Padmi

Analyst - GRC (Governance, Risk & Compliance)

IndiaPosted 3 months ago
CybersecurityJuniorFull Time; Regular
Apply at AMI Corporation

Opens the source posting on shine.com

Source description

About the role

View original

As a candidate for the role of supporting sustainable governance and compliance practices at Amagi, you will play a crucial part in building repeatable internal compliance validation and vendor security risk review processes. Your success in this position will rely on your deep understanding of the company's vendor landscape and compliance requirements. Key Responsibilities: - Support products in sustaining SOC2 compliance through regular internal assessments. - Engage with vendors for regular security and risk reviews. - Continuously monitor and score vendor risk. - Monitor the effectiveness of security controls and highlight any deviations. - Implement Amagi's Security Awareness Program. - Manage governance documentation. Qualification Required: - Basic understanding and working knowledge of AWS / GCP. - Familiarity with security standards, policies, and processes. - Knowledge of SOC2, audit, and compliance validation. - Experience in carrying out TPRM assessments. - Strong documentation skills. - Ability to collaborate cross-functionally with Legal, IT, and Engineering. - Analytical and problem-solving mindset. - Comfort with ambiguity and willingness to shape early-stage processes. In the next two years, the desired outcomes include establishing a sustainable vendor security risk management process, a dedicated internal compliance team, continuous monitoring and reporting of the Product risk posture, and processes to evaluate the implementation effectiveness of security controls. You will report to the Director - GRC and operate within the realms of Third-Party Risk Management (TPRM), support for Audit Readiness and Evidence Collection, and Internal Governance and Risk Management. With 1-3 years of experience in Vendor risk management and Compliance review, you will be a valuable addition to the team at Amagi as you embody traits such as being a team player, hands-on at work, innovative in cybersecurity risk management and governance, eager to learn technical aspects of security, and a self-starter. As a candidate for the role of supporting sustainable governance and compliance practices at Amagi, you will play a crucial part in building repeatable internal compliance validation and vendor security risk review processes. Your success in this position will rely on your deep understanding of the company's vendor landscape and compliance requirements. Key Responsibilities: - Support products in sustaining SOC2 compliance through regular internal assessments. - Engage with vendors for regular security and risk reviews. - Continuously monitor and score vendor risk. - Monitor the effectiveness of security controls and highlight any deviations. - Implement Amagi's Security Awareness Program. - Manage governance documentation. Qualification Required: - Basic understanding and working knowledge of AWS / GCP. - Familiarity with security standards, policies, and processes. - Knowledge of SOC2, audit, and compliance validation. - Experience in carrying out TPRM assessments. - Strong documentation skills. - Ability to collaborate cross-functionally with Legal, IT, and Engineering. - Analytical and problem-solving mindset. - Comfort with ambiguity and willingness to shape early-stage processes. In the next two years, the desired outcomes include establishing a sustainable vendor security risk management process, a dedicated internal compliance team, continuous monitoring and reporting of the Product risk posture, and processes to evaluate the implementation effectiveness of security controls. You will report to the Director - GRC and operate within the realms of Third-Party Risk Management (TPRM), support for Audit Readiness and Evidence Collection, and Internal Governance and Risk Management. With 1-3 years of experience in Vendor risk management and Compliance review, you will be a valuable addition to the team at Amagi as you embody traits such as being a team player, hands-on at work, innovative in cybersecurity risk management and governance, eager to learn technical aspects of security, and a self-starter.

One address, no account. We’ll tell you when matching roles go live.