Nutanix Jobs

Mobile nutanix Logo

Job Information

Nutanix Senior Security Governance, Risk, Compliance (GRC) Lead in Bangalore, India

Hungry, Humble, Honest, with Heart.

The Opportunity

Reporting to the Director Information Security, Governance, Risk, and Compliance, the Senior GRC Lead will contribute to the development and operational execution of the program, including risk management and compliance with standards and regulations such as ISO27001 and EU GDPR.

Information Technology at Nutanix

Your Role

· Support the GRC operating model and the service-oriented customer engagement model.

· Provide Cybersecurity Risk Management leadership and operational delivery of the program.

· Support GRC capabilities, such as compliance and audit management, policy management, security awareness training, third party risk management, and metrics and reporting.

· Assist to manage security compliance programs and activities that support various compliance regulations.

· Perform risk assessments to address security threats, changes to systems and/or applications, process improvement initiatives, supplier assessments (including downstream outsourcers) and other requests from the business.

· Collaborate with various operational and business teams to complete assessments, develop treatment plans, and drive remediation items to closure. Maintain accurate reporting of remediation activities to bring appropriate visibility to stakeholders and leadership.

· Monitor the security risk profiles and events of our suppliers to objectively determine high risk suppliers that require additional review and treatment plans.

. Establish and maintain security metrics and reporting.

·Respond to customer security/compliance questionnaires.

· Act as security risk management “ambassador” to internal customers.

What You Will Bring

· Candidates must have at least 7 years working in governance, risk and compliance and/or information security and risk management, and at least 5 in risk management.

· Functional knowledge of the CISSP security domains and information security industry standard and best practices.

· Functional knowledge of applicable security regulatory and compliance requirements (SOX, GDPR). Functional knowledge of ISMS governance models and analysis of certification reports (i.e. ISO 27001, SOC, CAIQ), information security roles, security controls.

· Ability to communicate risk methodologies and concepts to business units and IT teams.

· Demonstrated experience with controls definition, development, implementation and assessment.

· Strong interpersonal skills and ability to work effectively with diverse and globally distributed teams.

· Strong attention to detail, project management and organizational skills.

· Self-starter with the ability to effectively manage independent workloads asynchronously with stakeholders across multiple time zones.

· Ability to independently lead program areas and cross-functional teams to deliver high quality results according to well-defined planning.

· Define and communicate program and activity plans and roadmaps, and effectively collaborate with all business and IT groups to achieve goals.

· The use of defined risk methodologies and best practices to perform IT/Security assessments. Responsible for the planning, scoping, tracking, and execution of these assessments.

· Driving remediation activities from identification, treatment plan, remediation, and closure. Hold owners accountable to delivery of remediation solution within the agreed upon/reasonable SLA.

· Operations and improvements of security audit and compliance programs to support various compliance regulations.

· Operationalization of a metrics and reporting function to continually report on meaningful security, risk and compliance metrics for operational and executive management. Support the automation of KRIs and KPI reporting that align with operational/business risk areas and corporate risk.

About the Team

Meet the Hiring Manager

Daniel Pekol- Director, Information Security, Governance, Risk & Compliance

Previous professional role highlights

  • Systems and Security Engineering

  • Information Security Officer

  • GRC Director

Looking for

Hoping to find a seasoned and senior security risk lead, who can work independently and communicate well. Must be able to determine necessary direction, align stakeholders, communicate to keep everyone informed. Adapt to the changing business environment and adjust to keep everything on track

You can see my memberships on LinkedIn.

https://www.linkedin.com/in/dpekol/

We're an Equal Opportunity Employer Nutanix is an Equal Employment Opportunity and (in the U.S.) an Affirmative Action employer. Qualified applicants are considered for employment opportunities without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, marital status, protected veteran status, disability status or any other category protected by applicable law. We hire and promote individuals solely on the basis of qualifications for the job to be filled. We strive to foster an inclusive working environment that enables all our Nutants to be themselves and to do great work in a safe and welcoming environment, free of unlawful discrimination, intimidation or harassment. As part of this commitment, we will ensure that persons with disabilities are provided reasonable accommodations. If you need a reasonable accommodation, please let us know by contacting CandidateAccommodationRequests@nutanix.com.

DirectEmployers