Information Risk Manager

Cognizant ,
London, Greater London

Overview

Job Description

Job title: Information Risk Manager Reference number: 34859 Location: London Salary: 55,000-66,000 Advert posting: 8/05/2020 Advert expiry: 4/06/2020 The Information Risk Management (IRM) is a global team that is responsible for ensuring all security risks pertaining to business delivery and Client engagements are managed end to end. The team engages on a frequent basis with business leaders to identify, analyze and mitigate security risks. As a Senior Manager in IRM (Information Risk Management), you will be part of Corporate Security Group and facilitate security requirements for Cognizant EU office(s) and its clients. Key responsibilities: Manage security and compliance risks in service delivery for key verticals and communicate with Business teams to understand all critical security requirements and risk scenarios. Engage in IRM program for the key accounts: define control framework; identify and evaluate risks; understand business context and prepare reports and recommendations. Coordinate with Incident management team during incidents and support investigation of security breaches. Perform annual Security Risk assessments and conduct related ongoing compliance monitoring activities in coordination with Privacy Officer and Legal Team members. Manage External ISO 27001 audit and coordination with auditors: plan out audit schedule and charter for corporate functions and coordinate with all internal stakeholders towards preparation. Assess, prepare and ensure all IT systems, policies and procedures fully comply with Cognizant ISO 27001 SoA, security laws, rules and regulations. Engage with different stakeholders: external auditors, customer visitor, business leaders and corporate teams, such as HR, legal, IT, etc. Conduct reviews to assess the service delivery control environment and evaluate adherence to client identified contractual requirements, Cognizant policies and standards. PCI-DSS related activities including the identification of compliance gaps, the development of remediation plans, scan, PCI certification, documentation, monitoring compliance status, and ultimate attestation of compliance. Support business team during deal pursuit. Key requirements: Relevant information risk management experience gained in a Tier 1 IT consultancy. Security certifications such as CISA or CISSP. Strong knowledge on GDPR, PCI Security requirements, SOC2 Standards, rules and regulations. Experience across different industry sectors. Proven experience in information security and risk management field, especially with Technology Risk Management / IT Audit in Enterprise organizations. Strong experience in understanding and deploying risk management and security frameworks such as NIST, ISF and ISO. Master's degree level in Computer Science ideally within Information Security. In-depth understanding of network and system security technology and practices across all major-computing areas with a special emphasis on Internet related technology. Understanding of DLP and eDiscovery tools as well as mapping Data Flows and processes. Experience and certification in ISO 27001 Information Security Management system, Risk Assessments, Evaluation of results / findings, IT GRC Governance Risk Compliance Tools. Strong collaboration skills and willingness to be a team player.