Information Security Governance, Risk and Compliance Manager
NTT DATA Global Delivery Services Ltd
Apply on company website
Information Security Governance, Risk and Compliance Manager
NTT DATA Global Delivery Services Ltd
Hyderabad
Not disclosed
Job Details
Job Description
Manager, Information Security Governance, Risk and Compliance
Make an impact with NTT DATA
Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can grow, belong and thrive.
The Manager, Information Security Governance, Risk and Compliance is a management role that supports the organization by way of protecting its brand, warranting compliance to its regulatory and contractual obligations.
This role is accountable for the preparation, monitoring and implementation of controls for successful completion and maintenance of various compliance programs, including but not limited to ISO27001, SOC in line with the Information Security Management System (ISMS), ensuring that information security is effectively managed in all services and business functions within region.
This role is also accountable for managing the people resources for the program whilst fostering a collaborative and innovative team culture focused on operational excellence.
Key responsibilities:
- Supports the development and operational effectiveness of IT security controls.
- Manages and monitors Group risk in the company preferred risk management solution, ensure that risk is assessed, allocated and assigned, managed, monitored, and treated appropriately.
- Supports with the development, scoping and discussing of security compliance review schedules, review risk registers, risk and policy exceptions and authorization and perform threat and risk assessments of new technologies and vendors.
- Documents improvement in service design and ensures that the required security plan is developed and reviewed.
- Reviews service level and business requirements to develop service methodologies and an information security policy, assessments and methodologies.
- Advises on the reporting requirements and ensure the overall implementation of the ISM policy in service operation.
- Assists with the design and operation of related compliance with both internal security policies and application laws and regulations.
- Ensures that appropriate security assessment have been carried out so that the ISMS security strategy is developed and aligned to service and operational requirements.
- Supports the development of an ISMS security audit management strategy that is aligned to service and operational requirements and develop information security design criteria and templates.
- Considers technical requirements and implications of service and business levels and develop the ISMS security review criteria, verifying that the solution design meets ISMS, client, and regulatory requirements.
- Evaluates the adequacy, implementation, maintenance of operational processes, guides and drives the implementation of process controls to ensure alignment to ISMS obligations. When deviations occur, ensures root cause is identified and treated. Monitors and holds accountable managers to implement prevention and remediation to ensure ongoing compliance to ISM policy.
To thrive in this role, you need to have:
- Relevant people management skills.
- Ability to participate with other senior managers to establish strategic plans and objectives.
- Ability to make final decisions on administrative or operational matters and ensures operations effective achievement of objectives.
- Advanced understanding of complex inter-relationships in an overall system or process.
- Excellent interpersonal and consultative skills with the ability to map business needs to technology solutions.
- Ability to discuss and report technology and information security risk with non-technology and executive business stakeholders.
- Ability to display analytical thinking and a proactive approach.
- Team player with the ability to display consistent client focus and orientation.
- Ability to develop, define and articulate ISM strategies.
- Good strategic thinking and decision-making abilities.
- Ability to plan and organize, with good project management skills.
- Advanced understanding of security risk management, operational processes and controls - End-to-end information security risk lifecycle management.
- Advanced knowledge of information security management and policies, risk management and risk frameworks.
Academic qualifications and certifications:
- Bachelor’s degree or equivalent in Information Technology or Computer Science degree or related field.
- Security certifications such as CISA, CRISC, COBIT, IIA or equivalent preferred.
- Certifications such as Lead audit/Implementer - ISO 27001, SOC TSP preferred.
Required experience:
- Advanced experience gained within the Technology Information Security Industry.
- Advanced experience with Operational Risk Management and Enterprise Risk Management.
- Advanced experience in risk Identification in complex technical program of work, new technologies, changes in systems, changes in organizational structures, changes in regulatory requirements, changes in the attestation standards, and Security Operational activities.
- Advanced experience with Enterprise Risk Management solutions (i.e., ServiceNow GRC or similar).
- Advanced experience in technical Information Security consulting, architecture, design, implementation or similar technical qualifications (although not current).
- Advanced experience in maintaining up-to-date knowledge of security threats, countermeasures, security tools, and network technologies.
- Advanced knowledge of technological advances within the information security arena.
Workplace type:
On-site WorkingAbout NTT DATA
NTT DATA is a $30+ billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world’s leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. Our consulting and industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is part of NTT Group, which invests over $3 billion each year in R&D.
Equal Opportunity Employer
NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Join our growing global team and accelerate your career with us. Apply today.
Third parties fraudulently posing as NTT DATA recruiters
NTT DATA recruiters will never ask job seekers or candidates for payment or banking information during the recruitment process, for any reason. Please remain vigilant of third parties who may attempt to impersonate NTT DATA recruiters—whether in writing or by phone—in order to deceptively obtain personal data or money from you. All email communications from an NTT DATA recruiter will come from an @nttdata.com email address. If you suspect any fraudulent activity, please contact us.
Experience Level
Mid LevelJob role
Work location
hyderabad, India
Department
IT & Information Security
Role / Category
IT Security
Employment type
Full Time
Shift
Day Shift
Job requirements
Experience
Min. 5 years
About company
Name
NTT DATA Global Delivery Services Ltd
Job posted by NTT DATA Global Delivery Services Ltd
Apply on company website