Risk, Compliance & Information Security Executive
Core
Ensure software products are secure and compliant with regulations by managing penetration testing, vulnerability assessments, and certification processes.
Role type
Senior IC application security executive (compliance & risk)
Builds
Secure and compliant software products for e-commerce clients
Domain
E-commerce, Information Security, Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
PCI DSS framework expertise, ISO 27001 framework expertise, vulnerability scanning (Nessus, Qualys), SIEM platforms, GRC systems, risk assessment, audit preparation, documentation, analytical skills
Preferred skills
Secure software development practices, penetration test remediation follow-up, OSCP, CEH, ISO 27001 Lead Auditor, CISA
Technologies
Nessus, Qualys, SIEM, GRC tools
Responsibilities
Manage PCI DSS and ISO 27001 compliance and certification processes, Analyze security vulnerabilities and propose controls, Plan and coordinate penetration tests, Perform regular vulnerability assessments, Conduct risk assessments and prepare corrective action plans, Use SIEM and GRC tools for monitoring and reporting, Prepare for audits and manage documentation
Seniority
Senior, hands-on IC