跳到主要內容

GRC Architect

00070266861

Job Summary

We need urgently one GRC person who is good at documentation and is knowledgeable about controls needed for regulations. Perfect match would be someone who knows NIS 2 especially ENISA controls. If not we can consider NIST CSF or 800-53.


Responsibilities

  • Design and maintain an integrated governance risk and compliance framework that aligns PCI DSS GDPR and CCPA obligations with organizational policies and control objectives to support sustainable business growth
  • Develop comprehensive compliance management strategies and roadmaps that translate regulatory requirements into practical control designs tailored to work from home environments and rotational shift operations
  • Conduct detailed assessments of existing processes and systems to identify compliance gaps related to PCI DSS GDPR and CCPA and recommend remediation actions that strengthen organizational resilience
  • Create standardized methodologies for risk identification risk prioritization and risk treatment that embed data protection and payment card security into everyday business activities
  • Coordinate cross functional compliance initiatives by defining clear objectives deliverables and timelines that help teams understand their responsibilities and achieve consistent regulatory adherence
  • Implement monitoring mechanisms and compliance dashboards that provide management with transparent visibility into control effectiveness incident trends and regulatory obligations across geographies
  • Guide project teams on embedding privacy by design and security by design principles into technology solutions ensuring that customer data and payment information remain protected throughout the lifecycle
  • Prepare and refine policies standards and procedures for data handling access management logging and incident response that reflect PCI DSS GDPR and CCPA requirements and support remote work practices
  • Collaborate with audit and assurance functions to plan and support internal and external assessments ensuring evidence is well organized findings are accurately documented and remediation is tracked
  • Provide structured training and awareness content for employees working remotely and in rotational shifts so they understand compliance expectations practical behaviors and the impact of nonconformance
  • Evaluate new tools platforms and automation opportunities that improve compliance management activities such as control testing documentation retention and regulatory reporting while reducing manual overhead
  • Analyze incidents deviations and near misses to determine root causes and recommend targeted improvements that reduce the likelihood of recurrence and improve overall governance maturity
  • Document architecture decisions data flows and control mappings in a clear manner so stakeholders can trace how regulatory requirements are implemented and verify that risk is appropriately managed


Qualifications

  • Possess extensive hands on experience in compliance management frameworks with demonstrated ability to interpret complex regulatory requirements and convert them into actionable control designs
  • Bring deep expertise in PCI DSS domains including network security access control logging vulnerability management and cardholder data protection applied within large scale enterprise environments
  • Demonstrate strong knowledge of GDPR principles such as lawfulness fairness transparency data minimization purpose limitation and data subject rights with proven experience implementing compliant solutions
  • Show practical experience applying CCPA requirements including consumer rights disclosure obligations data sale restrictions and opt out mechanisms within business processes and technical architectures
  • Apply advanced understanding of governance and compliance methodologies to design policies standards and procedures that are pragmatic easy to adopt and aligned with organizational risk appetite
  • Utilize excellent analytical and problem solving skills to assess complex environments balance regulatory expectations with business needs and propose clear prioritized remediation actions
  • Communicate clearly with technical and nontechnical stakeholders to explain regulatory impacts control choices and risk implications in a concise actionable manner that encourages informed decisions

关于高知特 (Cognizant)
高知特(Cognizant)(纳斯达克代码:CTSH)作为一家AI Builder和相关技术服务提供商,致力于通过打造全栈AI解决方案,帮助企业将人工智能投资转化为实际价值。公司凭借深厚的行业经验、流程优化和工程技术专长,将企业独特的业务场景融入科技系统,赋能组织释放人才潜能,推动切实成果,并帮助全球企业在瞬息万变的环境中保持领先。如需了解更多详情,敬请访问 cognizant.ai 或关注@cognizant。

补充雇佣信息
薪酬信息截至本职位发布之日为准。Cognizant 保留在适用法律允许的范围内随时修改该信息的权利。
申请人可能需要通过现场面试或视频会议的方式参加面试。此外,候选人在每次面试时可能需要出示其当前所在州或政府签发的有效身份证件。
Cognizant 是一家提供平等就业机会的雇主。在招聘过程中,您的申请和候选资格不会因种族、肤色、性别、宗教、信仰、性取向、性别认同、国籍、残疾、遗传信息、怀孕、退伍军人身份或任何其他受联邦、州或地方法律保护的特征而受到影响。

帮助您蓬勃发展与成长的福利

我们的福利计划以您为中心打造——帮助您享受充实、平衡且健康的生活。
有葉子的植物的藍色線條圖

财务健康

我们会定期审查市场数据,确保薪酬体现您所带来的价值。您的福利不仅限于薪资,还可能包括退休计划、财务教育等。

Stay Healthy Midnight Blue RGB

身心健康

我们通过带薪休假、在条件允许下的灵活工作安排、医疗保障计划、心理咨询、心理健康盟友计划等,赋能您将身心健康放在首位。

Build The Career You Want Midnight Blue RGB

您的职业发展,由您做主

在 Cognizant 提供的 35 万多个岗位中,您将有机会探索新的技术、行业和工作地点,并打造推动职业发展的关键技能。

Making A Meaningful Impact Midnight Blue RGB

现实世界的影响力

想想您所依赖的那些知名品牌。很可能,他们也依赖我们来帮助强化其业务。在这里,您将把大胆的想法转化为改善全球生活的解决方案。

还没有找到合适的机会吗?

获取为您量身定制的最新职位机会、招聘活动和公司新闻!

掌握最新动态