We are looking for talented people for the role of
Information Security Manager
The Information Security & Assurance (IS&A) is a global team that is responsible for ensuring all security risks pertaining to business delivery and Client engagements are managed end to end. The team engages on a frequent basis with business leaders to identify, analyze and mitigate security risks. The team is also the primary touch point between the Corporate Security Group and Business teams, while supporting the business on Client security requirements and compliance.
As a Manager in IS&A, you will be part of Corporate Security Group and facilitate security requirements for Cognizant GGM (Global Growth Markets) Business and its clients.
- Manage security and compliance risks in service delivery for key verticals
- Communicate with Business teams to understand all critical security requirements and risk scenarios
- Engage in IS&A program for the key accounts: define control framework; identify and evaluate risks; understand business context and prepare reports and recommendations
- Coordinate with Incident management team during incidents and support investigation of security breaches
- Perform annual Security Risk assessments and conduct related ongoing compliance monitoring activities in coordination with Privacy Officer and Legal Team members
- Manage External ISO 27001 audit and coordination with auditors: plan out audit schedule and charter for corporate functions and coordinate with all internal stakeholders towards preparation
- Assess, prepare and ensure all IT systems, policies and procedures fully comply with Cognizant ISO 27001 SoA, local laws and cross-borders regulations
- Engage with different stakeholders: external auditors, customer visitor, business leaders and corporate teams, such as HR, legal, IT, etc.
- Conduct reviews to assess the service delivery control environment and evaluate adherence to client identified contractual requirements, Cognizant policies and standards
- Already have or in process to obtain relevant Security Certifications e.g. CISA, CISSP, CISM, etc.
- Experience on ISO 27001 Information Security Management system, Risk Assessments, Evaluation of results / findings, IT GRC Governance Risk Compliance Tools
- Knowledge on GDPR and EU Data Protection directive is beneficial
- Participation in information security and risk management field, especially with Technology Risk Management / IT Audit in Enterprise organizations
- Knowledge in understanding and deploying risk management and security frameworks such as NIST, ISF and ISO
- Knowledge of SSAE/ISAE3402, SOC 1 and SOC 2 and PCI-DSS, assessment and control implementation
- Basic Understanding of network and system security technology and practices across all major-computing areas with a special emphasis on Internet related technology
- Ability to think strategically; work with a sense of urgency and pay attention to detail
- Ability to present complex solutions and methods to a general community
- Independent thinking, willingness to "step outside the box" and take reasonable, calculated risks
- Excellent written and verbal communication and organizational skills in English
- Strong collaboration skills and willingness to be a team player to solve problems and incorporate input from various sources
- Willing to travel (10%)
- Opportunity to be part of a rapidly expanding global organization with irreproachable reputation.
- Pleasant and inspiring working atmosphere.
- Professional development and clear career path.
- Training & development opportunities.
- Competitive salary with cafeteria benefits.