Senior Associate - It Risk- Strategic Assurance And Soc Services
Overall Security and Privacy Compliance experience:• Experienced in performing SOC, ISO, PCI, and HIPPA compliance reviews.• Planned, organized, and executed SOC 1 and SOC 2 security risk assessments to enhance clients’ IT security control environments, including business continuity programs, incident response procedures, access management, encryption, threat monitoring, and more• Conducted walkthroughs to understand organizations’ processes and identify the products, services, and applications in scope for the trust principles – Security, Availability, Confidentiality, Integrity, and Privacy.• Led a team of professionals in the execution of cybersecurity risk advisory projects, ensuring the timely completion of high-quality deliverables• Collaborated with clients to understand their specific business processes, control objectives, and regulatory requirements and assisted them in complying with those requirements.• Responsible for end-to-end management of audits, including planning and executing tasks like budgeting, documenting PBCs, client interaction, complex walkthroughs, control testing, reviewing deliverables, creating reports, providing feedback, and ensuring adherence to the project plan.• Experienced in performing gap and readiness assessments.• Comprehensive understanding of the DevOps pipeline and its security requirements.• Sound knowledge and experience in assessing private and public cloud environments' compliance with security best practices and regulatory requirements• Comprehensive understanding of privacy regulations such as GDPR, CCPA and assessing compliance with these requirements.• Experience in assessing compliance with privacy requirements such as privacy by design, individual rights, incident management, reporting and consent management, and notice