Cybersecurity Risk and Compliance Engineer
Hewlett Packard Enterprise · Bengaluru, Karnataka, India
Hewlett Packard Enterprise · Bengaluru, Karnataka, India
This role has been designed as 'Hybrid' with a requirement that you will work on average 2 days per week from an HPE office. **Who We Are** Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever they live, from edge to cloud, so they can turn insights into outcomes at the speed required to thrive in today’s complex world. Our culture thrives on finding new and better ways to accelerate what’s next. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good. If you are looking to stretch and grow your career our culture will embrace you. Open up opportunities with HPE. **Job Description** Within HPE, our **Operations, Legal and Admin teams** work across the business, providing visible accountability and measurable outcomes. With a variety of roles and responsibilities these teams really connect the dots, giving us the essential insights, support and capability to accelerate our transformation to be the world’s edge to cloud company. Join us redefine what’s next for you. **Job Family Definition** Identifies, tracks, monitors, and manages cybersecurity risks within our supply chain. Evaluates and guides vendors, third parties and supply chain teams in the development and implementation of controls to address systems vulnerabilities. Researches threat intelligence, vulnerabilities, campaigns and indicators of compromise. Define cybersecurity requirements and performs annual vendor audits to assess and ensure controls are in place. **Management Level Definition** Applies developed subject matter knowledge to solve common and complex business issues and recommends appropriate alternatives. Works on problems of diverse complexity and scope. May act as a team or project leader providing direction to team activities and facilitates information validation and team decision making process. Exercises independent judgment to identify and select a solution. Ability to handle most unique situations. May seek advice in order to make decisions on complex business issues. **What You’ll Do** ***Responsibilities:*** - Manages and proactively monitors Third Party Risk Management and supply chain cybersecurity system issues and threats. - Develop cybersecurity audit assessments, scopes and content with accuracy and timeliness. - Coordinates and perform cybersecurity audit activities, third party assessments, assess controls in place, document and communicate findings. - Evaluate risks and controls in place to determine priorities and provide recommendations on mitigation strategies. - Ensure compliance with company cybersecurity standards, policies and government regulations - Create detailed cybersecurity reports with findings and gaps. Monitor actions to address findings until closure. - Combines industry expertise with a thorough understanding of information and security technology to direct vendor design of software patches. - Recommends and coordinates the development, enhancement, organization, and maintenance of a client's or company's security solutions, including research and security system analysis. - Evaluates internal systems, define or update supply chain cybersecurity standards, policies and processes. - Developing and tracking Third Party Assessments and audit related Plan & Milestones and associated performance metrics **What You Need To Bring** ***Education and Experience Required:*** - Bachelors degree required, preferably in computer science, engineering or related area of study - Typically 4+ years of relevant experience - Certifications: Preferred CISA or CISSP or other cybersecurity and risk related certification **Knowledge And Skills** - Ease to communicate at all levels, including management level presentations and summaries. - Advanced Cyber and IT security knowledge - Advanced understanding of Cyber and IT security risks, threats and prevention measures - Understanding of SQL and relevant scripting languages - Advanced security system analysis skills - Advanced understanding of security standards and best practices - Advanced risk assessment and management skills - Advanced understanding of networking and network security - Advanced understanding of network monitoring and protocols - Knowledge of relevant .Net development, programming and scripting languages - Advance experience in writing technical reports that analyze and interpret results. - Experience in Third Party Assessments (SaaS, IaaS, On Premises, Contractors, etc.) - Understanding of relevant industry security standards and protocols including, NIST, ISO, SOC2 Type II, etc. - Travel required. **What We Can Offer You** **Health & Wellbeing** We strive to provide our team members and their loved ones with a comprehensive suite of benefits that supports their physical, financial and emotional wellbeing. **Personal & Professional Development** We also invest in your career because the better you are, the better we all are. We have specific programs catered to helping you reach any career goals you have — whether you want to become a knowledge expert in your field or apply your skills to another division. **Unconditional Inclusion** We are unconditionally inclusive in the way we work and celebrate individual uniqueness. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good. **Let's Stay Connected** Follow @HPECareers on Instagram to see the latest on people, culture and tech at HPE. #india **Job** Information Technology **Job Level** Specialist HPE is an Equal Employment Opportunity/ Veterans/Disabled/LGBT employer. We do not discriminate on the basis of race, gender, or any other