GRC - Security Audit
ECMS Requirement Format | |
Number of Openings |
2 |
ECMS ID in sourcing stage |
539204 |
Assignment Duration |
12 months |
Total Yrs. of Experience |
More than 3 years of experiences of cybersecurity domain, including but not limited to risk assessment, security operation, penetration test, network deployment, data privacy, etc. |
Familiar with auditing methodology and providing solution to risk findings | |
Obtained related certifications, e.g.: CISSP, CISA, ISO27001LA, CEH, OSCP, CCSP, etc. | |
Relevant Yrs. of experience |
Minimum 5 years relevant experience in cybersecurity with a focus on governance, risk and compliance. |
Detailed JD (Roles and Responsibilities) |
The Security Auditing SME is responsible for executing security assessments across infrastructure, applications, and data environments. This role ensures robust protection against threats by applying deep expertise in audits, network and firewall security, and secure application design. |
| |
Key Responsibilities : | |
Perform onsite audits for security compliance review at client locations as well as client vendor offices. | |
Conduct comprehensive security audits across systems, applications, and networks. | |
Review vulnerability assessment and penetration testing reports for web, mobile, and cloud-based applications. | |
Evaluate network security controls, including segmentation, IDS/IPS, and firewall configurations. | |
Validate data security by reviewing encryption standards, access control policy& process, and secure storage practices. | |
Review and validate firewall rules, policies, and change management processes. | |
Document findings, provide remediation guidance, and support compliance with standards like ISO 27001, NIST | |
| |
Service #1: Onsite & Remote CM audit : | |
Objective: Provide resources to assist Apple's new product security team in performing Security Assessments of CM sites under Apple's supervision. Sample activities include: | |
| |
Arrange resources with the required skillset and experience as described by Apple to execute CM Electronic Security Assessments | |
Participate in training and workshops organized by Apple's security team to understand the CM Electronic Security Assessment requirements | |
Conduct Electronic Security Assessments as planned and document results for Apple's security team | |
Track CM's discrepancy items against Apple security standard (SRAS) and assist with follow-ups on the remediation on a weekly basis | |
Consultant will use Apple's methodologies and reporting templates throughout the course of this engagement. | |
| |
DELIVERABLES: | |
Service #1: Onsite & Remote CM audit | |
Consultant to perform spell check and review for consistency in CM naming convention prior to delivery of draft reports to Apple | |
Consultant must deliver each CM ESA finding report and CM site reporting master data based on testing performed to date | |
| |
Sample activities include : | |
Collect security control logs of CM-related threat scenarios | |
Develop and design the key threat scenarios use case and monitoring metrics | |
Develop multiple Security applications, factory security control systems and other tools to enhance the security monitoring and operation capabilities. Through the develop support to help Apple construct the end-to-end security monitoring system. | |
Integrate relevant monitoring metrics, analysis processes and corresponding measures into platform-based tools or products | |
Related tools or products hosting, maintenance and upgradation | |
Continuous log monitoring, Security Operation and incident response support in accordance with agreed service processes and SLAs. | |
Mandatory skills |
1. Resources who have worked on remediating audit findings |
2. Resource should have working knowledge on CCM | |
3. Resource should have excellent oral and written skills (as they will have to communicate with Supplier leadership) | |
Desired/ Secondary skills |
Have knowledge on multiple security domains. |
Domain |
GRC – Security Audit |
Max Vendor Rate in Per Day (Currency in relevance to work location) |
11500 INR / Day |
Work Location given in ECMS ID |
Bangalore, Chennai only |
WFO/WFH/Hybrid WFO |
Hybrid WFO |
BG Check (Before OR After onboarding) |
After |
Is there any working in shifts from standard Daylight (to avoid confusions post onboarding) YES/ NO |
YES |