IN_Associate_Compliance Specialist _IN IT Services CO_IFS_PAN India

2 Months ago • 4 Years + • Cyber Security

Job Summary

Job Description

PwC's Network Information Security (NIS) team seeks a Compliance Assessor to identify gaps in adherence to PwC's Information Security Policy. This role involves using questionnaires to assess whether solutions/tools meet security control requirements. Collaboration with risk managers is crucial to identify and address compliance gaps, creating risk treatment plans and mitigating network security risks. The ideal candidate will be familiar with PwC's security policies, risk tolerance, and industry best practices. Responsibilities include reviewing control effectiveness, conducting security reviews across platforms, benchmarking findings, preparing reports, and working with project teams to ensure appropriate risk treatments. Expertise in Identity and Access Management, Data Protection, and other security domains is necessary. Excellent communication and collaboration skills are essential for this position.
Must have:
  • Review control effectiveness
  • Conduct security reviews
  • Benchmark findings, prepare reports
  • Collaborate with risk managers
  • ISO270001 knowledge
  • Power BI proficiency
  • Information Security Policy understanding
Good to have:
  • Understanding of Security Standards (on-premises & cloud)
  • Familiarity with development platforms & secure software lifecycle
  • Technical risk assessment, vulnerability assessment, penetration testing experience
  • Issue tracking, follow-up, global communication skills

Job Details

Line of Service

Internal Firm Services

Industry/Sector

Not Applicable

Specialism

Operations

Management Level

Associate

Job Description & Summary

At PwC, our people in cybersecurity focus on protecting organisations from cyber threats through advanced technologies and strategies. They work to identify vulnerabilities, develop secure systems, and provide proactive solutions to safeguard sensitive data.

In threat intelligence and vulnerability management at PwC, you will focus on identifying and analysing potential threats to an organisation's security, as well as managing vulnerabilities to prevent cyber attacks. You will play a crucial role in safeguarding sensitive information and enabling the resilience of digital infrastructure.

*Why PWC

At PwC, you will be part of a vibrant community of solvers that leads with trust and creates distinctive outcomes for our clients and communities. This purpose-led and values-driven work, powered by technology in an environment that drives innovation, will enable you to make a tangible impact in the real world. We reward your contributions, support your wellbeing, and offer inclusive benefits, flexibility programmes and mentorship that will help you thrive in work and life. Together, we grow, learn, care, collaborate, and create a future of infinite experiences for each other. Learn more about us.

At PwC, we believe in providing equal employment opportunities, without any discrimination on the grounds of gender, ethnic background, age, disability, marital status, sexual orientation, pregnancy, gender identity or expression, religion or other beliefs, perceived differences and status protected by law. We strive to create an environment where each one of our people can bring their true selves and contribute to their personal growth and the firm’s growth. To enable this, we have zero tolerance for any discrimination and harassment based on the above considerations. "

Job Description & Summary: 

PwC is driving major change across information and cybersecurity by building a centralized model to provide security services across the entire member firm network. The Network Information Security (NIS) organization is tasked with designing, implementing and maintaining information security capabilities and services for PwC Network of member firms.  
The NIS - ISP Compliance team role is to identify compliance gaps against the PwC Information Security Policy. The compliance assessor will use the provided questionnaires to identify when a solution or tool is meeting or is not meeting PwC security control requirements.  
The compliance assessor will work closely with the aligned risk manager to identify which compliance gaps should be raised as findings against policy and require a risk treatment plan; thereby limiting security risk in the PwC network. 
The ideal compliance assessor will have familiarity with PwC security policies and standards, and with PwC’s risk tolerance. He or she will identify areas of non-compliance within applications against PwC controls, identify the risk to the project team, and work with the project teams to ensure appropriate risk treatments are in place, culminating in a final risk report. Compliance Assessors should have familiarity with industry security controls and best practices and should have experience in performing compliance assessments

Responsibilities:

