Data Protect & InfoSec Compl Spec
Accenture in India · Bengaluru, Karnataka, India
Accenture in India · Bengaluru, Karnataka, India
**Must have skills:** - Should have a good understanding of information security risk management. - Application Security Risk Assessment - Security Control Evaluation - Good communication and collaboration skills. - Good knowledge of MS Office applications (Excel; Word; PowerPoint). - Self-motivated, team player who also works well independently. - Strong stakeholder management skill - Understand and work with a culturally diverse team. **Good to have skills:** - Security certificates such as CISA, CISSP. - Experience in application integration with Azure AD. - Should be open to flexible working hours to support global teams across time zones. **Experience:** Minimum 5-7 year(s) of experience is required **Educational Qualification:** Bachelor’s Degree in Engineering – B.Tech/ B.E in Computer Science, Information Technology. **Job Summary:** The role involves conducting V&A Security Assessments for retained applications post-acquisition (PMI), identifying applicable security controls, and collaborating with technical teams and global stakeholders to drive implementation. **Roles & Responsibilities:** - Review and assess application security controls for web, mobile (Android & iOS), and API-based applications coming through the Ventures & Acquisitions pipeline. - Evaluate security compliance of applications against Accenture policies and established industry standards (e.g., OWASP, NIST, ISO 27001). - Identify and document security control gaps and risks; recommend and track mitigation actions. - Collaborate with acquisition stakeholders, application owners, and internal security teams to support secure integration of acquired applications. - Contribute to continuous improvement of security assessment processes, templates, and standards. - Communicate technical security findings to both technical and non-technical stakeholders in a clear and actionable manner. **Professional & Technical Skills:** - Should have a good understanding of information security risk management. - Working knowledge in security frameworks like OWASP top 10, GDPR, ISO 27001, and SANS top 25 - Knowledge of common security attacks and threat vectors - Basic knowledge of web applications, audit and assessments, security frameworks - Good analytical skills.