Talent.com
This job offer is not available in your country.
Senior Security Compliance Consultant

Senior Security Compliance Consultant

IL RomaniaBucharest, Romania
17 days ago
Job description

Job description Today, the corporate landscape is dynamic, and the world ahead is full of possibilities! None of the amazing things we do at Infosys would be possible without an equally amazing culture, the environment where ideas can flourish and where you are empowered to move forward as far as your ideas will take you. At Infosys, we assure that your career will never stand still, we will inspire you to build what’s next and we will navigate further together. Our journey of learnability, values and trusted relationships with our clients continue to be the cornerstones of our organization and these values are upheld only because of our people. The RoleIn your role as Security Compliance Consultant, you will help us achieve our goals and deliver success on behalf of our customers by : Building and overseeing our Information Security controls framework and environment in line with industry standards to ensure enterprise-wide security compliance and leading us to ISO certification.Collaboratively creating, implementing and maintaining security policies, standards and procedures which improve our posture in alignment with industry best practice and internationally recognised compliance standards.Ensuring the annual successful execution of all compliance recertification efforts by leading and coordinating our preparation, responses and submissions for certifications such as ISO, PCI DSS and SOC2, etc.Providing assurance to our customers by coordinating the responses to customer RFP questions and customer audits in the Information Security area.Coordinating with and supporting our Legal, Risk & Compliance teams in understanding and quantifying security risk, responding to third-party requests and performing security assessments of our suppliers, their products and services.Tracking our security awareness programme compliance.Acting as a subject matter expert on compliance requirements and consulting across the enterprise to ensure or products and services are "secure and compliant by design".ResponsibilitiesAs a company we hire people with a willingness to adapt to a variable role, so along with the key responsibilities below, we ask for ownership of any other duties as required.Create, review, update and complete information security policy, standards, and guidelines, maintaining document management disciplines and dependency mapping; consulting with and coordinating the input of SMEs as needed.Conduct security risk assessments, business impact analyses and recommend appropriate control improvements. Provide oversight and assurance of corrective, preventative or remediation activities, escalating issues at risk of missing deadlines in a timely and efficient manner.Maintain a security risk register in collaboration with the Risk and Compliance team which documents and quantifies risks, tracks remediation plans, risk ownership and acceptances, and facilitates regular reviews. prioritisation and overall residual risk reduction.Coordinate and lead our responses to customer RFP questions and security audits in a timely and efficient manner, helping to create repeatable, re-usable answers and examples for common questions and ensuring all responses are traceable to SMEs and responsible teams within the organization. Represent the Information Security Department directly with customers when required.Lead the security assessment aspects of our third-party assurance programme by developing and maintaining questionnaires and collating responses, enhancing the supporting processes where applicable. Coordinate the assessment programme and conduct additional risk-based information security due diligence activities against suppliers to provide appropriate levels of assurance to key stakeholders when needed.Stay up to date with the latest security and technology trends and development. Research and evaluate emerging security threats and closely monitor and understand current and potential changes to compliance frameworks and regulations, making recommendations on mitigations and programs for the organization to address them.Ensure that security architecture and compliance concepts and best practices are embedded throughout the business. Ensure compliance training is regularly updated, and completion rates monitored.Consult with internal teams, clients, auditors, and regulators regarding information security compliance, and related topics as necessary. Act as a subject matter expert when internal teams have questions / need guidance and be a liaison with external compliance advisory firms as well as the governing body and industry communities.Liaise with internal teams and stakeholders (e.g. Legal, Privacy, GDPR, Risk and Compliance) in relation to security compliance to ensure coordination of requirements, agreed controls and shared consistent documentation and tooling wherever possible.Gain knowledge and understanding of our goals and culture and ensure that our control and compliance framework delivers the information security architecture and compliance strategy aligned with industry best practices and the company security posture defined by the CISO.Contribute advice and guidance for departmental security strategies to manage identified risks and ensure adoption and adherence to standards and compliance frameworks.Develop and maintain documentation, controls, processes, workflows, metrics, reporting, solutions, and applications / tools as needed to ensure effective operation and visibility of the state of the compliance function.Engage as required during actual and simulated incidents and recovery operations.Ensure all processes and controls that fall within your area of responsibility are operating effectively and are correctly evidenced.Travel periodically as required for customer, company, or relevant events.Skills and ExperienceMust haves3 or more years’ experience with ensuring information security compliance, preferably in highly regulated environments.Strong experience working with, building, and implementing successfully, a range of security control frameworks including ISO and SOC 2, e.g. worked as ISO Lead Auditor / Implementer.Strong experience of ISMS, security risk management and associated practices.Experience of performing internal or third-party security compliance assessments.Demonstrated ability to multi-task, work calmly under pressure, think analytically, understand complex systems and communicate complexity effectively.Ability to communicate clearly with both technical and non-technical staff and stakeholders at different levels across the business.Excellent written and verbal communication as well as good presentation skills. Proficient English language skills are required.Be able to build relationships and influence actions from all areas of the business including senior leadership, engineering teams and auditors and regulators.Ability to adapt and stretch capabilities and skills to meet the business needs of a fast-growing technology firm.Ability to create repeatable and re-usable principles, processes and solutions.Broad knowledge / understanding of basic technical security controls / control frameworks including, but not limited to, areas such as cloud computing, network security, endpoint security and identity and access management, etc.Knowledge of common security vulnerabilities / risk factors in information processes, infrastructure and applications, e.g., Separation of Duties, CVEs, OWASP Top 10, etc.Great to havesPreferably one or more of the following security qualifications : ISO LI / LA, PCIP, ISA, CISA, CISM or similar.Strong / Deep understanding of information security controls, technologies, policies, processes, and best practices as applied to applications, compute, networking, cloud, and containers.Experience / knowledge of Financial Services Compliance such as PCI. Why InfosysInfosys is a global leader in next-generation digital services and consulting. We enable clients in more than 50 countries to navigate their digital transformation.With nearly four decades of experience in managing the systems and workings of global enterprises, we expertly steer our clients through their digital journey. We do it by enabling the enterprise with an AI-powered core that helps prioritize the execution of change. We also empower the business with agile digital at scale to deliver unprecedented levels of performance and customer delight. Our always-on learning agenda drives their continuous improvement through building and transferring digital skills, expertise, and ideas from our innovation ecosystem.