As a Compliance assessor, you would, 

  • Review of the effectiveness of controls referring the evidence provided 
  • Responsible for carrying out critical security reviews in a cross territory cross-platform environment where collaboration with different teams is a key requirement. 
  • Ability to understand the Information Security Policy, evidence requirements and test procedures linked to controls 
  • Benchmark the findings with the best practices 
  • Prepare matrix and reports 
  • Demonstrate appropriate knowledge on understanding effective control implementation in the following domains: 
  • Identity and Access Management 
  • Data Protection 
  • Borderless Connectivity 
  • Cloud & Services Hosting 
  • Endpoint Security 
  • Cyber Security Operations 
  • Application Security 
  • Demonstrate flexibility, adaptation, and eagerness for learning in an ever-changing global enterprise environment. 
  • Flexible with the time of operations (no night shift though) 
  • IT Audit exposure/experience preferred 
  • Good working knowledge in MS Office tools 
  • Demonstrates some abilities and/or a proven record of success in the following areas: 
  • Building solid relationships with stakeholders and colleagues. 
  • Approaching stakeholders and colleagues in an organized manner 
  • Delivering clear requests for information 
  • Demonstrating flexibility in prioritizing and completing tasks 
  • Escalating potential conflicts to a supervisor 
  • Performing research using available tools and methodologies 
  • Writing and communicating in a corporate environment 

Mandatory skill sets:

ISO270001, Power BI, Information Security Policy

Preferred skill sets:

  • Good understanding of Security Standards, on-premises as well as cloud-based. 
  • Good understanding of different development platforms and secure software lifecycle concepts. 
  • Good understanding and exposure to technical risk assessment along with vulnerability assessment and penetration testing. 
  • Proper experience in coordination Issue tracking, Follow-Ups, and communication skills in a global environment. 

Years of experience required:

  4 yrs

Education qualification:

Bachelor’s degree 

Education (if blank, degree and/or field of study not specified)

Degrees/Field of Study required: Bachelor Degree

Degrees/Field of Study preferred:

Certifications (if blank, certifications not specified)

Required Skills

Compliance PCI

Optional Skills

Accepting Feedback, Accepting Feedback, Active Listening, Cloud Security, Communication, Conducting Research, Cyber Defense, Cyber Threat Intelligence, Emotional Regulation, Empathy, Encryption, Inclusion, Information Security, Intellectual Curiosity, Intelligence Analysis, Intelligence Report, Intrusion Detection, Intrusion Detection System (IDS), IT Operations, Malware Analysis, Malware Detection Tools, Malware Intelligence Gathering, Malware Research, Malware Reverse Engineering, Malware Sandboxing {+ 11 more}

Desired Languages (If blank, desired languages not specified)

Travel Requirements

Available for Work Visa Sponsorship?

Government Clearance Required?

Job Posting End Date

Similar Jobs

Blinkhealth - Sr. Security Analyst – Cloud Security & Application Security

Blinkhealth

India (On-Site)
2 Months ago
Microsoft - Senior/Principal Software Engineer - CTJ - Poly

Microsoft

Redmond, Washington, United States (On-Site)
1 Month ago
Nielsen Holdings - Data Engineer

Nielsen Holdings

Mumbai, Maharashtra, India (Hybrid)
2 Months ago
HRS Group - Security Compliance Engineer (all genders)

HRS Group

Sahibzada Ajit Singh Nagar, Punjab, India (Hybrid)
4 Months ago
Axinous - Principal Product Specialist

Axinous

United States (Remote)
3 Weeks ago
Tesla - Security Operations Center (SOC) Operator

Tesla

Milton Keynes, England, United Kingdom (On-Site)
1 Week ago
PwC - Cloud Security | Manager | Cyber Security | Technology Consulting

PwC

Dublin, County Dublin, Ireland (On-Site)
4 Months ago
PwC - Senior Cyber Security Consultant

PwC

Athens, Greece (Hybrid)
4 Months ago
King - Summer 2025 Security Data Analyst Intern

King

Barcelona, Catalonia, Spain (On-Site)
3 Weeks ago
ION - Network Security Engineer

ION

Milan, Lombardy, Italy (Hybrid)
4 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Axinous - Senior Financial Analyst, FP&A

Axinous

Sahibzada Ajit Singh Nagar, Punjab, India (On-Site)
2 Months ago
PwC - Manager_ Cloud Architecture _ Advisory corporate _ Advisory _ Hyderabad

PwC

Hyderabad, Telangana, India (On-Site)
3 Months ago
Axinous - Account Executive, Enterprise - Mexico

