) to determine needs of new product features, releases and overall platform. Participate in all phases of technology development of a product release. Mentor and Collaborate with Product teams implementing releases in accordance with the architecture. Adhere to the requirements and guidelines for process, quality, security etc. Participating in Agile practices of the team/organization as a team player. Adaptability to learn and enhance skills in the domain of data security alongside the products technical environment (like OS, cloud technology, container orchestration, native programming language of the environment, hardware etc.) Ability to be a good team player and soft skilled person. Qualifications: 2+ years of post-bachelor’s degree experience in software development 2+ years of design, development, test & integration of application software written in Python & Linux Good understanding of Linux OS and internals Experience on any or multiple of programming languages like Go/Java Knowledge of Public Cloud technologies like AWS/GCP/Azure Knowledge of testing frameworks, such as pytest and Robot Framework Should be strong at debugging, troubleshooting, profiling own’s code as well as reviewing that of peers Sufficient knowledge of office productivity tools to represent formal exchange of technical content communication especially architecture and design Excellent verbal and written communication skills along with good rapport and collaboration with teammates Good to have skills Knowledge of software performance measurement and tuning Understanding of software security requirements and associated standards like NIST, OWASP, PCI-DSS etc Has gone through a devops cycle, CI/CD pipelines and software test automations Knowledge of cryptography and cryptographic algorithms Know of Agile process for product delivery Preferred Qualifications Background to computer science and systems Experience on Python programming language, Shell Scripting and Linux OS Knowledge of Public Cloud technologies like AWS/GCP/Azure Has gone through Application Design/architecture lifecycle
Posted 2 weeks ago
5.0 - 7.0 years
8 - 14 Lacs
Coimbatore
Work from Office
We are looking for an experienced Cybersecurity Engineer with 5+ years of experience, including a minimum of 3 years working in an Azure cloud environment, to join our team. The ideal candidate will have expertise in designing, implementing, and maintaining cloud security solutions to protect our infrastructure, applications, and data. As part of the cybersecurity team, you will work to ensure the confidentiality, integrity, and availability of our systems and data within Microsoft Azure. You will be responsible for leveraging a range of Azure security tools, maintaining best practices, and ensuring the organization is protected from emerging security threats. Key Responsibilities : - Lead and implement security solutions in the Azure cloud environment using tools such as Azure Security Center, Azure Sentinel, Azure AD, and Key Vault. - Configure, monitor, and optimize Azure Security Center and Microsoft Defender for Cloud to ensure the highest level of security. - Implement and enforce identity and access management (IAM) policies using Azure Active Directory (Azure AD), ensuring secure user authentication, authorization, and access control. - Use SIEM (Security Information and Event Management) tools like Azure Sentinel to monitor and respond to security events, conducting proactive threat hunting and incident response. - Investigate security breaches and potential threats, providing detailed incident reports and recommending corrective actions. - Conduct vulnerability assessments and coordinate with other teams to address and resolve security issues. - Work closely with cloud-native security tools like Azure Sentinel, Microsoft Defender for Identity, and Azure Key Vault to ensure seamless encryption and secure key management. - Collaborate with DevOps and development teams to embed security practices into the CI/CD pipeline (DevSecOps) within Azure DevOps, securing applications from development through deployment. - Review and analyze cloud logs, vulnerabilities, and risk factors to implement appropriate remediation measures in the Azure cloud environment. - Ensure the security architecture complies with established security frameworks and standards such as NIST, CIS, SOC 2, GDPR, and ISO 27001. - Conduct risk assessments and ensure compliance with industry regulations and internal policies, maintaining comprehensive documentation for audits and assessments. - Implement controls to meet organizational compliance goals while ensuring data privacy and security. - Automate security tasks and monitoring using tools such as PowerShell, Azure CLI, or Terraform for Infrastructure as Code (IaC). - Create and maintain automation scripts to enforce security policies, automate response actions, and integrate security measures into Azure environments. - Secure containerized applications and microservices deployed on Azure Kubernetes Service (AKS). - Implement best practices to secure Docker containers and ensure security in AKS environments, including image scanning, vulnerability management, and runtime protection. - Collaborate with IT teams, development teams, and security architects to define and implement security policies, protocols, and standards. - Participate in regular security audits and ensure that all security policies are enforced and maintained across the organization's Azure environment. - Provide cybersecurity training and guidance to employees to foster a security-aware culture within the organization. - 5+ years of experience in cybersecurity, with at least 3 years of experience working within an Azure cloud environment. - Expertise in Azure cloud security services, including Azure Security Center, Azure Sentinel, Azure AD, and Azure Key Vault. - Hands-on experience in managing cloud security policies, configuring role-based access control (RBAC), and enforcing encryption techniques across Azure resources - Proficiency in using SIEM tools such as Azure Sentinel to monitor, analyze, and respond to security incidents. - Experience with cloud security best practices, including encryption, identity management, vulnerability scanning, and incident response. - Strong knowledge of security frameworks and standards such as NIST, CIS, SOC 2, GDPR, and ISO 27001. - Proficient with scripting and automation tools like PowerShell, Azure CLI, and Terraform for automating security tasks and cloud infrastructure. - Familiarity with container security in Azure Kubernetes Service (AKS) and microservices environments.
