Skip to content

GRC - Prin Cybersecurity Analyst

Unisys

Bangalore, KA, India

What success looks like in this role:

Job Title: GRC - Prin Cybersecurity Analyst

Location: Home Based India

Who we are:

Unisys is a global information technology company that builds high-performance, security-centric solutions for the most digitally demanding businesses and governments on Earth. Unisys’ offerings include security software and services; digital transformation and workplace services; industry applications and services; and innovative software operating environments for high-intensity enterprise computing. Unisys builds better outcomes securely for its clients across the Government, Financial Services and Commercial markets. For more information, visit www.unisys.com.

Our Vision: Enhancing people’s lives through secure, reliable advanced technology.

Our Core Beliefs:

  • Curiosity: We embrace the unknown and continuous learning.
  • Creativity: We look past routine ways of doing things.
  • Client-Centricity: Our clients’ success is our success.
  • Integrity: We act ethically and honestly.

Position Summary:

Unisys is looking for a candidate who will be responsible for managing the internal security audit program including planning, scheduling and conducting the audit across the organisation. The candidate will be required to provide regular updates regarding the status of the audits to senior management, highlight challenges and actions being taken to address them.

This role will also be responsible for maintaining the cloud compliance program. This includes working with various internal teams to ensure compliance to Unisys cloud security policies and supporting the continuous improvement of the cloud compliance.

This role involves communication with management stakeholders and various GIS, CIT and Business Unit teams.

Working relationship with Internal and External Teams

  • Work with GIS and CIT teams – Infrastructure, Applications, Security Architecture, GIS Leadership team, Security Operations team,
  • Work with BISO’s of the four Business units
  • External – Certifying agencies, vendors, client auditors, client account teams

Key Responsibilities:

Manage Security Audits – 70%

  • Manage internal security audit programs based on requirements from International Standards such as ISO, NIST, PCI, SSAE 18 etc.
  • Prepare, review and maintain annual audit calendar, audit plans, audit management documentation & audit lifecycle
  • Schedule and plan audits, perform audit work, including plan preparation, field notes, document findings, and confirm completion of associated remediation actions.
  • Perform Audits based on criteria defined in ISO 27001, ISO 9001, ISO 22301, ISO 20000, NIST, SSAE18 SOC1/SOC2, SOX, PCI-DSS, etc.
  • Perform audits on various internal processes not limited to HR, facilities, endpoint services, and various business processes based on ISO standards
  • Perform Technical audits for various domains of Security – Few examples include Vulnerability and Patch management, Identity and Access Management, Application Development, DevSecOps, Crisis Management and BC/DR.
  • Work with GIS teams to identify scope of infrastructure and applications services to be covered by technical audits.
  • Plan, schedule, and conduct technical audits.
  • Prepare status reports and review with stakeholders on a regular basis

Cloud Compliance – 20%

  • Establish and maintain Cloud Compliance program to determine compliance to Unisys Cloud Security policies and industry frameworks like CIS Benchmarks, NIST etc.
  • Work with GIS Cloud security teams to define and implement cloud security controls .
  • Conduct regular compliance review and support implementation of remediation actions
  • Review compliance status with GIS and CIT leadership on a regular basis.
  • Drive continuous improvement and leverage automation to improve effectiveness and efficiency of cloud security program.
  • Continuously monitor the external environment for new technology/tools/platform and provide recommendations to enhance the cloud security program.
  • Conduct Cloud User access reviews, track remediation and report results.

Other responsibilities –10%

  • Drive GRC tool selection and implementation efforts for the organisation by having experience working with various GRC tools
  • Comfortable working with various AI tools and support secure AI adoption by supporting AI security efforts
  • Work with AI governance to ensure AI security requirements are covered
  • Support global privacy compliance efforts and ensure privacy is considered within the GIS internal processes #LI-RB1

You will be successful in this role if you have:

Knowledge and Qualifications:

  • Bachelors/ Master’s Degree in Engineering in Computer Science.
  • Must have an overall experience of 12-15 years with atleast 5 years technical experience working on infrastructure or application systems.
  • Must have a minimum of 5-8 years relevant experience in internal security audits based on the Industry standards.
  • Must have done technical audits. Should have had and minimum of 2 years experience in Cloud compliance and governance.
  • Must have CISA certification and CCSP or equivalent. CISSP certification would be preferable.
  • Must have working knowledge of ITGC and SSAE18 SOC1/SOC2. Working knowledge of SOX, PCI-DSS, NIST 800=53, CIS Benchmarks would be preferable.
  • Knowledge and experience in AI security and AI security audits
  • Experience working with various GRC tools and GRC automation
  • Must have working knowledge on atleast one CSP – Azure, AWS or GCP. Security-related certifications like AZ 500 would be preferable.
  • Excellent oral, written and presentation skills.
  • Excellent interpersonal and teamwork capabilities.
  • Ability to indirectly manage by influencing larger groups.
  • Ability to work individually but also to collaborate in a virtual team, with vendors and clients.
  • Good change management and project management skills.

Unisys is proud to be an equal opportunity employer that considers all qualified applicants without regard to age, blood type, caste, citizenship, color, disability, family medical history, family status, ethnicity, gender, gender expression, gender identity, genetic information, marital status, national origin, parental status, pregnancy, race, religion, sex, sexual orientation, transgender status, veteran status or any other category protected by law.

Local employment practices and rights may vary by jurisdiction and are subject to applicable local laws. This commitment includes our efforts to provide for all those who seek to express interest in employment the opportunity to participate without barriers.

If you are a US job seeker unable to review the job opportunities herein, or cannot otherwise complete your expression of interest, without additional assistance and would like to discuss a request for reasonable accommodation, please contact our Global Recruiting organization at [email protected]. US job seekers can find more information about Unisys’ EEO commitment here.

Seen 2 hours ago.

Original posting on Unisys's site ↗

Posting text belongs to the employer. Removal requests: contact us.

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

One job at a time

One posting. One CV. $25.

Pick the job you actually want and we write for it.

Get my CV for this job