GRC - Prin Cybersecurity Analyst
What success looks like in this role:
Job Title: GRC - Prin Cybersecurity Analyst
Location : Home Based India
Who we are:
Unisys is a global information technology company that builds high-performance, security-centric solutions for the most digitally demanding businesses and governments on Earth. Unisys β offerings include security software and services; digital transformation and workplace services; industry applications and services; and innovative software operating environments for high-intensity enterprise computing. Unisys builds better outcomes securely for its clients across the Government, Financial Services and Commercial markets. For more information, visit .
Our Vision: Enhancing peopleβs lives through secure, reliable advanced technology.
Our Core Beliefs:
- Curiosity: We embrace the unknown and continuous learning.
- Creativity: We look past routine ways of doing things.
- Client-Centricity: Our clientsβ success is our success.
- Integrity: We act ethically and honestly.
Position Summary:
Unisys is looking for a candidate who will be responsible for managing the internal security audit program including planning, scheduling and conducting the audit across the organisation. The candidate will be required to provide regular updates regarding the status of the audits to senior management, highlight challenges and actions being taken to address them.
This role will also be responsible for maintaining the cloud compliance program. This includes working with various internal teams to ensure compliance to Unisys cloud security policies and supporting the continuous improvement of the cloud compliance.
This role involves communication with management stakeholders and various GIS, CIT and Business Unit teams.
Working relationship with Internal and External Teams
- Work with GIS and CIT teams β Infrastructure, Applications, Security Architecture, GIS Leadership team, Security Operations team,
- Work with BISOβs of the four Business units
- External β Certifying agencies, vendors, client auditors, client account teams
Key Responsibilities:
Manage Security Audits β 70%
- Manage internal security audit programs based on requirements from International Standards such as ISO, NIST, PCI, SSAE 18 etc.
- Prepare, review and maintain annual audit calendar, audit plans, audit management documentation & audit lifecycle
- Schedule and plan audits, perform audit work, including plan preparation, field notes, document findings, and confirm completion of associated remediation actions.
- Perform Audits based on criteria defined in ISO 27001, ISO 9001, ISO 22301, ISO 20000, NIST, SSAE18 SOC1/SOC2, SOX, PCI-DSS, etc.
- Perform audits on various internal processes not limited to HR, facilities, endpoint services, and various business processes based on ISO standards
- Perform Technical audits for various domains of Security β Few examples include Vulnerability and Patch management, Identity and Access Management, Application Development, DevSecOps, Crisis Management and BC/DR.
- Work with GIS teams to identify scope of infrastructure and applications services to be covered by technical audits.
- Plan, schedule, and conduct technical audits.
- Prepare status reports and review with stakeholders on a regular basis
Cloud Compliance β 20%
- Establish and maintain Cloud Compliance program to determine compliance to Unisys Cloud Security policies and industry frameworks like CIS Benchmarks, NIST etc.
- Work with GIS Cloud security teams to define and implement cloud security controls .
- Conduct regular compliance review and support implementation of remediation actions
- Review compliance status with GIS and CIT leadership on a regular basis.
- Drive continuous improvement and leverage automation to improve effectiveness and efficiency of cloud security program.
- Continuously monitor the external environment for new technology/tools/platform and provide recommendatio
Get remote developer jobs like this by email
10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.
Similar for you
Get 10 hand-picked remote jobs like this one in your inbox every morning. One email a day, matched to what you browse. No spam, one-click unsubscribe.
No thanks β continue to the application β