About this role
EXL (NASDAQ: EXLS) is a leading data analytics and digital operations and solutions company. We partner with clients using a data and AI-led approach to reinvent business models, drive better business outcomes and unlock growth with speed. EXL harnesses the power of data, analytics, AI, and deep industry knowledge to transform operations for the world’s leading corporations in industries including insurance, healthcare, banking and financial services, media and retail, among others. EXL was founded in 1999 with the core values of innovation, collaboration, excellence, integrity and respect. We are headquartered in New York and have more than 54,000 employees spanning six continents. For more information, visit www.exlservice.com.
EXL never requires or asks for fees/payments or credit card or bank details during any phase of the recruitment or hiring process and has not authorized any agencies or partners to collect any fee or payment from prospective candidates. EXL will only extend a job offer after a candidate has gone through a formal interview process with members of EXL’s Human Resources team, as well as our hiring managers.
• Instrumental in design and enforce security by design. • Policy and procedure creation and updates/improvements • Cloud Security Governance • Metric reporting • Security Controls
Key Responsibilities
• Providing security advice, requirements and guidance to the business when delivering new systems or updates to existing, to ensure Security by design. • Performing security-focused risk assessment on new systems/services and changes to existing to ensure they are within risk tolerance. • Working with the business to review designs and ensure that they are in line with existing security principles, patterns, standards, and best practice. • Work with the business to define, document and implement core security patterns, standards, and guidelines. • Reviewing the current security processes within your area of focus, to ensure optimization and coverage. • Be the initial security point of contact for your region and route any questions to the relevant teams. • Work with the wider security architecture team to ensure a standardized approach to security is defined and followed. • Collaborate with IT teams to make sure the correct security controls and measures are in place before implementation.
• Bachelor’s degree or equivalent experience in computer science, IT engineering, or related field • An MSc Information Security or equivalent would be an advantage. • Information Security and/or Information Technology certifications such as CISSP etc. are desirable, also acceptable is having experience in this area, any security certification, CISSP may not be relevant in the SA market • Azure Security Certifications are preferred: Azure knowledge is important. AWS is also ok. Understanding how firewalls work rather than building them. • Experience of common frameworks such as NIST, CIS, ISO27k and MITRE: Azure knowledge is important. AWS is also ok. Understanding how firewalls work rather than building them. • Experience in using SABSA valuable: Azure knowledge is important. AWS are also ok. Understanding how firewalls work rather than building them. • Review solution designs and recognize security concerns. • Work with vendors to understand the mitigations and make recommendations. • Be able to pragmatically review and understand where the security risk could outweigh the business benefits. • Represent both the business to security and security to the business. • Help make the business understand the importance of considering security in designs. • Ability to support the business in the delivery of security requirements. • Understanding of Threat Modelling frameworks and implementation e.g., STRIDE • Ability to deconstruct complex environments and navigate conflicting project requirements. • Work with the wider security team to mature security processes and patterns. • Prior experience working in Information security is essential. • Prior experience of working as a security architect is essential. • Prior experience of creating security artefacts is preferred.