Risk Compliance and Governance Analyst
Job Description
Job Description
- Expertise in cyber security frameworks such as ISO27001, NIST 800-53, NIST CSF, PCI-DSS, ISO22301, data privacy etc.
- Skilled in risk management, risk assessment and analysis, internal audit
- Technical knowledge in the security domains such as information security management and governance, systems and network security, Physical and logical IT controls, application security, data security, cloud security, access controls, authentication, or security protocols etc.
- Experience in conducting vendor onsite assessments. Experience of assessing cloud service providers(CSP) will be an added advantage.
- Understanding third-party risk management concepts, exposure to third party (or) outsourcing regulatory requirements.
Want more jobs like this?
Get jobs in Mumbai, India delivered to your inbox every week.

Role Purpose
The purpose of the role is to analyse security requirements and design security solutions towards
protecting organization's security assets.
Do
- Analyse Risk and Compliance assurance to protect sensitive information
- Identify Risk and compliance issues at all levels as per the updates
- Analyse common compliance frameworks and ensure policies, processes and standards are in place
- Perform quarterly audit, sample testing and report risks
- Communicate assurance findings to the clients in a timely manner
- Monitor remediation on assurance findings and ensure closure of all open points
- Ensure all required controls are implemented, documented and monitored so as to ensure full audit compliance.
- Coordinate with IT team members to ensure IT audit findings are addressed in a timely manner.
- Provide timely and accurate reporting and documentation to management on all key parameters as needed.
- Perform annual SOC preparedness audit to ensure that system set up are secure and maintain privacy of customer data
- Suggest corrective measures to cyber security issues and provide timely support and future recommendations
Stakeholder Interaction
Stakeholder TypeStakeholder IdentificationPurpose of InteractionInternalCRS practice teamReporting and updatesIT teamTo understand IT systems and auditInternal Legal TeamFor discussing legal PracticesExternalCustomerData analysis and reporting
Display
Lists the competencies required to perform this role effectively:
- Functional Competencies/ Skill
- Domain/Industry Knowledge - Awareness and knowledge of Corporate IT Security ~ Contractual IT Governance & Compliance ~ Data Protection ~ Privacy ~ IT General Controls ~ Internal & External IT - Expert
- Leveraging Technology - In-depth knowledge of and mastery over ecosystem technology that commands expert authority respect - Master
- Technical knowledge - Complete understanding of risk and compliance audits((ISO27001, SOX, HIPAA, GLBA, PCI DSS, SSAE16 etc.) - Expert
Competency LevelsFoundationKnowledgeable about the competency requirements. Demonstrates (in parts) frequently with minimal support and guidance.CompetentConsistently demonstrates the full range of the competency without guidance. Extends the competency to difficult and unknown situations as well.ExpertApplies the competency in all situations and is serves as a guide to others as well.MasterCoaches others and builds organizational capability in the competency area. Serves as a key resource for that competency and is recognised within the entire organization.
- Behavioural Competencies
- Strategic perspective
- Technology Acumen
- Communication and Presentation Skills
- Problem Solving approach
- Managing Complexity
- Client centricity
Deliver
No.Performance ParameterMeasure1.Adherence to established risk and compliance framework% deviation from audit, release audit scores, closure on audit points, cyber health of the organization, audit timelines2.Disaster recoveryNumber of risks identified and mitigated, Timely communication to the client
If you encounter any suspicious mail, advertisements, or persons who offer jobs at Wipro, please email us at [email protected]. Do not email your resume to this ID as it is not monitored for resumes and career applications.
Any complaints or concerns regarding unethical/unfair hiring practices should be directed to our Ombuds Group at [email protected].
We are an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, caste, creed, religion, gender, marital status, age, ethnic and national origin, gender identity, gender expression, sexual orientation, political orientation, disability status, protected veteran status, or any other characteristic protected by law.
Wipro is committed to creating an accessible, supportive, and inclusive workplace. Reasonable accommodation will be provided to all applicants including persons with disabilities, throughout the recruitment and selection process. Accommodations must be communicated in advance of the application, where possible, and will be reviewed on an individual basis. Wipro provides equal opportunities to all and values diversity.
Explore More
Apply Now
Back to Job Listings
Add To Job List
Company Profile
View Company Reviews
Date Posted
01/22/2025
Views
0
Neutral
Subjectivity Score: 0
Similar Jobs
Director - Financial Crime & Fraud Analytics, Model Risk (Risk Management) - Morgan Stanley
Views in the last 30 days - 0
View DetailsManager - Risk Consulting, Visa Consulting & Analytics - Visa
Views in the last 30 days - 0
View DetailsDirector, Relationship Manager - Corporate Banking, Subsidiaries, India - Bank of America
Views in the last 30 days - 0
View DetailsSenior Lead Software Engineer - Java Fullstack AWS - JPMorgan Chase
Views in the last 30 days - 0
View Details