Expert Governance Analyst, India – Cis Icc
Country : India
Region : Karnataka
Town : Bengaluru
Category : Retail
Contract type : Permanent
Availability : Full time
You must be passionate about GRC, as you'll need a good working knowledge of industry best practice frameworks, such as ISO, NIST and CoBIT. You will regularly meet with business and technology teams across Nike to consult with them on their security and compliance requirements. You will work cross-functionally within the Corporate Information Security (CIS) teams and across Nike.
To make it clear, we're not looking for just anyone. We're looking for someone special, someone who has clearly demonstrated skills and experience, since your responsibilities will include, but not be limited to:
* Help ensure that audit findings have appropriate remediation, key processes are designed and operating effectively, and effective handoffs exist between CIS functions. Provide expert-level process consulting and evaluation with recommendations for improvements to drive maturity in key functional areas.
* Drive Nike's compliance control validation testing program by developing testing procedures, being accountable for deliverables, allocating work to team members, and driving remediation of control gaps.
* Perform detailed analysis of threats and vulnerabilities in all areas of information security including network security, asset security, security engineering, identity and access management, security operations and software development security. This also includes reviewing key system configurations and complex IT infrastructures (e.g. cloud services).
* Utilize your thorough understanding of ITGC's to consult with and lead Technology units on compliance matters.
* Champion information security policies, standards, controls, and processes so that compliance requirements are addressed as part of "business as usual" operations.
* Help lead overall Nike control design and control operations related in support of compliance requirements.
* Assess current platforms against Nike security and configuration standards.
* Evaluate and process exceptions to information security policies and standards.
* Provide analysis and insights into data supporting the effectiveness of technical and process-based cyber security controls and establish automated data pipelines that feed data visualization tools, such as Tableau.
* Collaborate effectively with NIKE leaders, managers, employees, and partners to provide deliberate and thoughtful engagement throughout NIKE.
* Effective, positive verbal and written communication skills and experienced creating and developing high-quality PowerPoint presentations.
To make it clear, we're not looking for just anyone. We're looking for someone special, someone who had these experiences and clearly demonstrated these skills:
* Knowledge of information security principles and practices, general procedures and guidelines.
* A general understanding of technology use, trends and risks as it applies in a business context and environment.
* Experience reviewing third party SOC reports.
* Experience/working knowledge with PCI DSS (Former QSA is a benefit).
* Knowledge of information security principles, frameworks, and best practices (e.g., PCI DSS, COBIT, COSO, NIST and ISO 27000).
* Excellent collaboration skills - must be eager to work as part of a cohesive team and work as a partner to others within Nike, Inc. both at WHQ and globally.
* Experience with ServiceNow, Confluence or JIRA.