Axinous

Mexico (Remote)
1 Week ago
Nagarro - Associate Principal Engineer

Nagarro

Sri Lanka (Remote)
4 Months ago
Morning Star - Senior Application Security Architect

Morning Star

Chicago, Illinois, United States (Hybrid)
4 Months ago
Zazz - Cybersecurity Analyst

Zazz

(Remote)
5 Days ago
ION - Senior DevSecOps Engineer, Italy

ION

London, England, United Kingdom (On-Site)
4 Months ago
Google - Staff Software Engineer, Security/Privacy, Google Cloud Security and Privacy

Google

San Francisco, California, United States (On-Site)
3 Months ago
bosh group india - 2024_MS_EDE3_XC_SRE_DataEngineering

bosh group india

Bengaluru, Karnataka, India (On-Site)
2 Months ago
Axinous - Account Executive - Enterprise

Axinous

Hyderabad, Telangana, India (Remote)
1 Week ago

Get notifed when new similar jobs are uploaded

Jobs in Gurugram, Haryana, India

Azul - Senior Compiler Engineer

Azul

Bengaluru, Karnataka, India (Remote)
4 Months ago
Unity - Developer Relations Consultant

Unity

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Advarra - UI Developer

Advarra

Bengaluru, Karnataka, India (Hybrid)
4 Months ago
NVIDIA - Senior CPU Verification Engineer

NVIDIA

Hyderabad, Telangana, India (On-Site)
1 Month ago
PwC - IN_Manager_Digital Strategy _IT Function Transformation _Advisory_Mumbai

PwC

Mumbai, Maharashtra, India (On-Site)
3 Months ago
Dream Sports - Senior Manager - Human Resources

Dream Sports

Mumbai, Maharashtra, India (On-Site)
1 Month ago
Carina Softlabs  Inc  - Unreal Game Developer

Carina Softlabs Inc

Indore, Madhya Pradesh, India (On-Site)
4 Months ago
Actian - C++ Engineer - Pune

Actian

Pune, Maharashtra, India (On-Site)
4 Months ago
Nagarro - Senior Staff Engineer, .Net Web

Nagarro

India (Remote)
4 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

NVIDIA - Senior Security Engineer, Purple Team - GPU Firmware

NVIDIA

Santa Clara, California, United States (On-Site)
1 Month ago
Anavation - Information Security Engineer

Anavation

Reston, Virginia, United States (On-Site)
4 Months ago
Globalization Partners - Information Security Analyst - SecOps

Globalization Partners

United States (Remote)
1 Month ago
The Walt Disney Company - Associate Security Specialist, Corrective Action

The Walt Disney Company

Orlando, Florida, United States (On-Site)
5 Days ago
Axinous - Sr. Product Support Engineer- Zero Trust Network

Axinous

Texas, United States (Remote)
4 Days ago
Normalyze - Performance Test - Senior Engineer - Solutions - Data Security - India

Normalyze

Bengaluru, Karnataka, India (Remote)
2 Months ago
ION - Pen Tester, Italy

ION

Italy (Hybrid)
4 Months ago
Infoblox - Technical Writer II

Infoblox

Bengaluru, Karnataka, India (On-Site)
4 Months ago
NVIDIA - Senior GPU Hardware Security Architect, Memory Security and System Configuration

NVIDIA

Santa Clara, California, United States (On-Site)
1 Month ago
ION - Senior Security Architect

ION

Italy (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

About The Company

At PwC, our purpose is to build trust in society and solve important problems. We’re a network of firms in 152 countries with over 327,000 people who are committed to delivering quality in assurance, advisory and tax services. Find out more and tell us what matters to you by visiting us at www.pwc.com. PwC refers to the PwC network and/or one or more of its member firms, each of which is a separate legal entity.


Content on this page has been prepared for general information only and is not intended to be relied upon as accounting, tax or professional advice. Please reach out to your advisors for specific advice.

Gqeberha, Eastern Cape, South Africa (On-Site)

Athens, Greece (Remote)

Qormi, Malta (On-Site)

Kolkata, West Bengal, India (On-Site)

Copenhagen, Denmark (On-Site)

Bucharest, Bucharest, Romania (On-Site)

Kolkata, West Bengal, India (On-Site)

Kolkata, West Bengal, India (On-Site)

View All Jobs

Get notified when new jobs are added by PWC

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug