JD for Information Security and Compliance Specialist:
Responsibilities:
1. Utilize 3-5 years of direct experience in information security, specializing in risk and compliance management.
Proficiently conduct audits and manage audit responses and observations.
2. Implement ISMS (Information Security Management System) standards, policies, and conduct access reviews
to ensure regulatory compliance. Perform thorough risk assessments and remain updated on relevant
regulatory requirements.
3. Demonstrate a proficient understanding of identity management standards, Business Continuity Planning
(BCP), Disaster Recovery (DR), and Cloud Security.
4. Utilize GRC (Governance, Risk, and Compliance) tools and techniques to organize and execute risk and
compliance projects. Conduct audits, compile evidence, and coordinate audit responses efficiently.
5. Manage risk and vulnerability assessments, along with compliance reviews, to ensure adherence to security
standards.
6. Maintain and monitor a centralized repository for procedures and documents related to security and
compliance.
7. Demonstrate proficiency in incident response and change management practices.
8. Collaborate with stakeholders to align IT General Controls (ITGC) objectives with organizational goals.
9. Support functional teams in achieving ongoing operational compliance.
10. Conduct Vulnerability Assessment and Penetration Testing (VAPT) assessments, drive remediation efforts, and
ensure the closure of identified vulnerabilities.
11. Stay updated on regulatory changes impacting information security and ensure organizational compliance.
12. Conduct security awareness training sessions and effectively communicate security policies and best practices
to all stakeholders.
13. Possess effective written and verbal communication skills to interact with cross-functional teams.
14. Demonstrate strong analytical and problem-solving abilities to effectively address security and compliance
challenges.