Posted 2 weeks ago
15.0 years
0 Lacs
Chennai, Tamil Nadu, India
On-site
Job Description Title “Director – Fraud Surveillance” The Purpose Of Your Role As a Team Leader Fraud Surveillance, you will be responsible for leading a team tasked with preventing financially motivated criminals from causing significant financial exposure to the firm. The team is tasked with vetting fraud detection output, and all aspects of responding to fraud incidents. Our environment is fast-paced and requires frequent changes in how we operate based on the latest criminal tactics. As the leader of this team, the candidate will have the opportunity to influence how we react to these changes and coach a team of highly motivated fraud analysts. You will also drive innovation and engage leadership stakeholders, learn from failures while celebrating success. You are committed to developing your own expertise and knowledge to ensure you bring the latest thinking to your role. You will be crucial to identify suspected frauds and assess the impacts of fraud incidents and accountable to meet Incident process and communication. The Team Fraud Surveillance is part of Risk’s Financial Intelligence Unit (FIU) and plays a critical, role in the protection of Fidelity assets from account takeover, account owner fraud and Identity theft. Fraud Surveillance Analysts are working together with FIU’s Cyber Fraud Fusion Center and Investigation Teams as well as business partners across the enterprise. The Value You Deliver Accountable to build capability for customer account Fraud and Fraud Surveillance (Money Movement, Financial Fraud), manage team and influence global leadership stakeholders. Assess Fraud analytics to identify fraud trends / patterns, investigate suspected fraud and assess impact and leadership communication. Review business transaction behavior to identify suspected frauds. Fraud incidents caused due to (not limited to): Financial Transaction Fraud Third party transfer ACH, Wire transfer Debit & Credit card Fraud Account Takeover Fraud Account Owner Fraud Liaise with detection and analytics teams to help build out data models needed for fraud analytics. Capacity planning, Talent Development and Building team to enable 24X7 fraud prevention. Ensure closure of action points from fraud Investigations and present the Incident summary, learnings, new controls and process improvements to the management. Ensure fraud policies, processes and systems are aligned with changing regulatory and business need. Enable capability to monitor and build appropriate alerting / reporting for emerging fraud attacks. Enable automation of fraud identification & incident closure processes. Obtaining and monitoring reports from Audit, Collections, Customer Service, Finance, Credit, Risk, and Customer Complaints to identify red flags/ early warning signals of fraud Enable conducting periodic reviews of key processes and systems to identify gaps in terms of fraud and operational risk, and suggest controls to address the same Conduct investigations of customer frauds, including Root Cause Analysis and suggest measures to strengthen existing processes and systems Ability to build incident/case summary and present to leadership stakeholders Work with the Detection team to build & deploy fraud rules in production; and, to review adequacy of controls to mitigate fraud at the design stage Accountable for the strategic build-out of the fraud incidents metrics on a regular basis and continuous improvement Give feedback to Design fraud risk dashboards, identify high-risk areas & parameters, and resolve the same with relevant teams. Influencing operational efficiencies, policies & procedures Required Skills SME in setting up US Financial Surveillance capability, assessing financial frauds impacts Identify suspected Fraud from Login, Money movement, trading and business transactions. SME to detect Account Take Over, Identity theft and account owner frauds, identify Debit and credit card frauds, Third party money transfer frauds, Crypto currency fraud, suspicious financial activities You have very strong analytical, Critical thinking, communication and leadership skills Sound understanding of US Bank operations, financial operations, payments, money movement processes, and the fraud trends and controls. A total of 15 years of experience working in roles with responsibilities and a minimum of 5-7 years Fraud detection and Surveillance and additionally US Bank operations experience is preferred. Ability to communicate effectively with stakeholders and senior management, including Board Committee members, both verbally and in written presentations. Ability to balance risk, potential impact, resourcing, business drivers, and timelines Strong understanding of / ability to interpret regulatory requirements for financial services The Expertise We’re Looking For Prior experience managing people preferred Previous Risk/Supervisory/Compliance/Fraud/Anti-Money Laundering experience a plus Detailed knowledge of brokerage and institutional operations Must have US Bank fraud operations expertise How Your Work Impacts Organization Fidelity is rated as one of the most trusted brands in the US Financial industry and “Enterprise Cyber Security (ECS)” is one of the key contributors. Protecting customers’ assets is amongst the top priorities of Fidelity and ECS is entrusted with engaging initiatives to protect Fidelity’s information against diverse cyber threats. It’s a dynamic organization with a highly experienced and competent team with organization & operations aligned with NIST Cyber Security Framework. The team is focused on managing both classical as well evolving risk areas through an optimal combination of People, Process and Technology. Its operations span across the globe to have 24*7 protections to Fidelity’s assets. Location: Chennai Shift timings: Mostly Business as Usual, few times you will work during weekend and off Business hours for escalation. Certifications Category: Information Technology Show more Show less
Posted 2 weeks ago
5.0 years
0 Lacs
Chennai, Tamil Nadu, India
On-site
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. EY- Cyber Security Strategy, Risk, Compliance and Resilience – Technology Consulting – Senior As part of our EY Strategy, Risk, Compliance and Resilience (SRCR) Technology Consulting team, you would work on various SRCR projects for our customers across the globe. An important part of your role will be to actively establish, maintain and strengthen internal and external relationships. You’ll also identify potential business opportunities for EY and GDS within existing engagements and escalate these as appropriate. Similarly, you’ll anticipate and identify risks within engagements and share any issues with senior members of the team. In line with EY’s commitment to quality, you’ll confirm that work is of the highest quality as per EY’s quality standards and is reviewed by the next-level reviewer. As an influential member of the team, you’ll help to create a positive learning culture, coach and counsel junior team members and help them to develop. The opportunity We’re looking for Senior Security Consultant with expertise in cyber / information security, risk and controls concepts. This is a fantastic opportunity to be part of a leading firm whilst being instrumental in the growth of a new service offering. Your Key Responsibilities Engage in Cyber Strategy & Governance, Cyber Risk & Compliance, Cyber Resilience, Cyber Transformation and Co-Sourcing, Application & Network Security engagements Work effectively as a team member, sharing responsibility, providing support, maintaining communication and updating senior team members on progress. Execute the engagement requirements, along with review of work by junior team members. Help prepare reports and schedules that will be delivered to clients and other parties. Develop and maintain productive working relationships with client personnel. Build strong internal relationships within EY Consulting Services and with other services across the organization Contribute to people related initiatives including recruiting and retaining Cyber Transformation professionals Maintain an educational program to continually develop personal skills of staff Understand and follow workplace policies and procedures Building a quality