Manager - ARM
HCLTech · Noida, Uttar Pradesh, India
HCLTech · Noida, Uttar Pradesh, India
**Role & responsibilities** - Manage end-to-end **Compliance, Information Security, and Customer Data Protection programs** in an outsourcing environment. - Conduct **risk assessments**, compliance audits, and gap analyses to identify vulnerabilities and recommend remediation. - Lead development and enforcement of **Risk & Compliance programs, procedures, and standards**. - Engage with business leadership through regular governance meetings to provide risk insights and ensure remediation plans are agreed upon. - Coordinate with support functions (IT, Physical Security, HR, etc.) for risk mitigation. - Maintain risk registers and R&C calendars for engagements. - Review and improve security and compliance control frameworks. - Ensure adherence to regulatory and contractual requirements (e.g., **ISO 27001, SOC2, SOX, NIST, PCI-DSS, HIPAA**). **Preferred candidate profile** - Extensive experience in **risk management, compliance monitoring, and auditing** within IT outsourcing/service delivery. - Strong knowledge of **control frameworks** for IT and non-IT domains. - Hands-on experience with compliance programs such as **ISO 27001, SOC2, SOX, NIST, PCI-DSS, HIPAA**. - Proven ability to lead small teams and manage cross-functional stakeholders. - Excellent communication and analytical skills. **Qualifications** - 10+ relevant years of experience in **Information Risk Management / Information Security** - Certifications: **CISA, CISSP, CISM, CRISC, ISO 27001** - Strong communication, analytical, and leadership skills