HamburgerMenu
hirist

Ekfrazo Technologies - Security Risk & Compliance Management Specialist III

EKFRAZO TECHNOLOGIES PRIVATE LIMITED
6 - 8 Years
Hyderabad

Posted on: 29/08/2026

Job Description

Job Description :

Acts as an advocate in development of overall information security program globally. Creates and performs global IT Risk and Compliance assessments. Assists in development and execution of information security, compliance, and risk best practices globally through audits, assessments, and policy-making.

Career Level Summary :

- Requires in-depth conceptual and practical knowledge in own job discipline and basic knowledge of related job disciplines.

- Solves complex problems.

- Works independently, receives minimal guidance.

- May lead projects or project steps within a broader project or may have accountability for ongoing activities or objectives.

- Acts as a resource for colleagues with less experience.

- Level at which career may stabilize for many years or until retirement.

Critical Competencies :

- Excellence : Exceeds expectations by consistently demonstrating accountability, discipline, high performance, and a proven track record of exceptional results.

- Customer-driven : Prioritizes customer needs and satisfaction through collaborative and proactive problem-solving, and an unwavering commitment to customer success.

- Expertise : Possesses deep understanding of customer needs and continually grows and enhances skills to provide customer-focused solutions.

- Agility : Quickly adapts and responds to dynamic customer needs and expectations through innovative solutions.

- Compassion : Cultivates a positive and supportive environment to effectively work together towards a common goal, fostering trust within HGS and with external stakeholders.

Key Responsibilities :

- Collaborates across the organization to execute and mature the Risk Assessment process, including developing all necessary charters, processes, methodologies, and reports.

- Participates in cross-functional workgroups and planning meetings to promote ideal solutions that meet the objectives of both the business and the IT Risk, Compliance, and Information Security team.

- Where ideal solutions cannot be found, identifies and reports enterprise level risks and failures to management for escalation.

- Promotes sharing of expertise through consulting, presentation, and documentation.

- Assists in training other Information Security, IT Risk, and compliance staff.

- Communicates the value of IT Risk, Compliance, and Information Security within the organization.

- Continuously validates the organization against additional mandates, as developed, to ensure full compliance.

- Coordinates cross-functionally to ensure a holistic approach to security and compliance across the organization.

- Evaluates, monitors, and ensures compliance with IT Risk and Information Security policies, standards, guidelines and relevant legal and regulatory requirements.

- Supports business partners where necessary in dealing with current and prospective clients.

- Risk: Conducts IT Risk and Information Security due diligence activities relative to vendors and third parties.

- Conducts risk assessments and documents findings where the deviation from an information security or IT Risk policy or standard is desired.

- Creates risk remediation plans with business owners and follows through in the implementation of changes.

- Compliance : Conducts annual audits for industry specific reports, including PCI, ISO27001, SOC1, SOC2, SOC3, SOX, and CDSA.

- Documents findings where deviations exist through internal or external testing.

- Develops internal control testing and documented processes.

- Updates internal control matrices where necessary to support annual changing environments.

- Ability to adapt and create processes as applicable, including changes in processes or reporting metrics.

- Executes as the conduit between internal control owners and external auditors, including kickoff meetings, interview requests, closing meetings, and evidence gathering.

- Executes internal customer audits which include scheduling, presentation of the HGS compliance portfolio, and overseeing the successful visit in conjunction with Account Managers.

Knowledge :

- Intermediate knowledge of various Compliance Regulations/ Standards; PCI, ISO27001, Audit Standard #70, Safe Harbor, HIPPA and FISMA.

- Intermediate knowledge of IT Risk Management, Governance, Risk and Compliance, Information Security, Data Privacy, Vendor Management, and/or Business Continuity Management.

Education :

- High School Diploma or regional equivalent required.

- Bachelor's Degree required, preferably in field related to role. At the managers discretion, additional relevant experience may substitute degree requirement.

Certifications :

- Security+, Network+, Project+, CISSP, Professional certifications preferred.

- Risk : CRISC, ISSEP, GCED, GCIA.

- Compliance : CISA.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...