Information Security Auditor ensuring Nextiva’s compliance with global security and privacy regulations. Collaborating with teams to monitor compliance and lead audits effectively.
Responsibilities
Assess compliance of the organization to industry standards, security frameworks, and privacy regulations.
Review and update security and privacy policies and procedures to ensure consistency with new and evolving requirements.
Plan and conduct internal audits of the design and effectiveness of the organization’s security and privacy controls, policies, processes and procedures.
Document audit findings, identify and report gaps and risks in controls, and lead remediation efforts.
Support external audits by working with the auditor and internal asset, process, and control owners to gather and submit evidence for compliance.
Keep up to date with changes in security frameworks, regulatory changes, and commercial requirements that affect the organization’s compliance, including all countries where Nextiva provides, or intends to provide, service.
Work with product development teams, infrastructure, and other parts of the organization to define policies and procedures, implement remediation plans, and monitor compliance.
Effectively use available AI tools to plan and conduct audits, develop policies and procedures, and document audits.
Perform other duties to support the security and compliance of the organization as required.
Comply with organization information security policies.
Requirements
Bachelor’s degree in an IT related field or equivalent experience and 4-6 years of experience in working in IT security, software development, or IT or information security audit.
Strong knowledge of IT infrastructure and networking, including data center infrastructure, cloud infrastructure (GCP and AWS), IP networking, firewalls, IDS/IPS and endpoint security tools, backup and recovery, identity and access management, application security, and SIEM tools.
Understanding of security and privacy frameworks and regulations, including SOC 2, ISO-27001, UK Cyber Essentials, NIST, NIS2, HITRUST, PCI-DSS, HIPAA, GDPR, and CPRA.
Desired certifications – one or more of the following: CISSP (Certified Information Systems Security Professional), Certified Information Security Manager (CISM), SSCP (Systems Security Certified Practitioner), CCSP (Certified Cloud Security Professional) or CompTIA Security+.
Flexibility to work extended hours and off-hours to support global project teams.
Benefits
Medical - Medical insurance coverage is available for employees, their spouse, and up to two dependent children with a limit of 500,000 INR, as well as their parents or in-laws for up to 300,000 INR.
Group Term & Group Personal Accident Insurance - Provides insurance coverage against the risk of death / injury during the policy period sustained due to an accident caused by violent, visible & external means.
Work-Life Balance - 15 days of Privilege leaves per calendar year, 6 days of Paid Sick leave per calendar year, 6 days of Casual leave per calendar year. Paid 26 weeks of Maternity leaves, 1 week of Paternity leave, a day off on your Birthday, and paid holidays.
Financial Security - Provident Fund & Gratuity.
Wellness - Employee Assistance Program and comprehensive wellness initiatives.
Growth - Access to ongoing learning and development opportunities and career advancement.
Security Manager responsible for operational security and compliance at DSV. Collaborating with law enforcement and ensuring safety in Swedish transport operations.
Coordination of Physical Security for Sicredi's Monitoring Operations, managing teams and overseeing operational procedures. Focused on electronic security and risk management for assets and personnel.
Senior Security Architect at KUBRA designing and implementing security solutions across cloud environments. Overseeing security in application and database platforms with a focus on AWS.
Internship in food safety and quality support at Nestlé in Dieppe, France. Responsibilities include developing quality standards and supporting quality culture initiatives.
Safety, Physical Security & Data Protection Officer structuring safety policies in a multi - site environment at Eviden. Focused on data protection and compliance in France.
Security Analyst responsible for safeguarding digital and physical environments using data - driven security practices. Collaborate on security initiatives to ensure integrity at testing centres and platforms.
Chief Information Security Officer leading governance and oversight of information security at Nokia Defense. Responsible for protecting classified information and ensuring compliance with defense authority requirements.
Chief Information Security Officer leading the cybersecurity strategy at Sabyk for engineering and active defense. Overseeing security architecture and incident management with a focus on compliance.
Product Specialist BDE responsible for advising on Networks and Cybersecurity at Datacom. Supporting development of product strategies and sales ideas to drive customer success.