GRC – ITGC(General Control) SME
About The Role
As a Cybersecurity Audit & Compliance Specialist, you will make an impact by supporting global cybersecurity audit, compliance, certification, and governance initiatives across the organization. You will be a valued member of the Cybersecurity and Risk Management team and work collaboratively with Information Security, Legal, Vendor Management, IT, Internal Audit, and business stakeholders to ensure compliance with industry standards, regulatory requirements, and corporate security policies. In this role, you will help strengthen the organization's security posture through audit readiness, certification management, compliance monitoring, and continuous improvement initiatives while supporting global information security frameworks and standards.
In This Role, You Will
- Support cybersecurity audit and compliance initiatives, including ISO 27001 certification, ENS certification, and other global information security standards and regulatory requirements.
- Prepare the organization for internal and external security audits by coordinating audit activities, tracking deliverables, and ensuring timely completion of remediation efforts.
- Partner with cross-functional teams, external auditors, advisors, and vendors to collect, validate, organize, and present audit evidence and compliance documentation.
- Conduct compliance reviews, gap assessments, and remediation tracking to identify and address deficiencies against applicable security frameworks and policies.
- Review information security requirements within vendor and customer contracts and provide guidance to ensure alignment with corporate cybersecurity standards and controls.
Work Model
Based on this role's business requirements, this is a remote position open to qualified applicants in the United States. Regardless of your working arrangement, we are here to support a healthy work-life balance through our various wellbeing programs. The working arrangements for this role are accurate as of the date of posting. This may change based on the project you're engaged in, as well as business and client requirements. Rest assured; we will always be clear about role expectations.
What You Need to Have to Be Considered
- Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Business Administration, Risk Management, or a related field, or equivalent professional experience.
- Experience supporting cybersecurity audits, compliance programs, regulatory assessments, or certification initiatives.
- Knowledge of ISO 27001 requirements, controls, risk management principles, and certification processes.
- Experience conducting compliance assessments, gap analyses, evidence collection, and remediation tracking activities.
- Strong understanding of information security governance, policies, standards, and audit methodologies.
- Experience managing audit documentation, compliance records, and evidence repositories.
- Ability to coordinate multiple projects and compliance initiatives while meeting deadlines.
- Strong stakeholder management skills with experience collaborating across technical and business teams.
- Excellent written and verbal communication skills with exceptional attention to detail.
- Strong analytical, organizational, and problem-solving abilities.
These Will Help You Stand Out
- Experience supporting ISO 27001 certification or recertification efforts.
- Knowledge of ENS (Esquema Nacional de Seguridad) requirements and other global cybersecurity compliance frameworks.
- Experience working with third-party risk management, vendor security reviews, and contract security assessments.
- Familiarity with NIST Cybersecurity Framework, SOC 2, CIS Controls, GDPR, or other regulatory and security frameworks.
- Experience managing corrective action plans and compliance remediation programs.
- Professional certifications such as CISA, CRISC, CISM, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, or similar credentials.
- Knowledge of cybersecurity risk assessments, security governance, and control testing methodologies.
- Experience supporting global audit and compliance programs within large enterprise environments.
Salary and Other Compensation
The annual salary for this position is anticipated to be between $95,000 and $135,000, depending on experience, qualifications, geographic location, skills, and other job-related factors. This position is also eligible for Cognizant's discretionary annual incentive program, based on performance and subject to the terms of Cognizant's applicable plans.
Benefits
- Medical, dental, and vision insurance
- Health Savings Account (HSA) and Flexible Spending Accounts (FSA), where applicable
- Company-paid life insurance and disability coverage
- 401(k) retirement savings plan with company contributions, subject to plan provisions
- Paid time off, company holidays, and leave programs
- Employee Assistance Program (EAP)
- Wellbeing and mental health resources
- Professional development, training, and certification opportunities
- Career growth and internal mobility programs
- Associate recognition and reward programs
Benefits may vary by location and employment status and are subject to change.