culture at GDS Help senior team members in performance reviews and contribute to performance feedback for staff/junior level team members Manage the performance management for the direct reportees, as per the organization policies. Foster teamwork and lead by example; training and mentoring of project resources Participating in the organization-wide people initiatives Skills And Attributes For Success Hands-on experience of more than 5 years with key components of cybersecurity including (but not limited to): Vendor/3rd Party Risk Management & Assessment Cyber Strategy & Governance, Cyber Transformation, Cyber Dashboarding Regulations/standards such as ISO 27001, PCI DSS, HIPAA, HITRUST, GDPR, CCPA, FISMA/FEDRAMP, COBIT, OWASP Top 10, NIST 800-53 Business Continuity & Disaster Recovery Must have experience in working in client facing roles, interacting with the third parties, assessing different kinds of environments (IT and non-IT) and ability to apply cyber security concepts in all these sectors. Experienced in creation and review of security policy/procedures, and in performing risk assessments. Good to have experience in assessing ITGC requirements across various industries including both Cybersecurity and resilience requirements. Should have a good understanding of VAPT process, common application security vulnerabilities, exploitation techniques and remediation measures. Basic understanding of Network Security and network architecture diagram reviews, access and perimeter control, vulnerability management and intrusion detection, firewall rule-based reviews. Good understanding of logging and monitoring tools (SIEM). Knowledge in any one of the SIEM tools is a plus. To qualify for the role, you must have: BE - B. Tech / MCA / M. Tech/ MBA with background in computer science and programming. More than 5 Years of relevant experience. Strong Excel and PowerPoint skills. Should be proficient in leading medium to large engagements and coach junior staff. Ideally, you’ll also have CISSP, CISA, CISM, CEH, ISO 27001 Lead Auditor and Lead Implementer. Project management skills. What We Look For A team of people with commercial acumen, technical experience and enthusiasm to learn new things in this fast-moving environment with consulting skills. An opportunity to be a part of market-leading, multi-disciplinary team of 1400 + professionals, in the only integrated global transaction business worldwide. Opportunities to work with EY Consulting practices globally with leading businesses across a range of industries. What Working At EY Offers At EY, we’re dedicated to helping our clients, from start–ups to Fortune 500 companies — and the work we do with them is as varied as they are. You get to work with inspiring and meaningful projects. Our focus is education and coaching alongside practical experience to ensure your personal development. We value our employees and you will be able to control your own development with an individual progression plan. You will quickly grow into a responsible role with challenging and stimulating assignments. Moreover, you will be part of an interdisciplinary environment that emphasizes high quality and knowledge exchange. Plus, we offer: Support, coaching and feedback from some of the most engaging colleagues around Opportunities to develop new skills and progress your career The freedom and flexibility to handle your role in a way that’s right for you EY | Building a better working world EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today. Show more Show less
Posted 2 weeks ago
5.0 years
0 Lacs
Pune, Maharashtra, India
On-site
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. EY- Cyber Security Strategy, Risk, Compliance and Resilience – Technology Consulting – Senior As part of our EY Strategy, Risk, Compliance and Resilience (SRCR) Technology Consulting team, you would work on various SRCR projects for our customers across the globe. An important part of your role will be to actively establish, maintain and strengthen internal and external relationships. You’ll also identify potential business opportunities for EY and GDS within existing engagements and escalate these as appropriate. Similarly, you’ll anticipate and identify risks within engagements and share any issues with senior members of the team. In line with EY’s commitment to quality, you’ll confirm that work is of the highest quality as per EY’s quality standards and is reviewed by the next-level reviewer. As an influential member of the team, you’ll help to create a positive learning culture, coach and counsel junior team members and help them to develop. The opportunity We’re looking for Senior Security Consultant with expertise in cyber / information security, risk and controls concepts. This is a fantastic opportunity to be part of a leading firm whilst being instrumental in the growth of a new service offering. Your Key Responsibilities Engage in Cyber Strategy & Governance, Cyber Risk & Compliance, Cyber Resilience, Cyber Transformation and Co-Sourcing, Application & Network Security engagements Work effectively as a team member, sharing responsibility, providing support, maintaining communication and updating senior team members on progress. Execute the engagement requirements, along with review of work by junior team members. Help prepare reports and schedules that will be delivered to clients and other parties. Develop and maintain productive working relationships with client personnel. Build strong internal relationships within EY Consulting Services and with other services across the organization Contribute to people related initiatives including recruiting and retaining Cyber Transformation professionals Maintain an educational program to continually develop personal skills of staff Understand and follow workplace policies and procedures Building a quality culture at GDS Help senior team members in performance reviews and contribute to performance feedback for staff/junior level team members Manage the performance management for the direct reportees, as per the organization policies. Foster teamwork and lead by example; training and mentoring of project resources Participating in the organization-wide people initiatives Skills And Attributes For Success Hands-on experience of more than 5 years with key components of cybersecurity including (but not limited to): Vendor/3rd Party Risk Management & Assessment Cyber Strategy & Governance, Cyber Transformation, Cyber Dashboarding Regulations/standards such as ISO 27001, PCI DSS, HIPAA, HITRUST, GDPR, CCPA, FISMA/FEDRAMP, COBIT, OWASP Top 10, NIST 800-53 Business Continuity & Disaster Recovery Must have experience in working in client facing roles, interacting with the third parties, assessing different kinds of environments (IT and non-IT) and ability to apply cyber security concepts in all these sectors. Experienced in creation and review of security policy/procedures, and in performing risk assessments. Good to have experience in assessing ITGC requirements across various industries including both Cybersecurity and resilience requirements. Should have a good understanding of VAPT process, common application security vulnerabilities, exploitation techniques and remediation measures. Basic understanding of Network Security and network architecture diagram reviews, access and perimeter control, vulnerability management and intrusion detection, firewall rule-based reviews. Good understanding of logging and monitoring tools (SIEM). Knowledge in any one of the SIEM tools is a plus. To qualify for the role, you must have: BE - B. Tech / MCA / M. Tech/ MBA with background in computer science and programming. More than 5 Years of relevant experience. Strong Excel and PowerPoint skills. Should be proficient in leading medium to large engagements and coach junior staff. Ideally, you’ll also have CISSP, CISA, CISM, CEH, ISO 27001 Lead Auditor and Lead Implementer. Project management skills. What We Look For A team of people with commercial acumen, technical experience and enthusiasm to learn new things in this fast-moving environment with consulting skills. An opportunity to be a part of market-leading, multi-disciplinary team of 1400 + professionals, in the only integrated global transaction business worldwide. Opportunities to work with EY Consulting practices globally with leading businesses across a range of industries. What Working At EY Offers At EY, we’re dedicated to helping our clients, from start–ups to Fortune 500 companies — and the work we do with them is as varied as they are. You get to work with inspiring and meaningful projects. Our focus is education and coaching alongside practical experience to ensure your personal development. We value our employees and you will be able to control your own development with an individual progression plan. You will quickly grow into a responsible role with challenging and stimulating assignments. Moreover, you will be part of an interdisciplinary environment that emphasizes high quality and knowledge exchange. Plus, we offer: Support, coaching and feedback from some of the most engaging colleagues around Opportunities to develop new skills and progress your career The freedom and flexibility to handle your role in a way that’s right for you EY | Building a better working world EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today. Show more Show less
