Client Security Manager - Bengaluru, India - Atos

    Atos
    atos background
    Description
    Experience -10+yrsLocation-Bangalore/Chennai/Pune/Mumbai

    Tools & skills- Vulnerability management, ISO 27001 clauses & controls,Anti Virus/Patching, Security Tools, Risk Management, IPS/IDE firewall, Data protection, Penetration testing, Security Baselines, Access Management, Physical and environmental security controls, Certification : CISM , CISSP ,Information Security frameworks

    Location- Chennai/Bangalore/Pune


    The CSM is a consulting and coordination role within the Client Security Management service, which is responsible for the delivery of the customer security related contractually agreed upon requirements.

    To this end the CSM supports the Account Service Team, providing leadership for Information Security, Governance, Risk and Compliance (incl. assurance) in adherence to both regulatory and contractual requirements.

    A customer facing role – maintaining oversight of all Information Security and Compliance Related activities as the first point of contact.

    Work with the Client and the Client Delivery Executive/Client Executive Partner to gain understanding of the contract in business context/priorities of the account.

    Lead meeting directly with Client as part of ongoing contractual relationshipHas sufficient technical overview and knowledge to understand the importance of Information Security.

    Contributes as an expert to consult operational teams.

    Coordination of information and creation of the monthly Security & Compliance report for all Atos services to demonstrate compliance over security obligations.

    Continuously monitor the effectiveness of controls and initiate and prioritise improvement actions.
    Ensure that the critical operating controls are successfully implemented throughout the contract lifecycle.

    Member of the Account Service Team, CSM is the single interface to the account and customer for security governance and compliance, wherever the services are run (onshore & offshore).Proactively analyse the risk of threats within the managed estate.

    Inform Clients on new rules and regulations such as GDPR and what Atos could do for themRecipient of a threat report leading to assessment of potential zero-day vulnerabilities on operations, which present significant risk and warrant risk mitigation/appropriate actions/priority.

    Demonstrates an understanding of operational risk issues of interest to Atos service. Raise awareness via risk register for risk treatment within the scope of own expertise. Approve and reject risks as appropriate.
    Is able to drive and lead incident applying knowledge, skills, and experience.

    Formal communication with the external client regarding security incidents aligned with Account Service TeamIs able to drive and lead assignments or projects or resources in support of proactive internal escalation or reactively to any external escalation applying knowledge, skills, and experience.

    Is able to drive and lead service improvement initiative in support of increased customer satisfactionInitiation of the creation of a yearly audit plan together with the client.

    Coordinate Audit Plan for Atos entities delivering service to CustomerCreation of an audit findings overview (incl. improvement plans)Creating, advising, or validating the solution part of limited upselling proposal.

    Skillset:
    Certification: CISSP, CISM, ISO 27001 Lead Auditor, , PCI DSS QSA (Preferrable)

    Knowledge of Standards & compliance framework:

    HIPAA/ISO/PCI DSS/GDPR/SOC 1 & SOC 2/FDA compliance/GxP /NIST othersHave analytical skills and attentive to detailsSound judgment and assertivenessStrong relationship building and interpersonal skills / Work as part of a teamGood organizational skillsGood communication skills / Excellent oral and written communication skillsGood Presentation SkillsExperience interacting with all levels of managementAbility to work independently and take decisions where necessary.

    Successful delivery against commitments and deadlines