Job Summary
Serve as a GRC Specialist with deep experience in cloud native security risk and compliance to strengthen enterprise controls and protect critical data assets in a hybrid work setting. Apply expertise in GCP native security vulnerability and compliance management vendor risk oversight and ServiceNow GRC to embed governance into daily operations while enabling secure innovation for global stakeholders.
Responsibilities
- Should have information security background 3 - 5 years.
- Capable of understanding and assessing gaps based on frameworks such as NIST CIS etc.
- Able to support during EST/PST hours for collaboration.
- Should be comfortable drafting presentations and co-ordinate with key stakeholders.
- Willing to learn and deliver on the job
Scope and Key Deliverables
Deployment 1 CJ 2.1 Existing Applications
1. Check the Survey questionnaire.
2. Gap Assessment for v2.1 controls.
3. Pre-population of control questionnaire with answers from Survey Questionnaire.
4. Send pre-populated control questionnaire to SMs for re-certification.
5. Identify Gaps & Remediation.
6. Raise Exception or Submit evidence for remediation to close the gap.
7. Pending CJ 2.0 tasks.
8. Get approvals for exceptions in progress.
9. Track status of controls for approved exceptions.
Deployment 2 CJ 2.1 New applications
1. Document the process for onboarding new applications into CJ 2.1.
2. Revalidation of existing CJ data and Tier.
3. Identification of new CJ data and Tier.
4. CJ Applicability Assessment.
5. Perform CJ applicability assessment for each application.
6. Identify new applications from New Entities for onboarding into CJ 2.1.
7. Identify new applications from existing entities for onboarding into CJ 2.1.
8. Get inventory of Applications to be scoped for CJ 2.1.
Deployment 3 CJ 2.1 Metrics & Dashboards
1. Produce data for generating the Reports Metrics & Dashboards.
Qualifications
- Demonstrate seven to nine years of specialized experience in governance risk and compliance functions with significant exposure to enterprise scale technology environments.
- Apply strong hands on expertise in GCP native security capabilities such as identity management logging configuration assessment and data protection to secure cloud workloads.
- Use solid background in vulnerability management tools practices and coordination to ensure timely identification prioritization and remediation of technical weaknesses.
- Bring proven experience in compliance management by interpreting regulatory frameworks and industry standards and translating them into practical control activities for technology teams.
- Show practical knowledge of vendor risk management by evaluating third party security controls contracts and attestations to protect information shared with external partners.
- Utilize experience with ServiceNow GRC configuration workflows and reporting to build structured governance processes that reduce manual effort and improve traceability.
- Apply incident management experience in assessing security and compliance events coordinating with responders documenting actions and supporting continuous improvement initiatives.
What we offer
- The chance to work with impact. Here, you’re empowered to bring your biggest thinking to help our company and clients improve everyday life.
- Ownership over your career. Stay at the top of your game through our award-winning learning and development ecosystem. And when your ambitions change or we offer new opportunities, we help you pivot by providing reskilling, on-the-job learning and guidance to find new roles that might be a better fit.
- The opportunity to thrive on a high caliber team with heart. We celebrate each other’s experiences and perspectives and promote a sense of belonging through our affinity groups and diversity and inclusion initiatives.
- A comprehensive total rewards package, including a competitive salary and a pension plan with matching contributions.
- Flexible health and financial benefits to support you and your eligible dependents—from day one.
- True work-life balance. Be at your best through paid time off, flexible work arrangements, volunteering opportunities, social events, and so much more.
About us
Cognizant (Nasdaq: CTSH) is an AI Builder and technology services provider, building the bridge between AI investment and enterprise value by building full-stack AI solutions for our clients. Our deep industry, process and engineering expertise enables us to build an organization’s unique context into technology systems that amplify human potential, realize tangible returns and keep global enterprises ahead in a fast-changing world. See how at www.cognizant.com or @cognizant.
Other employment-related information
Cognizant is an equal opportunity employer. Your application and candidacy will not be considered based on race, color, sex, religion, creed, sexual orientation, gender identity, national origin, disability, genetic information, pregnancy, veteran status or any other characteristic protected by federal, provincial or local laws.
If you have a disability that requires reasonable accommodation to search for a job opening or submit an application, please email [email protected] with your request and contact information.
Language requirements vary depending on roles, but we ask that all candidates have basic English proficiency for company-wide communications purposes. For roles based in Quebec, professional English proficiency is required, as you’ll deliver services to and collaborate with stakeholders outside the province who may not speak French.