Posted 2 weeks ago
5.0 - 7.0 years
0 Lacs
Hyderabad, Telangana, India
On-site
Summary The RealPage Information Security Operations team monitors and manages risks associated with threats and vulnerabilities faced by our infrastructure, platforms, and systems. We work closely with our teammates from IT, Product Development, and across the business to coordinate and execute our vulnerability management and incident response strategies and capabilities. We work with industry-leading tools and implement creative solutions to complex problems. What You’ll Do As an Incident Response Engineer, you will work directly with our security teams and partners across IT and the Application teams to contain and remediate security incidents, as well as designing solutions to improve the overall security architecture for the enterprise. Success in this role will be determined by your deep analytical expertise, including deep packet analysis, malware analysis, de-obfuscation skills, insights into endpoint analytics, and detailed log analysis. You will be called upon to flex your offensive security skills to drive rapid containment and remediation of security incidents, as well as your interpersonal skills to coordinate response with your teammates. Broad experience with security analytics including host logs, endpoint investigations, and network analysis are critical skills for this role. Primary Responsibilities Drive and co-ordinate containment and remediation efforts during a security incident with cross functional teams. Collect and analyze key data and telemetry during a security incident. Complete all required incident documentation and reporting within established time frames. Drive improvements from incident lessons learned. Develop playbook\SOP to improve Incident Response processes to align with industry guidelines and standards. Develop and implement security monitoring use cases driven by threat intelligence. Conduct periodic threat hunting exercises to actively discover suspicious activity across the enterprise. Participate in periodic exercises to test the effectiveness of IR\SOC process and controls. Required Knowledge/Skills/Abilities Bachelor's degree and 5 to 7 years of experience in Incident Response and SOC. Additional relevant experience and professional certifications will be considered in lieu of a degree. Understanding of host-based and network security logging. Experience in usage of enterprise security solutions. Understanding related to security encompassing end point technologies, applications, application hosting, physical and virtual data center hosting. Experience with security practices such as security incident response and risk management. Excellent verbal and written communication skills with a wide range of audiences including technologists, executives, business stakeholders and IT team members. Must be a critical thinker with strong problem-solving skills. Knowledge and understanding of relevant legal and regulatory requirements. Knowledge of information security management frameworks, such as ISO 27001, ITIL, COBIT or NIST, MITRE. High level of personal integrity, and the ability to professionally handle confidential matters and show an appropriate level of judgment and maturity. High degree of initiative, dependability, and ability to work with little supervision. Proven ability in security process and organizational design; Current understanding of Industry trends and emerging threats; and knowledge of incident response methodologies and technologies. QUALIFICATION Degree in applicable field Professional information security certification, such as GCIA, GCIH, or OSCP Knowledge of common security frameworks and regulations including FFIEC, NYDFS and NIST Cybersecurity Framework In-depth and hands-on experience with Security Analytics and Incident Response, Forensic Analysis, Malware analysis. Knowledge in Scripting languages (e.g. BASH, Python, etc) Show more Show less
Posted 2 weeks ago
5.0 years
0 Lacs
Trivandrum, Kerala, India
On-site
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. EY- Cyber Security Strategy, Risk, Compliance and Resilience – Technology Consulting – Senior As part of our EY Strategy, Risk, Compliance and Resilience (SRCR) Technology Consulting team, you would work on various SRCR projects for our customers across the globe. An important part of your role will be to actively establish, maintain and strengthen internal and external relationships. You’ll also identify potential business opportunities for EY and GDS within existing engagements and escalate these as appropriate. Similarly, you’ll anticipate and identify risks within engagements and share any issues with senior members of the team. In line with EY’s commitment to quality, you’ll confirm that work is of the highest quality as per EY’s quality standards and is reviewed by the next-level reviewer. As an influential member of the team, you’ll help to create a positive learning culture, coach and counsel junior team members and help them to develop. The opportunity We’re looking for Senior Security Consultant with expertise in cyber / information security, risk and controls concepts. This is a fantastic opportunity to be part of a leading firm whilst being instrumental in the growth of a new service offering. Your Key Responsibilities Engage in Cyber Strategy & Governance, Cyber Risk & Compliance, Cyber Resilience, Cyber Transformation and Co-Sourcing, Application & Network Security engagements Work effectively as a team member, sharing responsibility, providing support, maintaining communication and updating senior team members on progress. Execute the engagement requirements, along with review of work by junior team members. Help prepare reports and schedules that will be delivered to clients and other parties. Develop and maintain productive working relationships with client personnel. Build strong internal relationships within EY Consulting Services and with other services across the organization Contribute to people related initiatives including recruiting and retaining Cyber Transformation professionals Maintain an educational program to continually develop personal skills of staff Understand and follow workplace policies and procedures Building a quality culture at GDS Help senior team members in performance reviews and contribute to performance feedback for staff/junior level team members Manage the performance management for the direct reportees, as per the organization policies. Foster teamwork and lead by example; training and mentoring of project resources Participating in the organization-wide people initiatives Skills And Attributes For Success Hands-on experience of more than 5 years with key components of cybersecurity including (but not limited to): Vendor/3rd Party Risk Management & Assessment Cyber Strategy & Governance, Cyber Transformation, Cyber Dashboarding Regulations/standards such as ISO 27001, PCI DSS, HIPAA, HITRUST, GDPR, CCPA, FISMA/FEDRAMP, COBIT, OWASP Top 10, NIST 800-53 Business Continuity & Disaster Recovery Must have experience in working in client facing roles, interacting with the third parties, assessing different kinds of environments (IT and non-IT) and ability to apply cyber security concepts in all these sectors. Experienced in creation and review of security