About this role
About the Role Senior information security professional tasked with defining, implementing, and auditing cybersecurity standards across clients, with a focus on PCI DSS, SWIFT CSP, ISO 27001:2022, ISO 27701, and SOC 2. The role involves risk assessment, data flow analysis, and guidance on data protection, governance, and compliance, based in Mumbai or Bengaluru. What You'll Do
- Hands-on experience in information security and cybersecurity standards (PCI DSS, SWIFT CSP, ISO 27001:2022, ISO 27701, SOC2, etc).
- Develop and implement cybersecurity standards, procedures, and guidelines for multiple frameworks.
- Analyze security requirements, perform risk assessments, and identify vulnerabilities within IT systems.
- Conduct gap analyses and risk assessments to identify threats using NIST, ISO, PCI DSS, and SWIFT frameworks.
- Analyze cardholder data flows and provide guidance on PCI DSS awareness.
- Conduct regular PCI DSS audits to ensure secure payment transactions.
- Collect, analyze, and consolidate evidence of PCI DSS compliance, including AOC and ROC documentation.
- Conduct current-state data flow assessments to identify sensitive datasets requiring obfuscation.
- Develop a comprehensive data obfuscation framework with governance, workflows, and control points.
- Deliver documentation, playbooks, and knowledge transfer for long-term sustainability.
- Provide guidance on tool selection and integration within data management and DevOps environments.
- Establish validation and monitoring controls to ensure data integrity and protection.
- Explain technical vulnerabilities clearly and effectively.
- Possess intermediate knowledge of Active Directory, firewalls, routers, switches, SCCM, McAfee, DLP, secure coding practices, and product security. What We're Looking For
- Excellent communication and presentation skills.
- Hands-on experience with cybersecurity standards and regulatory frameworks (PCI DSS, SWIFT CSP, ISO 27001:2022, ISO 27701, SOC2).
- Strong ability to perform risk assessments, gap analyses, and data flow analyses.
- Experience with PCI DSS audits, AOC/ROC documentation, and data governance.
- Familiarity with data obfuscation, data protection, and DevOps integration.
- Working knowledge of Active Directory, network security components, DLP, and secure coding practices. Compensation & Benefits
- Not specified in the posting.