Loading open roles
Loading open roles
Loading role

UpMan Placements Private Limited · posted 7 months ago
Job Description
Create and Maintain IT /IS vendor Risk assement framework, SOP, Schedules.
Review vendor security documentation like policies, procedures, system diagrams, and incident logs to verify their adherence to security standards.
Conduct thorough risk assessments of potential and existing vendors by reviewing their security policies, procedures, and technical infrastructure to identify potential security gaps.
Assess vendor compliance with industry regulations and standards like ISO 27001, PCI, RBI IT Outsourcing guideline, DPDP, ensuring they meet the necessary information /cyber security and data protection requirements.
Evaluate the effectiveness of vendor security controls including access management, data encryption, incident response plans, vulnerability management, and network security measures.
Perform on-site visits to vendor facilities to conduct hands-on assessments of their security posture, including physical security measures and data handling practices.
Prepare detailed assessment reports outlining identified security risks, vulnerabilities, and recommendations for remediation, communicating findings to both vendor and internal stakeholders.
Collaborate with procurement teams/ ERM team to identify and manage security risks associated with new vendors, ensuring they meet the required security standards before onboarding.
Monitor vendor security posture on an ongoing basis to ensure they maintain compliance and address identified issues promptly.
Required Skills:
Strong understanding of information security principles, best practices, and industry standards (e.g., NIST, ISO 27001, PCI DSS, DPDP, RBI Guidelines)
Experience with conducting security assessments and audits
Knowledge of network security, application security, and data protection technologies
Excellent communication and interpersonal skills to effectively interact with vendors and internal stakeholders
Analytical skills to identify potential security risks and prioritize mitigation strategies
Ability to write clear and concise reports with actionable recommendations
Phishing Drill & Information Security Awareness
Key Responsibilities:
Crafting targeted messaging and campaigns to deliver key security concepts to different employee groups
Developing content like presentations, videos, posters, and e-learning modules to reinforce security practice
Implement ongoing security awareness campaigns using various communication channels (email, intranet, posters) to reinforce cybersecurity best practices
Create realistic phishing email scenarios, including varied attack vectors like email attachments, malicious links, and social engineering tactics to test employee awareness.
Launch phishing simulations across the organization, closely monitor employee responses, and track click-through rates to identify potential risks.
Analyze results from phishing drills, generate comprehensive reports highlighting areas of concern, individual employee performance, and overall security awareness trends.
Design and deliver customized training modules based on identified weaknesses from phishing drills, focusing on specific phishing tactics and safe online behaviors.
Collaborate with security leadership to communicate phishing drill results, advocate for security awareness initiatives, and present actionable insights to improve the organization's cybersecurity posture.
Required Skills:
Understanding of common phishing techniques, social engineering tactics, and Information /cybersecurity /Data Privacy best practices.
Ability to craft engaging training materials, present information clearly, and effectively communicate security concerns to diverse audiences.
Proficiency in analyzing data from phishing simulations to identify patterns and trends, and generate actionable reports.
Familiarity with phishing simulation platforms, and learning management system.