policy/procedures, and in performing risk assessments. Good to have experience in assessing ITGC requirements across various industries including both Cybersecurity and resilience requirements. Should have a good understanding of VAPT process, common application security vulnerabilities, exploitation techniques and remediation measures. Basic understanding of Network Security and network architecture diagram reviews, access and perimeter control, vulnerability management and intrusion detection, firewall rule-based reviews. Good understanding of logging and monitoring tools (SIEM). Knowledge in any one of the SIEM tools is a plus. To qualify for the role, you must have: BE - B. Tech / MCA / M. Tech/ MBA with background in computer science and programming. More than 5 Years of relevant experience. Strong Excel and PowerPoint skills. Should be proficient in leading medium to large engagements and coach junior staff. Ideally, you’ll also have CISSP, CISA, CISM, CEH, ISO 27001 Lead Auditor and Lead Implementer. Project management skills. What We Look For A team of people with commercial acumen, technical experience and enthusiasm to learn new things in this fast-moving environment with consulting skills. An opportunity to be a part of market-leading, multi-disciplinary team of 1400 + professionals, in the only integrated global transaction business worldwide. Opportunities to work with EY Consulting practices globally with leading businesses across a range of industries. What Working At EY Offers At EY, we’re dedicated to helping our clients, from start–ups to Fortune 500 companies — and the work we do with them is as varied as they are. You get to work with inspiring and meaningful projects. Our focus is education and coaching alongside practical experience to ensure your personal development. We value our employees and you will be able to control your own development with an individual progression plan. You will quickly grow into a responsible role with challenging and stimulating assignments. Moreover, you will be part of an interdisciplinary environment that emphasizes high quality and knowledge exchange. Plus, we offer: Support, coaching and feedback from some of the most engaging colleagues around Opportunities to develop new skills and progress your career The freedom and flexibility to handle your role in a way that’s right for you EY | Building a better working world EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today. Show more Show less
Posted 2 weeks ago
5.0 years
0 Lacs
Chennai, Tamil Nadu, India
On-site
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. EY- Cyber Security (Strategy, Risk, Compliance and Resilience) – Technology Consulting – Senior As part of our EY Strategy, Risk, Compliance and Resilience (SRCR) Technology Consulting team, you would work on various SRCR projects for our customers across the globe. An important part of your role will be to actively establish, maintain and strengthen internal and external relationships. You’ll also identify potential business opportunities for EY and GDS within existing engagements and escalate these as appropriate. Similarly, you’ll anticipate and identify risks within engagements and share any issues with senior members of the team. In line with EY’s commitment to quality, you’ll confirm that work is of the highest quality as per EY’s quality standards and is reviewed by the next-level reviewer. As an influential member of the team, you’ll help to create a positive learning culture, coach and counsel junior team members and help them to develop. The opportunity We’re looking for Senior Security Consultant with expertise in cyber / information security, risk and controls concepts. This is a fantastic opportunity to be part of a leading firm whilst being instrumental in the growth of a new service offering. Your Key Responsibilities Engage in Cyber Strategy & Governance, Cyber Risk & Compliance, Cyber Resilience, Cyber Transformation and Co-Sourcing, Application & Network Security engagements Work effectively as a team member, sharing responsibility, providing support, maintaining communication and updating senior team members on progress. Execute the engagement requirements, along with review of work by junior team members. Help prepare reports and schedules that will be delivered to clients and other parties. Develop and maintain productive working relationships with client personnel. Build strong internal relationships within EY Consulting Services and with other services across the organization Contribute to people related initiatives including recruiting and retaining Cyber Transformation professionals Maintain an educational program to continually develop personal skills of staff Understand and follow workplace policies and procedures Building a quality culture at GDS Help senior team members in performance reviews and contribute to performance feedback for staff/junior level team members Manage the performance management for the direct reportees, as per the organization policies. Foster teamwork and lead by example; training and mentoring of project resources Participating in the organization-wide people initiatives Skills And Attributes For Success Hands-on experience of more than 5 years with key components of cybersecurity including (but not limited to): Vendor/3rd Party Risk Management & Assessment Cyber Strategy & Governance, Cyber Transformation, Cyber Dashboarding Regulations/standards such as ISO 27001, PCI DSS, HIPAA, HITRUST, GDPR, CCPA, FISMA/FEDRAMP, COBIT, OWASP Top 10, NIST 800-53 Business Continuity & Disaster Recovery Must have experience in working in client facing roles, interacting with the third parties, assessing different kinds of environments (IT and non-IT) and ability to apply cyber security concepts in all these sectors. Experienced in creation and review of security policy/procedures, and in performing risk assessments. Good to have experience in assessing ITGC requirements across various industries including both Cybersecurity and resilience requirements. Should have a good understanding of VAPT process, common application security vulnerabilities, exploitation techniques and remediation measures. Basic understanding of Network Security and network architecture diagram reviews, access and perimeter control, vulnerability management and intrusion detection, firewall rule-based reviews. Good understanding of logging and monitoring tools (SIEM). Knowledge in any one of the SIEM tools is a plus. To qualify for the role, you must have: BE - B. Tech / MCA / M. Tech/ MBA with background in computer science and programming. More than 5 Years of relevant experience. Strong Excel and PowerPoint skills. Should be proficient in leading medium to large engagements and coach junior staff. Ideally, you’ll also have CISSP, CISA, CISM, CEH, ISO 27001 Lead Auditor and Lead Implementer. Project management skills. What We Look For A team of people with commercial acumen, technical experience and enthusiasm to learn new things in this fast-moving environment with consulting skills. An opportunity to be a part of market-leading, multi-disciplinary team of 1400 + professionals, in the only integrated global transaction business worldwide. Opportunities to work with EY Consulting practices globally with leading businesses across a range of industries. What Working At EY Offers At EY, we’re dedicated to helping our clients, from start–ups to Fortune 500 companies — and the work we do with them is as varied as they are. You get to work with inspiring and meaningful projects. Our focus is education and coaching alongside practical experience to ensure your personal development. We value our employees and you will be able to control your own development with an individual progression plan. You will quickly grow into a responsible role with challenging and stimulating assignments. Moreover, you will be part of an interdisciplinary environment that emphasizes high quality and knowledge exchange. Plus, we offer: Support, coaching and feedback from some of the most engaging colleagues around Opportunities to develop new skills and progress your career The freedom and flexibility to handle your role in a way that’s right for you EY | Building a better working world EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today. Show more Show less