Create a job alert for this search

Senior Consultant • Bucharest, Romania

Related jobs
VAT Compliance Senior Consultant - Hybrid

VAT Compliance Senior Consultant - Hybrid

EYBucharest, RO
You’ll work as part of high-performing team on a broad range of clients and assignments that will stretch and challenge you. You’ll be encouraged and expected to take accountability and make an impa...Show moreLast updated: 30+ days ago
Senior Consultant SAP Security / Authorizations

Senior Consultant SAP Security / Authorizations

adessoromaniaBucureşti, România
YOUR ROLE - WHAT'S WAITING FOR YOU.As a Senior Consultant (all genders) SAP Security / Authorizations, you will be the link between the specialist department and the implementing IT.Your mission : to ...Show moreLast updated: 30+ days ago
Security & Compliance Engineer

Security & Compliance Engineer

Sales ConsultingBucurești, București, RO
Quick Apply
Since 1998, we've been active in the Human Resources consulting market, providing regional coverage across four key areas of expertise : recruitment and selection, personnel leasing, assessment cent...Show moreLast updated: 19 days ago
Security Compliance and Assurance SME

Security Compliance and Assurance SME

VodafoneBucuresti, Bucuresti, Romania
You will be responsible for ensuring that the policies, procedures and internal controls objectives in scope for Vodafone CIoud and Infrastructure (VCI) workstreams are fulfilled.You will ensures t...Show moreLast updated: 30+ days ago
Senior Services Consultant

Senior Services Consultant

AxwayBucharest, RO
In 2024, we are pursuing our ambitions to continue to enable organizations' digital transformation.Axway is an enterprise integration company that's been around for over 20 years to digitally trans...Show moreLast updated: 30+ days ago
ABAP Development Senior Consultant

ABAP Development Senior Consultant

SAPBucharest, RO
At SAP, we enable you to bring out your best.Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for...Show moreLast updated: 30+ days ago
Cyber Security Consultant with Italian (Job Ref. QYW856Y9)

