Senior/Staff Cyber security Engineer (Governance, Risk & Compliance)

  • Bengaluru
  • Synopsys Inc
Senior/Lead Cyber Security Engineer (Governance, Risk, Compliance) Location:

Bangalore Experience:

4yrs to 8yrs

The Synopsys Information Security team is expanding and searching for an

Information Security Analyst (GRC) . The candidate will be an integral part of the Synopsys Corporate Information Security group. The Information Security Analyst will enable and transform the risk management program, enhance compliance and track enterprise security risks. The Information Security Analyst will leverage multiple industry frameworks and regulatory standards including, but not limited to, ISO 27001, SOC 2 Type II, NIST 800-53, NIST CSF, GDPR, TISAX, SOX, etc. This person will liaise with all business groups including Finance, Legal, Audit, HR and other stakeholders globally to implement new solutions and processes, as well as document and remediate outstanding issues. Does this sound like a good role for you?

The Ideal Candidate Will Possess These Skills: Bachelor’s degree in computer science, Information Systems, or related field required Typically requires 5 - 8years of experience in related field Knowledge of common certification and attestation programs such as ISO 27001, SOC2 Type II. Practical working experience with control frameworks such as ISO 27001, NIST 800-53, NIST CSF, etc. A passion about solving security challenges High personal and professional ethical standards A quantitative or analytical work/school experience Ability to demonstrate experience with governance, risk, and compliance tools Have a working understanding of security control frameworks such as ISO 27001, SOC 2 Type II, NIST 800-53, NIST CSF, and similar Ability to present security risks to wide audience including senior management Ability to communicate and work seamlessly in a global team Ability to understand the end to end processes supporting IT, data, and security. Provide guidance of control implementations related to governance frameworks, regulations, and corporate security policies Job Requirements: It is imperative that the Information Security Analyst possesses experienced knowledge of computer and network security methods and procedures. The Information Security Analyst will be responsible for security risk assessments of suppliers and partners external to Synopsys, assessments of systems within the organization, examine and rate risks, and recommend risk mitigation controls. Being that cyber-attacks and threats are a constant menace, the Information Security Analyst must have excellent analytical and critical-thinking abilities to be able to identify any potential vulnerabilities in an organization's existing network and address any attacks quickly while examining existing risk mitigation policies and communicate with the organization's Director of Information Security, on the efficacy of these measures. Key Responsibilities Work with stakeholders to conduct third party (vendor) risk assessments Assist with providing security requirements to both internal partners and external third-party providers Assist with the identification, documentation, monitoring, and reporting on risk register items, KPI/KRI, including the monitoring of security control efficacy. Understanding of security functions including Incident Management, Change Management, Identity and Access Management, and Vendor Security Risk Management. Work closely within the Synopsys Information Security Security Team to detect potential security weaknesses and developing creative ways to handle challenges unique to the Synopsys business and systems architecture. Interacts with Synopsys IT and business stakeholders to understand risks to critical infrastructure by defining potential business impact with the responsibility to apply effective mitigation strategies. Maintain, enforce, and track the Synopsys Information Security Exception process Must stay current with industry, regulatory, and legal requirements relevant to security, compliance, and privacy.

Please share your updated CV to rasha@synopsys.com

along with your current CTC & notice period or refer those who would like to explore this opportunity.

Inclusion and Diversity are important to us. Synopsys considers all applicants for employment without regard to race, color, religion, national origin, gender, gender identity, age, military veteran status, or disability.