Source description
About the role
As a Senior Executive/ Assistant Manager in the Information Security team at Grant Thornton India, you will be responsible for developing, implementing, and monitoring security policies to ensure compliance and manage risks across the firm. Your expertise in Governance, Risk, and Compliance (GRC) will be crucial in tracking vulnerabilities, managing security alerts, and overseeing learning modules. Key Responsibilities: - Develop and implement Information Security Management System (ISMS) policies and procedures for policy & compliance. - Design, monitor, and enhance learning modules for security awareness under learning management. - Conduct contract reviews, manage Third-Party Risk Management (TPRM) processes for risk & compliance. - Track and resolve exploitable vulnerabilities, execute phishing tests, and monitor firm-wide progress for security monitoring and phishing & threat management. - Handle Infosec software installations, VPN access, generic email IDs, and admin rights requests ensuring proper tracking and documentation for access & software management. - Monitor and send Security Operations Center (SOC) alerts to relevant teams, prepare Management Information System (MIS) reports for the IT team under reporting & analysis. Qualifications & Skills: - 3-5 years of experience in Information Security Management within consultancy services. - ISO 27001:2022 & ISO 31000 Internal auditor certification required. - Preferred experience with ServiceNow, Learning Management, and Patch Management (Banks/NBFIs/Consultancy) in terms of technical expertise. - Strong analytical and problem-solving skills to assess risks and implement solutions effectively. - Excellent verbal and written communication skills for collaboration. - Attention to detail with a structured approach to security management, being organized and methodical. As a Senior Executive/ Assistant Manager in the Information Security team at Grant Thornton India, you will be responsible for developing, implementing, and monitoring security policies to ensure compliance and manage risks across the firm. Your expertise in Governance, Risk, and Compliance (GRC) will be crucial in tracking vulnerabilities, managing security alerts, and overseeing learning modules. Key Responsibilities: - Develop and implement Information Security Management System (ISMS) policies and procedures for policy & compliance. - Design, monitor, and enhance learning modules for security awareness under learning management. - Conduct contract reviews, manage Third-Party Risk Management (TPRM) processes for risk & compliance. - Track and resolve exploitable vulnerabilities, execute phishing tests, and monitor firm-wide progress for security monitoring and phishing & threat management. - Handle Infosec software installations, VPN access, generic email IDs, and admin rights requests ensuring proper tracking and documentation for access & software management. - Monitor and send Security Operations Center (SOC) alerts to relevant teams, prepare Management Information System (MIS) reports for the IT team under reporting & analysis. Qualifications & Skills: - 3-5 years of experience in Information Security Management within consultancy services. - ISO 27001:2022 & ISO 31000 Internal auditor certification required. - Preferred experience with ServiceNow, Learning Management, and Patch Management (Banks/NBFIs/Consultancy) in terms of technical expertise. - Strong analytical and problem-solving skills to assess risks and implement solutions effectively. - Excellent verbal and written communication skills for collaboration. - Attention to detail with a structured approach to security management, being organized and methodical.
More at Acura Solution