Job Description
Key responsibilities -
Daily:
- Physical security checks and floor walks to ensure compliance with physical security requirements.
- Recording exceptions in the system (e.g., unattended workstations, left IDs, manual circumvention of desktop controls like placing a mouse upside down to prevent timeout, decorations covering CCTV, safety reviews such as maintenance checks for fire hoses, fire extinguishers, pest control, health and safety insurances, maintenance of emergency exit doors, etc.)
Weekly:
- Attend security calls with business and vendor teams to discuss new issues and updates on open issues.
Monthly:
- Background check reviews for a sample of new hires to ensure contract compliance on vetting.
- Compliance logs/reports reviews, including various reports (e.g., inventory, AV scanning, vulnerability scanning, visitor logs, equipment transportation, etc.)
- Workstation reviews for a sample of 4 workstations to ensure compliance with acceptable workstation image (e.g., data exfiltration, USB controls, inability to copy-paste, etc.)
Annual (conducted twice yearly):
- Full contract compliance review and security framework review.
- Checking of local regulatory licenses (e.g., health and safety inspection, PEZA license).
Admin:
- Logging reviews in ServiceNow.
- Updating site visitors (e.g., visits from Verizon BO in the US).
- Providing logistics updates (e.g., headcount of vendor personnel).
Adhoc:
- Conducting site assessments for new vendor sites before approval.
- Managing site sanitization for decommissioning.
- Assisting in risk exceptions (usually assigned to tenured members).
- Conducting new reviews aligned with InfoSec requirements, including minimum cybersecurity requirements (similar to TPRM assessment but limited to vendor sites). Domains include access management, network security, HR security (background checks, awareness training), logging and monitoring, incident management, configuration management, media protection, vulnerability, and patch management.
͏
Deliver
No. | Performance Parameter | Measure |
1. | Adherence to established risk and compliance framework | % deviation from audit, release audit scores, closure on audit points, cyber health of the organization, audit timelines |
2. | Disaster recovery | Number of risks identified and mitigated, Timely communication to the client |
͏
͏
Experience: 5-8 Years .
Reinvent your world. We are building a modern Wipro. We are an end-to-end digital transformation partner with the boldest ambitions. To realize them, we need people inspired by reinvention. Of yourself, your career, and your skills. We want to see the constant evolution of our business and our industry. It has always been in our DNA - as the world around us changes, so do we. Join a business powered by purpose and a place that empowers you to design your own reinvention. Come to Wipro. Realize your ambitions. Applications from people with disabilities are explicitly welcome.