Posted 2 weeks ago
1.0 - 3.0 years
0 Lacs
Pune, Maharashtra, India
On-site
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. Job Summary JOB DESCRIPTION--STAFF –Risk Consulting- IT Risk Management In your role as a staff member in Information Technology Risk Management (ITRM) within Risk Consulting, you will provide technical support to client engagements and internal initiatives aimed at transforming risk. You will be responsible for recognizing potential risks during engagements and communicating any concerns to the senior team members. Client Responsibilities Ability to collaborate effectively within Information Technology Risk Management (ITRM) project teams Positive approach to teamwork, taking ownership, and exchanging knowledge Engage with the project team to ensure open communication, identify potential risks, and discuss strategies for risk mitigation Competence in designing and suggesting solutions tailored to customer needs based on their specified requirements Assist in the creation of reports and schedules that will be presented to clients and relevant stakeholders Contribute to the development of reports and timetables for delivery to clients and other interested parties. Build and keep up constructive working relationships with client contacts. Willingness to travel to client sites or other EY offices as required. Strong skills in documentation and communication. People Responsibilities Professionals with enthusiasm to develop new skills and knowledge and experience to succeed and inquisitiveness to learn new things in this fast-moving environment Works cross-functionally with team members to support and drive a collaborative team environment Understands client s business environment and basic risk management approaches Mandatory Skills Requirements Possessing 1-3 years of expertise in IT Security, Information Security, Cyber Security, or Cloud Security Proficient in conducting IT Audits, managing IT General Controls, and IT Attestation (including SOC1/SOC2 Reporting), as well as SOX-ITGC compliance Understanding of IT Risk Management frameworks for the identification, analysis, mitigation, monitoring, and communication of IT risks Experienced in validating IT controls, conducting tests, and pinpointing control gaps Ability to create IT/Information security policies, standards, and guidelines Familiar with leading industry frameworks and standards such as NIST-CSF, ISO27001, ITIL, COBIT, PCI-DSS, CSA-CCM, CCSK, ISO27017, and others Preferred Skills Experience in conducting IT Risk Assessments and IT Controls Testing B.E/B.Tech (Electronics, Electronics & Telecommunications, Comp. Science) /M.E. / M.Tech, MBA/M.Sc. having experience with other Big3 or panelled IT/ ITeS companies Certifications (Preferred) Relevant professional certifications such as ISO27001, ITIL, COBIT, etc EY | Building a better working world EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today. Show more Show less
Posted 2 weeks ago
3.0 years
0 Lacs
Gurugram, Haryana, India
On-site
About The Role Manage client Due Diligence Questionnaires (DDQs) and security inquiries, ensuring timely, accurate, and compliant responses. This role requires both technical security knowledge and compliance expertise to address cybersecurity controls, regulatory requirements, and risk management best practices. The ideal candidate will engage internal stakeholders, maintain response documentation, and continuously improve due diligence processes. Key Responsibilities Due Diligence Management: Act as the primary point of contact for client security inquiries and DDQs, coordinating responses with Compliance, Legal, IT, and Business Units. Security & Compliance Alignment: Ensure responses align with security best practices (ISO 27001, NIST CSF, SOC 2, GDPR, etc.) and company policies, providing necessary evidence of controls, risk assessments, and mitigations. Technical & Risk Assessment Support: Interpret and communicate technical security concepts (e.g., encryption, network security, access controls) while ensuring compliance with regulatory frameworks. Process Optimization & Documentation: Maintain accurate records of due diligence responses, enhance standardized templates, and identify trends to improve efficiency and security posture. Stakeholder Collaboration & Training: Work cross-functionally to resolve escalations, support audits, and provide guidance on security governance and compliance requirements. Qualifications Education: Bachelor's in technology related field. Experience: 3+ years in information security, risk management, or compliance, with hands-on experience in due diligence, security frameworks, and vendor/security risk assessments. Certifications (Preferred): CISSP, CISA, or equivalent. Skills: Strong understanding of cybersecurity principles and regulatory compliance requirements. Ability to translate technical security concepts into clear responses for non-technical stakeholders. Experience with GRC tools and security audits Excellent organizational and communication skills. About GLG / Gerson Lehrman Group GLG is the world’s insight network. Our clients rely on GLG’s global team to connect with powerful insight across fields from our network of approximately 1 million experts (and the hundreds of new experts we recruit every day). We serve thousands of the world’s best businesses, from Fortune 500 corporations to leading technology companies to professional services firms and financial institutions. We connect our clients to the world’s largest and most varied source of first-hand expertise, including executives, scientists, academics, former public-sector leaders, and the foremost subject matter specialists. GLG’s industry-leading compliance framework allows clients to learn in a structured, auditable, and transparent way, consistent with their own internal compliance obligations and the highest professional ethical standards. Our compliance standards are a major competitive differentiator and key component of the company’s culture. To learn more, visit www.GLGinsights.com. Gerson Lehrman Group, Inc. (“GLG”) is an equal opportunity employer and will not discriminate against any employee or applicant on the basis of age, race, religion, color, marital status, disability, gender, national origin, sexual orientation, veteran status, or any classification protected by federal, state, or local law. Show more Show less
Posted 2 weeks ago
3.0 - 7.0 years
7 - 11 Lacs
Kochi
Work from Office
Job Title Security Analyst Role and Responsibilities The security Analyst is a member of the CISO Regulatory & Compliance Team and will assist in ensuring the associated business units / accounts comply with applicable Conduent and NIS 2 security standards, regulations, and policies.The Security analyst will be professional, independent, impartial, and fair in all interactions. The security resource is accountable for procedures and processes that ensure the integrity, confidentiality, and availability of assigned Business units\u2019 information, applications, and infrastructure. Resource will perform routine risk assessments, security audits, and vulnerability scans to identify, evaluate, document, and remediate organization risk, control gaps and vulnerabilities. This position will be responsible for developing security reports, security recommendations, and security policies and procedures that are meaningful, defensible, and actionable for a variety of audiences as pertained to assigned business units. Perform log collection, correlation, reviews, archival, retention, and monitoring of automated alerts for items such as, and not limited to IPS/IDS alerts; change detection (FIM) alerts application firewall alerts; malware alerts rogue wireless network alerts security system health alerts; exploit attempt alerts Participate and be an integral component of audit, compliance, and regulatory functions, including and not limited to audits of system security to ensure compliance with Corporate security framework NIS 2, NIST 800-53, ISO 27001/2, PCI-DSS emerging country, state, and Federal privacy laws Primary POC in a vulnerability management program of the account that includes external and internal vulnerability scans of applications and systems external and internal penetration tests of applications and systems documentation and remediation of identified