This role reports to the Information Security Governance, Risk and Compliance (GRC) Manager and will work across all the product and technology teams to strengthen and enforce Bottomline’s information security posture. As the Information Security GRC consultant, you will be responsible for building trust and confidence among our clients on the information security posture. This role also involves working closely with stakeholders to ensure adherence to regulatory requirements and security frameworks (e.g., SWIFT, NACHA, PCI, NIST, GLBA). Candidates are advised to apply soon, before the link expires
Name of the
Organization: Bottomline
Requisition
ID: 7715080002
Positions: Information
Security GRC Analyst
Location: Remote (WFH)
Salary: As per
company Norms
Educational
Qualifications:
- Bachelor’s degree in risk management, cybersecurity, technology or equivalent
Preferred Experience
& Qualifications:
- Cyber or risk management certifications
- Understanding and knowledge of cyber regulatory and industry frameworks (i.e., SWIFT, NACHA, PCI, NIST, GLBA)
Responsibilities:
- Governance – work with key stakeholders to develop, implement and enhance the information security policies, standards and processes in alignment with regulatory requirements and security frameworks (e.g., SWIFT, NACHA, PCI, NIST, GLBA). Execute governance routines and reporting to ensure compliance with required policies and standards.
- Risk Management – build and maintain a control library for enterprise-wide controls and product specific controls. Maintain the risk register (issues and risk acceptances) to ensure effective tracking, prioritization and reporting of risks. Process risk acceptances to ensure they are appropriately rated with sufficient mitigating controls.
- Compliance – Coordinate assessments to ensure compliance with applicable regulations and industry requirements (e.g., SWIFT, NACHA, PCI, NIST, GLBA).
- Client Support - Gather, assess and present the information security posture to customer (i.e., completion of request for information, contract language reviews, completion of due diligence questionnaires etc.).
- Education and Awareness – develop and deliver information security awareness and training
Apply Link –
Click Here
For Regular
Updates Join our WhatsApp – Click Here
For Regular Updates Join our Telegram – Click Here
0 Comments
Thanks for your comment, Will Reply shortly.