GRC Architect
location_onChennaischedule昨天
home工作方式:远程
school学历:高中
职位描述
Job Summary
We need urgently one GRC person who is good at documentation and is knowledgeable about controls needed for regulations. Perfect match would be someone who knows NIS 2 especially ENISA controls. If not we can consider NIST CSF or 800-53.
Responsibilities
- Design and maintain an integrated governance risk and compliance framework that aligns PCI DSS GDPR and CCPA obligations with organizational policies and control objectives to support sustainable business growth
- Develop comprehensive compliance management strategies and roadmaps that translate regulatory requirements into practical control designs tailored to work from home environments and rotational shift operations
- Conduct detailed assessments of existing processes and systems to identify compliance gaps related to PCI DSS GDPR and CCPA and recommend remediation actions that strengthen organizational resilience
- Create standardized methodologies for risk identification risk prioritization and risk treatment that embed data protection and payment card security into everyday business activities
- Coordinate cross functional compliance initiatives by defining clear objectives deliverables and timelines that help teams understand their responsibilities and achieve consistent regulatory adherence
- Implement monitoring mechanisms and compliance dashboards that provide management with transparent visibility into control effectiveness incident trends and regulatory obligations across geographies
- Guide project teams on embedding privacy by design and security by design principles into technology solutions ensuring that customer data and payment information remain protected throughout the lifecycle
- Prepare and refine policies standards and procedures for data handling access management logging and incident response that reflect PCI DSS GDPR and CCPA requirements and support remote work practices
- Collaborate with audit and assurance functions to plan and support internal and external assessments ensuring evidence is well organized findings are accurately documented and remediation is tracked
- Provide structured training and awareness content for employees working remotely and in rotational shifts so they understand compliance expectations practical behaviors and the impact of nonconformance
- Evaluate new tools platforms and automation opportunities that improve compliance management activities such as control testing documentation retention and regulatory reporting while reducing manual overhead
- Analyze incidents deviations and near misses to determine root causes and recommend targeted improvements that reduce the likelihood of recurrence and improve overall governance maturity
- Document architecture decisions data flows and control mappings in a clear manner so stakeholders can trace how regulatory requirements are implemented and verify that risk is appropriately managed
Qualifications
- Possess extensive hands on experience in compliance management frameworks with demonstrated ability to interpret complex regulatory requirements and convert them into actionable control designs
- Bring deep expertise in PCI DSS domains including network security access control logging vulnerability management and cardholder data protection applied within large scale enterprise environments
- Demonstrate strong knowledge of GDPR principles such as lawfulness fairness transparency data minimization purpose limitation and data subject rights with proven experience implementing compliant solutions
- Show practical experience applying CCPA requirements including consumer rights disclosure obligations data sale restrictions and opt out mechanisms within business processes and technical architectures
- Apply advanced understanding of governance and compliance methodologies to design policies standards and procedures that are pragmatic easy to adopt and aligned with organizational risk appetite
- Utilize excellent analytical and problem solving skills to assess complex environments balance regulatory expectations with business needs and propose clear prioritized remediation actions
- Communicate clearly with technical and nontechnical stakeholders to explain regulatory impacts control choices and risk implications in a concise actionable manner that encourages informed decisions
提及的技能
申请该职位
Use the application link supplied with this listing to apply to Cognizant. Check the destination before entering personal information.