vulnerabilities and exploits routinely monitoring various communication avenues for security vulnerabilities and security patches taking a risk-based approach comparing those security vulnerabilities and security patches across the operating environments making recommendations to various IT teams on the mitigation process for those identified security vulnerabilities Coordinate with business units, operations, and technology teams for incident response, remediation, and improvement Acts as the initial point of contact to facilitate the handling of security audits and client requests Supports the creation of business continuity/disaster recovery plans, to include conducting disaster recovery tests, publishing test results, and making changes necessary to address deficiencies Maintain documentation that supports the annual Security compliance attestation as it is relevant to the assigned Business units Qualifications and Education Requirements CIPP, CRISC, CISA, CISSP, CISM, ISO or any security/IT audit certification is a plus. Minimum of Five (3 to 5) Years of experience in IT Security compliance, or Security Auditing is required. Knowledge and understanding of security controls across all security domains, such as access management, encryption, vulnerability management, authentication, authorization, network security, physical security, etc. Ability to identify security risks in application, system, and network architecture, data flow, and processes or procedures Ability to assess the organizational impact of identified security risks and recommend solutions or mitigating controls. Knowledge of security technologies, devices, and countermeasures, as well as the threats they are designed to counter. Experience with developing security reports, recommendations, policies, and procedures that are meaningful, defensible, and actionable for a variety of audiences. Familiarity with more than one framework (NIST 800-series, ISO 27000-series, PCI DSS and ISO, HIPAA, HITRUST, FISMA, FedRAMP other common security control frameworks). Experience in PowerPoint, Word, Excel; experience with Visio and MS Project. Communication skills (interpersonal, verbal, presentation written, email). Experience to write report segments and to participate in presentations. Familiarity with security, workflow, and collaboration tools such Nessus Tenable, Splunk, SharePoint and ServiceNow (Snow) is a plus Positive attitude, team player, self-starter; takes initiative, ability to work independently and effectively with all levels of staff and management both internally and externally Preferred Skills Creating and Maintaining NIST 800-53-rev5 based SSP and POAM Familiarity with more than one framework (NIST 800-series, ISO 27000-series, PCI DSS and ISO, HIPAA, HITRUST, FISMA, FedRAMP other common security control frameworks). Conduent is an Equal Opportunity Employer and considers applicants for all positions without regard to race, color, creed, religion, ancestry, national origin, age, gender identity, gender expression, sex/gender, marital status, sexual orientation, physical or mental disability, medical condition, use of a guide dog or service animal, military/veteran status, citizenship status, basis of genetic information, or any other group protected by law. People with disabilities who need a reasonable accommodation to apply for or compete for employment with Conduent may request such accommodation(s) by submitting their request through this form that must be downloaded:click here to access or download the form. Complete the form and then email it as an attachment toFTADAAA@conduent.com.You may alsoclick here to access Conduent's ADAAA Accommodation Policy. At Conduent we value the health and safety of our associates, their families and our community. For US applicants while we DO NOT require vaccination for most of our jobs, we DO require that you provide us with your vaccination status, where legally permissible. Providing this information is a requirement of your employment at Conduent.
Posted 2 weeks ago
1.0 - 3.0 years
0 Lacs
Noida, Uttar Pradesh, India
On-site
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. Job Summary JOB DESCRIPTION--STAFF –Risk Consulting- IT Risk Management In your role as a staff member in Information Technology Risk Management (ITRM) within Risk Consulting, you will provide technical support to client engagements and internal initiatives aimed at transforming risk. You will be responsible for recognizing potential risks during engagements and communicating any concerns to the senior team members. Client Responsibilities Ability to collaborate effectively within Information Technology Risk Management (ITRM) project teams Positive approach to teamwork, taking ownership, and exchanging knowledge Engage with the project team to ensure open communication, identify potential risks, and discuss strategies for risk mitigation Competence in designing and suggesting solutions tailored to customer needs based on their specified requirements Assist in the creation of reports and schedules that will be presented to clients and relevant stakeholders Contribute to the development of reports and timetables for delivery to clients and other interested parties. Build and keep up constructive working relationships with client contacts. Willingness to travel to client sites or other EY offices as required. Strong skills in documentation and communication. People Responsibilities Professionals with enthusiasm to develop new skills and knowledge and experience to succeed and inquisitiveness to learn new things in this fast-moving environment Works cross-functionally with team members to support and drive a collaborative team environment Understands client s business environment and basic risk management approaches Mandatory Skills Requirements Possessing 1-3 years of expertise in IT Security, Information Security, Cyber Security, or Cloud Security Proficient in conducting IT Audits, managing IT General Controls, and IT Attestation (including SOC1/SOC2 Reporting), as well as SOX-ITGC compliance Understanding of IT Risk Management frameworks for the identification, analysis, mitigation, monitoring, and communication of IT risks Experienced in validating IT controls, conducting tests, and pinpointing control gaps Ability to create IT/Information security policies, standards, and guidelines Familiar with leading industry frameworks and standards such as NIST-CSF, ISO27001, ITIL, COBIT, PCI-DSS, CSA-CCM, CCSK, ISO27017, and others Preferred Skills Experience in conducting IT Risk Assessments and IT Controls Testing B.E/B.Tech (Electronics, Electronics & Telecommunications, Comp. Science) /M.E. / M.Tech, MBA/M.Sc. having experience with other Big3 or panelled IT/ ITeS companies Certifications (Preferred) Relevant professional certifications such as ISO27001, ITIL, COBIT, etc EY | Building a better working world EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today. Show more Show less
Posted 2 weeks ago
0 years
0 Lacs
Pune, Maharashtra, India
On-site
Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential. Title And Summary Risk Analyst, Regulatory and Customer Assurance (India) Overview The Technology Risk Management (TRM) organization is a business enabler and industry leader of technology and security risk management practices, supported by a multi-disciplinary team of top security, technology, and risk professionals. Our mission is to exceed stakeholder expectations by providing enhanced visibility and proactive management of technology risks and ensuring strong security and sound operational environment. The Security Assurance team is responsible for working with, and demonstrating to, our stakeholders (e.g., regulators, customers, Mastercard businesses) how Mastercard complies with our security and technology promises, commitments, and obligations. India is a highly regulated environment requiring a strong risk management program to meet new and existing obligations, including audits of security processes and controls, tokenization practices and data localization compliance. Risk Management Framework/Governance Assist in preparation and maintenance of a consolidated control framework Support preparation of a centralized inventory of security and technology risk management requirements and assurance expectations Risk Management