What S&P Global Has to Offer:
Senior Lead Information Security Architect
Onsite
Hyderabad, India
Hyderabad, India
Posted 28 days ago
Job Details
About the Role: Grade Level (for internal use):11 About the Role: Cyber Security Risk Engineer The Team: Part of the Global Security Architecture team that is responsible for Security Consulting, Security Assessments and Measurement, Security Exceptions Management, New Security Technology Evaluation and Acquisitions and Divestitures. The Team is based in New York, Princeton, London, Hyderabad, Beijing and Shanghai. Responsibilities and Impact: The Security Risk Measurement analyst will interact extensively with internal technology and business clients in order to review, assess and report on the maturity of the security controls of current and proposed solutions within S&P Global. The position is critical as the business is very dynamic and constantly evolving to Power the Markets of the Future.
- Part of a team that enforces corporate, regulatory and risk management policy configurations. The position also assists in developing, implementing and maintaining corporate information security standards, technologies, processes and procedures.
- Reviews and provides guidance on the controls relating to all S&P Global current and future solutions.
- The role holder will look to ensure that the business adheres with expected minimum requirements and operates within agreed risk appetites for information, data and cyber security and ongoing assurance.
- The role holder will be expected to understand areas of concern and in conjunction with stakeholders provide advice and guidance, recommendations and mitigations where required.
- Serves as a subject matter expert for colleagues and line-of-business managers, and experience with multiple technologies, compliance requirements and risk analysis methodologies is crucial.
- Improve efficiencies using automation and orchestration solutions to reduce manual work that can be done programmatically.
- Influence tactical and strategic decisions.
- Identify process efficiencies through analysis and metrics driven decision making
- Responsible for the creation of guidance, security documentation and configuration practices.
- Ensure systems are protected against threats through the deployment of Security controls.
- Ensure guidance and assessment provides is aligned to regulatory and compliance requirement and local laws.
- Administer best practices and required configuration standards for compliance and privacy law obligations.
- Remain current with new security threats and assessing systems to ensure they can defend the business.
- Provide metrics and other management information to leadership to ensure decision making is sound.
- Perform other duties as assigned.
- At least 5-7+ years’ experience in cybersecurity, including compliance and risk management with a system and network security engineering background.
- Highly technical and analytical expertise, with a proven deep background in technology design, implementation and delivery.
- Experience of aligning to a NIST controls framework. Familiarity with the concepts of Security Control Frameworks
- Experience in cloud computing technologies, including software-, infrastructure- and platform-as-a-service, as well as public, private and hybrid environments.
- Extensive knowledge of traditional security controls and technologies, such as SIEM systems, IDS/IPS, public key infrastructure (PKI), IDAM systems, antivirus and firewalls, in addition to newer offerings such as endpoint detection and response (EDR), threat intelligence platforms, security automation and orchestration, deception technologies and application controls.
- Experience driving measurable improvement in monitoring and response capabilities at scale.
- Track record of acting with integrity, taking pride in work, seeking to excel, being curious and adaptable, and communicating effectively.
- Experience of information security and Data protection practices in financial services.
- Experience of working within cyber security and information security teams within an international business of scale and complexity
- Bachelor’s degree in computer science, information assurance, MIS or related field, or equivalent.
- Experience with Amazon Web Services (AWS) or Microsoft Azure.
- Experience with one or more of the following: ISO 27001, NIST, Payment Card Industry Data Security Standard (PCI DSS), Health Information Portability and Accountability Act (HIPAA), Health Information Technology for Economic and Clinical Health (HITECH) Act, Sarbanes-Oxley Act (SOX) the General Data Protection Regulation (GDPR), Center for Internet Security (CIS) standards or Service Organization Controls (SOC) 2.
- Working knowledge of Windows, Linux and Unix.
- Highly trustworthy; leads by example.
- Health & Wellness: Health care coverage designed for the mind and body.
- Flexible Downtime: Generous time off helps keep you energized for your time on.
- Continuous Learning: Access a wealth of resources to grow your career and learn valuable new skills.
- Invest in Your Future: Secure your financial future through competitive pay, retirement planning, a continuing education program with a company-matched student loan contribution, and financial wellness programs.
- Family Friendly Perks: It’s not just about you. S&P Global has perks for your partners and little ones, too, with some best-in class benefits for families.
- Beyond the Basics: From retail discounts to referral incentive awards—small perks can make a big difference.
Learn more about S&P Global
Help us maintain the quality of jobs posted on PowerToFly. Let us know if this job is closed.
Mission
We're connecting diverse talent to big career moves. Meeting people who boost your career is hard - yet networking is key to growth and economic empowerment. We’re here to support you - within your current workplace or somewhere new. Upskill, join daily virtual events, apply to roles (it’s free!).
Are you hiring? Join our platform for diversifiying your team