TPRM
Full Time | Hyderabad | India
Role Overview
1 Access management-Privilege access management , Segregation of duties, least privilege principle , RBAC , Password management , User access management, personal accounts & Non personal technical accounts
2 Data security – Encryption at rest and in transit , Key lifecycle management, Ciphers,
3 Secure operations- Log monitoring, Log protection, Log management, Endpoint security, Patching
4 Data Leakage Prevention- Understanding of DLP tools & technologies, structured and unstructured data, Instances (Dev, Test , PROD), Email security, Data classification.
5 Cyber Threat management – Threat & Vulnerability management, Hardening process, External attacks ( DDoS) , Penetration testing , Incident management
6 Network security- Basic network security components understanding ( Firewall, IDS ,IPS, WAF), Network ports & protocols, Network segmentation etc.
7 System acquisition , development & Change management– SLDC process for application design , development , deployment & Operations including defined change controls for approval and testing.
8 Operation resilience – BCP , Backup & restore, Records management , Data retention.
9 Governance , risk & compliance- Polices , Procedures, Risk management framework , Cyber risk management, Supply chain risk management.
10 Assurance reports – SOC 1, SOC 2 reports, ISO 27001 certificate including Statement of applicability, CSA star level 2 etc