Guidance/Direction Support business owners in analysis of business and functional requirements resulting from regulation and customer contracts; and help identify technology and security risk controls Help assess impact of business, market and regulatory landscape changes on controls and preactices Audit Support Support customer and regulatory examinations; provide documentation and evidence to demonstrate how Mastercard satisfies obligations and commitments Assist in completing customer and regulatory inquiries and requests for information Prepare periodic customer and regulator meetings and reporting Perform compliance monitoring and pre audit readiness reviews Collection, sorting and maintaining audit evidence repository and tracking open items to closure Assist with certification efforts (e.g., SOC, ISO, PCI) Assist in reviewing reports of related parties and review System Audit Reports (SARs) and System Audit Questionnaires (SAQs) to track ecosystem compliance Experience Have knowledge of relevant regulations (e.g., payment and settlement systems, tokenization, Data localization) applicable to India business Have strong understanding of technology and information security risk management practices. Experience in handling regulatory and customer audits, conducting assessments and good understanding of governance, risk and compliance practices Be seen as a trusted advisor who understands business processes and can provide security consultation and advisory Possess excellent communication and people management skills and stakeholder management experience Be culturally aware, sensitive and able to collaborate with cross-regional teams Be a team player with strong business and operations focus Knowledge of Risk and Control Framework standards such as NIST, ISO, PCI-DDS, SOC Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and IT management (e.g., GDPR, FBA, CBA, PFMI, etc.) Knowledge of Mastercard products and technology, security and other risk management programs and practices desired, a plus but not required Corporate Security Responsibility All Activities Involving Access To Mastercard Assets, Information, And Networks Comes With An Inherent Risk To The Organization And, Therefore, It Is Expected That Every Person Working For, Or On Behalf Of, Mastercard Is Responsible For Information Security And Must: Abide by Mastercard’s security policies and practices; Ensure the confidentiality and integrity of the information being accessed; Report any suspected information security violation or breach, and Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines. R-211366 Show more Show less
Posted 2 weeks ago
8.0 - 13.0 years
13 - 17 Lacs
Pune
Work from Office
Project Role : Security Architect Project Role Description : Define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. Document the implementation of the cloud security controls and transition to cloud security-managed operations. Must have skills : Governance Risk Compliance (GRC) Good to have skills : Security Architecture DesignMinimum 5 year(s) of experience is required Educational Qualification : 15 years full time education Summary :As a Security Architect, you will define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. Your typical day will involve collaborating with various teams to assess security needs, documenting the implementation of cloud security controls, and transitioning to cloud security-managed operations. You will engage in discussions to refine security strategies and ensure compliance with established standards, all while adapting to the evolving landscape of cloud technologies and security threats. Roles & Responsibilities:- Expected to be an SME.- Collaborate and manage the team to perform.- Responsible for team decisions.- Engage with multiple teams and contribute on key decisions.- Provide solutions to problems for their immediate team and across multiple teams.- Facilitate training sessions to enhance team knowledge on security best practices.- Monitor and evaluate the effectiveness of implemented security measures. Professional & Technical Skills: - Must To Have Skills: Proficiency in Governance Risk Compliance (GRC).- Good To Have Skills: Experience with Security Architecture Design.- Strong understanding of risk assessment methodologies and frameworks.- Experience in developing and implementing security policies and procedures.- Familiarity with compliance standards such as ISO 27001, NIST, and GDPR. Additional Information:- The candidate should have minimum 5 years of experience in Governance Risk Compliance (GRC).- This position is based in Pune.- A 15 years full time education is required. Qualification 15 years full time education
Posted 2 weeks ago
12.0 - 15.0 years
13 - 17 Lacs
Gurugram
Work from Office
Project Role : Security Architect Project Role Description : Define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. Document the implementation of the cloud security controls and transition to cloud security-managed operations. Must have skills : Security Delivery Governance Good to have skills : NAMinimum 12 year(s) of experience is required Educational Qualification : 15 years full time education Summary :As a Security Architect, you will define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. Your typical day will involve collaborating with various teams to assess security needs, documenting the implementation of cloud security controls, and overseeing the transition to cloud security-managed operations. You will engage in strategic discussions to align security measures with organizational objectives, ensuring a robust security posture while adapting to evolving threats and compliance requirements. Roles & Responsibilities:- SOC Operations:Lead and manage day-to-day operations of the SOC, including Tier 13 security analysts.Oversee security monitoring, threat detection, incident response, and threat intelligence activities.Ensure continuous tuning and enhancement of SIEM and EDR tools.Create and maintain incident response playbooks and workflows.Collaborate with infrastructure and application teams during security events.Security Governance, Risk & Compliance:Develop and enforce cybersecurity policies, standards, and procedures aligned with business objectives and regulatory requirements.Coordinate risk assessments, audits, and compliance initiatives (e.g., ISO 27001, NIST, GDPR, HIPAA).Lead security awareness and training initiatives across the organization.Track and report on cybersecurity risks, mitigation plans, and audit findings.Partner with legal, audit, and compliance teams to ensure alignment with industry and legal frameworks.Strategic Leadership:Provide executive-level reporting on threat posture, key risks, and SOC performance.Guide long-term planning and roadmap development for security operations and governance initiatives.Mentor and develop SOC staff and GRC team members.Stay current with industry trends, threat landscape changes, and evolving compliance standards. Professional & Technical Skills: - Must To Have Skills: Proficiency in Security Delivery Governance.- Strong understanding of cloud security principles and frameworks.- Experience with risk assessment and management methodologies.- Ability to design and implement security policies and procedures.- Familiarity with compliance standards such as ISO 27001, NIST, and GDPR.-Reccomend use case fine tuning-Regularly review use cases and suggest enhancements. -Run internal Table top exercises to help train the team-Maintain IR quality as per industry standards Additional Information:- The candidate should have minimum 12 years of experience in Security Delivery Governance.- This position is based at our Gurugram office.- A 15 years full time education is required. Qualification 15 years full time education
Posted 2 weeks ago
Upload Resume
Drag or click to upload
Your data is secure with us, protected by advanced encryption.
Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.
We have sent an OTP to your contact. Please enter it below to verify.
Accenture
36723 Jobs | Dublin
Wipro
11788 Jobs | Bengaluru
EY
8277 Jobs | London
IBM
6362 Jobs | Armonk
Amazon
6322 Jobs | Seattle,WA
Oracle
5543 Jobs | Redwood City
Capgemini
5131 Jobs | Paris,France
Uplers
4724 Jobs | Ahmedabad
Infosys
4329 Jobs | Bangalore,Karnataka
Accenture in India
4290 Jobs | Dublin 2