Infosec GRC Associate II

undefined ago • 2-5 Years

Job Summary

Job Description

This role is for an Infosec GRC Associate II within Zeta's Information Security Process and Compliance Team. The individual will be responsible for preparing and supporting external audits like PCIDSS, ISO 27001, and SOC. Key duties include strengthening internal audit processes, ensuring technology and process compliance, and collaborating with Cloud and Product security teams to achieve Risk and compliance goals.
Must have:
  • Assess IT architecture for PCI risks.
  • Review network architecture and firewall rules for PCI compliance.
  • Support audit and compliance activities.
  • Conduct PCI DSS scoping, gap analysis, and assessments.
  • Manage multiple assignments and deliverables.
  • Understand SOC reports (SOC2, Type 1, 2) and ISMS.
  • Develop and maintain Vendor Risk Management Program.
  • Implement controls as per RBI and regulatory requirements.
  • Maintain ISMS framework and evaluate controls.
  • Facilitate Client Due-Diligence.
  • Develop and maintain Enterprise Risk Assessment.
  • Perform Internal Assessments against standards.
  • Review contracts and respond to client RFPs.
  • Strong understanding of Technology Risk Assessment.
  • Hands-on experience with PCI DSS Standard.
  • Experience with ISMS, SSAE 18, ISO 27001, ISO 31000, ISO 22301.
  • Experience with CSA Star, NIST Risk framework, PCI 3DS, PCI PA-DSS/SSF, PCI S3.
  • Experience in Vendor Risk Assessment.
  • Excellent written and oral communication.
  • Strong technical documentation skills.
Good to have:
  • Experience of working in the Banking or Payment sector is preferred.
  • Information Security Certifications like CISA, CISM, CISSP etc.

Job Details

About Zeta

Zeta is a Next-Gen Banking Tech company that empowers banks and fintechs to launch banking products for the future. It was founded by Bhavin Turakhia and Ramki Gaddipati in 2015.

Our flagship processing platform - Zeta Tachyon - is the industry’s first modern, cloud-native, and fully API-enabled stack that brings together issuance, processing, lending, core banking, fraud & risk, and many more capabilities as a single-vendor stack. 20M+ cards have been issued on our platform globally.

Zeta is actively working with the largest Banks and Fintechs in multiple global markets transforming customer experience for multi-million card portfolios.

Zeta has over 1700+ employees - with over 70% roles in R&D - across locations in the US, EMEA, and Asia. We raised $280 million at a $1.5 billion valuation from Softbank, Mastercard, and other investors in 2021.

Learn more @ www.zeta.tech, careers.zeta.tech, Linkedin, Twitter

The Role:

This role is part of the Information Security Process and Compliance Team. The Sr. Associate of InfoSec Audit and compliance is responsible for preparing and supporting PCIDSS, ISO 27001 and SOC external Audits. Actively participate, strengthen and improve Internal Audit process and provide assurance on internal technology and process compliance. Collaborate with the Cloud and Product security team to drive Risk and compliance goals.

Responsibilities

  • Work with internal and external stakeholders to assess the IT architecture or proposed IT architecture solutions to identify the risk areas with regards to PCI controls.
  • Assess the network architecture and or reviews the Firewall rulesets, Network devices/appliances to see if they are aligned with the PCI control requirements and recommends compensatory controls where necessary.
  • Execute operational activities to support audit and compliance activities including technical validation processes.
  • Conduct PCI DSS scoping engagements, gap analysis and assessments related to securing the Cardholder Data Environment.
  • Effectively multi-tasks on multiple assignments and deliverables.
  • Actively accepts individual and team responsibilities to meet commitments. Takes responsibility for own performance and actions and demonstrates responsibility and teamwork towards overall team/department goals.
  • Discuss the SOP document with all relevant stakeholders - right from process owner to the BU functional heads Detailed understanding of SOC reports (SOC2, Type 1, 2), ISMS reports and ability to relate the IT General Controls, IT Application Controls, Cyber Controls to the SOC framework.
  • Develop and Maintain Vendor Risk Management /Third Party Risk Management Program including Vendor Onboarding Audit, Periodic Vendor Assessment, Maintain TPRM Database.
  • Review and implement controls and policies as per RBI and other regulatory requirements. Maintain ISMS framework, evaluate effectiveness of implemented controls and provides recommendations for improvement.
  • Facilitate Client Due - Diligence in collaboration with Business.
  • Develop and Maintain Enterprise Risk Assessment framework.
  • Perform Internal Assessment against various Standards to ensure the established policies are being followed and prepare internal reports.
  • Contract review and providing responses to client Request for Proposal (RFP)

Skills

  • Good Understanding of Technology Risk Assessment Frameworks and Application risk Assessment.
  • Good Understanding and hands on experience on PCI DSS Standard and various PCI compliance is must.
  • Experience of working in the Banking or Payment sector is preferred.
  • Hands-on experience with various Audits and Standards Such as ISMS, SSAE 18, ISO 27001,ISO 31000, ISO 22301, CSA Star, NIST Risk framework, PCI DSS, PCI 3DS, PCI PA-DSS/SSF, PCI S3 etc.
  • Good to have Information Security Certifications like CISA, CISM, CISSP etc.
  • Experience of Vendor Risk Assessment and responding to client Request for Proposal(RFP).Excellent written and oral communication and penchant for technical documentation

Experience and Qualifications

  • 2 - 5 years of experience in Information Security and Compliance in medium tolarge-sized companies.
  • Bachelor of Technology (BE/B.Tech), M.Tech or ME in Computer Science, MCA or equivalent.

Equal opportunity

  • Zeta is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We encourage applicants from all backgrounds, cultures, and communities to apply and believe that a diverse workforce is key to our success

Similar Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Similar Skill Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Jobs in Bengaluru, Karnataka, India

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Similar Category Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

About The Company

Bengaluru, Karnataka, India (On-Site)

Bengaluru, Karnataka, India (On-Site)

Bengaluru, Karnataka, India (On-Site)

Bengaluru, Karnataka, India (On-Site)

Bengaluru, Karnataka, India (On-Site)

Hyderabad, Telangana, India (On-Site)

Bengaluru, Karnataka, India (On-Site)

Bengaluru, Karnataka, India (On-Site)

Hyderabad, Telangana, India (On-Site)

Hyderabad, Telangana, India (On-Site)

View All Jobs

Get notified when new jobs are added by zeta

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug