Job Summary
We need urgently one GRC person who is good at documentation and is knowledgeable about controls needed for regulations. Perfect match would be someone who knows NIS 2 especially ENISA controls. If not we can consider NIST CSF or 800-53.
Responsibilities
- Design and maintain an integrated governance risk and compliance framework that aligns PCI DSS GDPR and CCPA obligations with organizational policies and control objectives to support sustainable business growth
- Develop comprehensive compliance management strategies and roadmaps that translate regulatory requirements into practical control designs tailored to work from home environments and rotational shift operations
- Conduct detailed assessments of existing processes and systems to identify compliance gaps related to PCI DSS GDPR and CCPA and recommend remediation actions that strengthen organizational resilience
- Create standardized methodologies for risk identification risk prioritization and risk treatment that embed data protection and payment card security into everyday business activities
- Coordinate cross functional compliance initiatives by defining clear objectives deliverables and timelines that help teams understand their responsibilities and achieve consistent regulatory adherence
- Implement monitoring mechanisms and compliance dashboards that provide management with transparent visibility into control effectiveness incident trends and regulatory obligations across geographies
- Guide project teams on embedding privacy by design and security by design principles into technology solutions ensuring that customer data and payment information remain protected throughout the lifecycle
- Prepare and refine policies standards and procedures for data handling access management logging and incident response that reflect PCI DSS GDPR and CCPA requirements and support remote work practices
- Collaborate with audit and assurance functions to plan and support internal and external assessments ensuring evidence is well organized findings are accurately documented and remediation is tracked
- Provide structured training and awareness content for employees working remotely and in rotational shifts so they understand compliance expectations practical behaviors and the impact of nonconformance
- Evaluate new tools platforms and automation opportunities that improve compliance management activities such as control testing documentation retention and regulatory reporting while reducing manual overhead
- Analyze incidents deviations and near misses to determine root causes and recommend targeted improvements that reduce the likelihood of recurrence and improve overall governance maturity
- Document architecture decisions data flows and control mappings in a clear manner so stakeholders can trace how regulatory requirements are implemented and verify that risk is appropriately managed
Qualifications
- Possess extensive hands on experience in compliance management frameworks with demonstrated ability to interpret complex regulatory requirements and convert them into actionable control designs
- Bring deep expertise in PCI DSS domains including network security access control logging vulnerability management and cardholder data protection applied within large scale enterprise environments
- Demonstrate strong knowledge of GDPR principles such as lawfulness fairness transparency data minimization purpose limitation and data subject rights with proven experience implementing compliant solutions
- Show practical experience applying CCPA requirements including consumer rights disclosure obligations data sale restrictions and opt out mechanisms within business processes and technical architectures
- Apply advanced understanding of governance and compliance methodologies to design policies standards and procedures that are pragmatic easy to adopt and aligned with organizational risk appetite
- Utilize excellent analytical and problem solving skills to assess complex environments balance regulatory expectations with business needs and propose clear prioritized remediation actions
- Communicate clearly with technical and nontechnical stakeholders to explain regulatory impacts control choices and risk implications in a concise actionable manner that encourages informed decisions
ข่าวประชาสัมพันธ์แบบสำเร็จรูปของ Cognizant
Cognizant(NASDAQ: CTSH) คือผู้สร้าง AI และผู้ให้บริการด้านเทคโนโลยี ซึ่งเชื่อมช่องว่างระหว่างการลงทุนใน AI และมูลค่าขององค์กรด้วยการสร้างโซลูชัน AI แบบครบวงจรให้แก่ไคลเอนต์ของเรา ความเชี่ยวชาญเชิงลึกด้านอุตสาหกรรม กระบวนการ และวิศวกรรมของเรา ช่วยให้เราผสานบริบทเฉพาะขององค์กรเข้ากับระบบเทคโนโลยีเพื่อเพิ่มศักยภาพมนุษย์ สร้างผลลัพธ์ที่จับต้องได้ และช่วยให้องค์กรระดับโลกก้าวนำหน้าอยู่เสมอในโลกที่เปลี่ยนแปลงไป ดูวิธีดำเนินการได้ที่ cognizant.ai หรือ @cognizant
ข้อมูลการจ้างงานเพิ่มเติม
ข้อมูลเกี่ยวกับค่าตอบแทนมีความถูกต้อง ณ วันที่ประกาศรับสมัครงานนี้ Cognizant ขอสงวนสิทธิ์ในการแก้ไขข้อมูลดังกล่าวได้ตลอดเวลา ภายใต้กฎหมายที่เกี่ยวข้อง
ผู้สมัครอาจถูกขอให้เข้ารับการสัมภาษณ์แบบพบตัวต่อตัวหรือผ่านการประชุมทางวิดีโอ นอกจากนี้ ผู้สมัครอาจถูกขอให้นำเอกสารประจำตัวที่ออกโดยหน่วยงานของรัฐ หรือบัตรประจำตัวที่ออกโดยรัฐบาลซึ่งยังมีผลบังคับใช้ มาแสดงในระหว่างการสัมภาษณ์แต่ละครั้ง
Cognizant เป็นนายจ้างที่ให้โอกาสอย่างเท่าเทียม การสมัครและการพิจารณาคุณสมบัติของคุณจะไม่ถูกตัดสินจากเชื้อชาติ สีผิว เพศ ศาสนา ความเชื่อ รสนิยมทางเพศ อัตลักษณ์ทางเพศ สัญชาติ ความพิการ ข้อมูลทางพันธุกรรม การตั้งครรภ์ สถานะทหารผ่านศึก หรือคุณลักษณะอื่นใดที่ได้รับการคุ้มครองตามกฎหมายของรัฐบาลกลาง รัฐ หรือท้องถิ่น







