Cyber Specialist
Sanofi
Date: 3 hours ago
City: Hyderabad, Telangana
Contract type: Full time
Our Team:
Our Governance, Risk & Compliance team, reporting directly to the CISO alongside the Security Architecture and Security Operations & SOC teams, plays a pivotal role in safeguarding the organization's assets and ensuring regulatory compliance. Under the leadership of the Governance, Risk & Compliance Lead, this team ensures our organization's technological infrastructure is secure, compliant, and resilient against evolving cyber threats.
Main responsibilities:
The Cyber Specialist, reporting to the GRC Lead, will play a pivotal role in will play a pivotal role in ensuring regulatory adherence and operational integrity within the Governance, Risk & Compliance team. This role focuses on maintaining compliance with industry standards, policies, and regulatory requirements to mitigate legal and operational risks effectively. Key responsibilities include:
Better is out there. Better medications, better outcomes, better science. But progress doesn’t happen without people – people from different backgrounds, in different locations, doing different roles, all united by one thing: a desire to make miracles happen. So, let’s be those people.
At Sanofi, we provide equal opportunities to all regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, or gender identity.
Watch our ALL IN video and check out our Diversity Equity and Inclusion actions at sanofi.com!
Pursue progress, discover extraordinary
Better is out there. Better medications, better outcomes, better science. But progress doesn’t happen without people – people from different backgrounds, in different locations, doing different roles, all united by one thing: a desire to make miracles happen. So, let’s be those people.
At Sanofi, we provide equal opportunities to all regardless of race, colour, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, ability or gender identity.
Watch our ALL IN video and check out our Diversity Equity and Inclusion actions at sanofi.com!
Our Governance, Risk & Compliance team, reporting directly to the CISO alongside the Security Architecture and Security Operations & SOC teams, plays a pivotal role in safeguarding the organization's assets and ensuring regulatory compliance. Under the leadership of the Governance, Risk & Compliance Lead, this team ensures our organization's technological infrastructure is secure, compliant, and resilient against evolving cyber threats.
Main responsibilities:
The Cyber Specialist, reporting to the GRC Lead, will play a pivotal role in will play a pivotal role in ensuring regulatory adherence and operational integrity within the Governance, Risk & Compliance team. This role focuses on maintaining compliance with industry standards, policies, and regulatory requirements to mitigate legal and operational risks effectively. Key responsibilities include:
- Pen testing
- Coordinate penetration testing activities to ensure testing is performed at least every 3-6 months across most (>75%) on-premise and cloud environments
- Prepare vulnerability disclosure reports on outward facing systems (in the future)
- Performance management & consistency
- Compile data from defined cybersecurity KPIs every month for analysis to drive improvement actions.
- Capability building
- Design, implement and maintain training/awareness programs for the wider org.
- Ensure cybersecurity team has the right capabilities through training and evaluation.
- Manage activities with cross-team dependencies
- Provide guidance for key digital & cloud initiatives from a cybersecurity standpoint.
- Manage insurance coverage aligned with board and leaders across wider organisation.
- Data privacy
- Support of Global Data Privacy program (e.g., managing requests across regions, mapping of data and specific regulations, coordination with Global GBS)
- Management of data process agreements (incl. review of contracts, annual assessment re-evaluation)
- Experience:
- 3-5 years of professional experience (equivalent combination of experience and education accepted)
- Previous work in an international environment.
- Demonstrated experience in cybersecurity compliance roles, focusing on strategic planning and execution.
- Proven track record of contributing to the development and implementation of cybersecurity strategies aligned with compliance standards and organizational goals.
- Experience in developing and implementing cybersecurity strategies that align with compliance standards and organizational objectives.
- Experience in managing cybersecurity performance metrics and KPIs to ensure continuous compliance and improvement.
- Experience collaborating with Security Architect and Operations teams in a feedback loop.
- Ability to develop and communicate policies based on feedback from the Security Architect team.
- Soft skills:
- Broad experience in working in large digital teams, with an understanding of how digital and business processes are linked.
- Expertise in stakeholder engagement and communication related to cybersecurity compliance, particularly with senior leadership and external auditors.
- Ability to design and execute training programs to enhance compliance awareness and build cybersecurity capabilities across the organization.
- Skilled problem solver and self-starter.
- A hands-on pragmatic attitude to driving change.
- Positive, "can-do" attitude.
- Technical skills:
- Experience with AGILE or similar project management frameworks.
- Working knowledge of common information security management frameworks (ISO/IEC 27001, ITIL, NIST, NISD, CISSP/CCSP, QxP, CIS20).
- Understanding of cybersecurity compliance frameworks and regulations (e.g., GDPR, CCPA, HIPAA, SOX) relevant to digital domains (network, cloud, endpoint, applications, data).
- Strong knowledge of cybersecurity risk management principles and practices, including risk assessment and mitigation strategies.
- Education:
- Bachelor’s and master’s degree (preferred) in any of the following fields of study: Information Technology, Computer Science, Cybersecurity or Information Security
- Languages:
- English
Better is out there. Better medications, better outcomes, better science. But progress doesn’t happen without people – people from different backgrounds, in different locations, doing different roles, all united by one thing: a desire to make miracles happen. So, let’s be those people.
At Sanofi, we provide equal opportunities to all regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, or gender identity.
Watch our ALL IN video and check out our Diversity Equity and Inclusion actions at sanofi.com!
Pursue progress, discover extraordinary
Better is out there. Better medications, better outcomes, better science. But progress doesn’t happen without people – people from different backgrounds, in different locations, doing different roles, all united by one thing: a desire to make miracles happen. So, let’s be those people.
At Sanofi, we provide equal opportunities to all regardless of race, colour, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, ability or gender identity.
Watch our ALL IN video and check out our Diversity Equity and Inclusion actions at sanofi.com!
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
Principal Scientist 2 - Preclinical Safety
Novartis India,
Hyderabad, Telangana
3 hours ago
SummaryThe Preclinical Safety (PCS) department within the Novartis Biomedical Research - Translational Medicine Unit provides non-clinical safety strategy of products in -discovery, -development and -market, globally, with state-of-the-art regulatory compliance.As a Principal Scientist-2, you will join our PCS team in India to discuss strategies and deliver non-clinical safety deliverables for the products you are globally responsible for. This role also...
NLP Data Scientist
Wipro,
Hyderabad, Telangana
7 hours ago
Role PurposeThe purpose of the role is to define, architect and lead delivery of machine learning and AI solutions.Do Demand generation through support in Solution development Support Go-To-Market strategy Contribute to development solutions, proof of concepts aligned to key offerings to enable solution led salesCollaborate with different colleges and institutes for research initiatives and provide data science coursesRevenue generation through...
Non-IT Recruiter - Freshers
The Golden Rise (Hyderabad),
Hyderabad, Telangana
13 hours ago
Company Overview: The Golden Rise, located in Hyderabad's vibrant Gachibowli district, is a premier talent outsourcing firm. We specialize in connecting skilled professionals with top multinational corporations and innovative startups, fostering career growth and organizational success. Position Summary: We are seeking a dedicated and experienced Non-IT Recruiter - Freshers to join our recruitment team. This role is perfect for individuals...