Cyber Security Consultant with Italian (Job Ref. QYW856Y9)

Oben TechnologyBucharest, Romania
Quick Apply
Oben stands ready to provide the IT Strategy and Consulting support for Global Leaders to help them steer their Organizations through Change. We leverage our functional and technology expertise, ins...Show moreLast updated: 27 days ago
Senior Sustainability Consultant

Senior Sustainability Consultant

Forvis Mazars RomaniaBucuresti, Bucuresti, Romania
Forvis Mazars is a leading global tax, audit and advisory network, recognized as one of the Best Places to Work in Central and Eastern Europe (CEE) and Central Asia for 2024-2025.What does reliable...Show moreLast updated: 30+ days ago
Senior Eloqua Consultant

Senior Eloqua Consultant

EndavaBucharest, Bucharest, Romania
We are looking for an experienced and proactive Senior Eloqua Consultant to join our team on a complex global support engagement. In this role, you will have ownership of the Eloqua production envir...Show moreLast updated: 8 days ago
Senior Implementation Consultant PSS

Senior Implementation Consultant PSS

ADPBucharest, rom-ro
ADP Celergo Organization is committed to providing World Class Service to clients by hiring, developing and retaining qualified service professionals. by treating each client contact as a service o...Show moreLast updated: 30+ days ago
  • New!
Network Consultant - SDA SME London 2 days per week - SC Cleared - Inside scope of IR35

Network Consultant - SDA SME London 2 days per week - SC Cleared - Inside scope of IR35

TrinIT GroupBucharest
Cisco SDA Network Consultant - London 2 days per week - SC Cleared - Inside scope of IR35.TrinIT Talent are looking for a Cisco SDA Network Consultant to come on board for a 6 month contract based ...Show moreLast updated: 2 hours ago
Senior Security Specialist

Senior Security Specialist

Deutsche BankBucharest
The Accounting Tribe Domain (AccTD) is looking for a Risk and Control(R&C) Senior Security Specialist, a role which provides oversight and impact over a domain operating ~70 IT applications, with e...Show moreLast updated: 11 days ago
Senior Security Software Engineer

Senior Security Software Engineer

Keysight TechnologiesBucharest, Bucuresti, RO
Overview About the Role Keysight is looking to hire a senior security software engineer to develop automated program analysis and fuzz testing capabilities for our security assessment products.The ...Show moreLast updated: 8 days ago
Senior Consultant, Custom Deployments

Senior Consultant, Custom Deployments

ShowpadBucharest
Senior Consultant, Custom Deployments.At Showpad, we empower others to be at their best.As a business, that means the Showpad sales enablement platform allows revenue teams to engage buyers through...Show moreLast updated: 30+ days ago
ERP Senior Principal Consultant

ERP Senior Principal Consultant

OracleBUCHAREST, Romania
Leads the solution design and implementation aspects of engagement(s) ensuring high quality, integrated software solutions within constraints of time and budget. Analyzes business needs to help ensu...Show moreLast updated: 17 days ago
  • New!
Compliance Senior Manager

Compliance Senior Manager

PwCBucharest
SummaryPwC IT Services Limited (ITSCo) was created to provide shared technology services to PwC firms in a secure, legally compliant, efficient, and transparent manner. ITSCo is a separate legal ent...Show moreLast updated: 16 hours ago
SAP Security & GRC Consultant | Enterprise Security | Romania

SAP Security & GRC Consultant | Enterprise Security | Romania

DeloitteBucharest, Romania
Join our growing Cyber Team, where innovation meets impact.If you’re ready to shape secure digital landscapes across complex SAP ecosystems — we would love to hear from you!🌟🎯 .Experience in desi...Show moreLast updated: 11 days ago
  • New!
Senior Salesforce Consultant

Senior Salesforce Consultant

Lawrence HarveyBucharest
A Salesforce Impact Partner who exclusively consult to nonprofits and public sector organisations is seeking a Senior Salesforce Consultant, with Experience Cloud knowledge, to join their technical...Show moreLast updated: 2 hours ago