job description
Join WNS, a global leader in business process management, as our Information Security, Risk & Compliance Supervisor in Bali. In this critical role, youâll safeguard our digital assets, ensure compliance with global regulations, and lead risk assessment initiatives for our technology and operations. This hybrid/remote position offers the flexibility to work from stunning locations like Canggu, Ubud, or Denpasar while contributing to a secure and resilient business environment.
As the guardian of information security, youâll conduct comprehensive risk assessments, privacy impact analyses, and compliance audits to protect client data and internal systems. Your expertise will drive strategic security policies, mitigate cyber threats, and ensure adherence to frameworks like ISO 27001, GDPR, and NIST. This role is perfect for a detail-oriented professional who thrives in a dynamic, fast-paced environment and is passionate about shaping the future of digital security.
At WNS, we value innovation, collaboration, and continuous learning. Youâll work alongside a talented team of IT and compliance experts, leveraging cutting-edge tools to address emerging threats and regulatory challenges. If youâre ready to take your career to the next level in one of the worldâs most desirable work destinations, weâd love to hear from you!
Responsibility
- Lead and conduct information security risk assessments for client operations, technology, and third-party vendors to identify vulnerabilities and recommend mitigation strategies.
- Perform Privacy Risk and Impact Assessments (PRIA) to ensure compliance with global data protection regulations (e.g., GDPR, CCPA, PDPA).
- Develop, implement, and enforce security policies, standards, and procedures aligned with industry best practices and regulatory requirements.
- Collaborate with IT, legal, and business teams to integrate security and compliance into project lifecycles, system designs, and operational processes.
- Monitor and report on security incidents, breaches, and compliance violations, ensuring timely resolution and corrective actions.
- Conduct security awareness training for employees and stakeholders to foster a culture of security and compliance.
- Oversee audits and assessments (internal and external) to validate compliance with security frameworks (e.g., ISO 27001, SOC 2, NIST).
- Stay updated on emerging threats, regulatory changes, and industry trends to proactively enhance security posture.
Qualifications
- Bachelorâs degree in Information Technology, Cybersecurity, Computer Science, or a related field (Masterâs degree or relevant certifications are a plus).
- 5+ years of experience in information security, risk management, or compliance roles, with at least 2 years in a supervisory or leadership capacity.
- Proven expertise in risk assessment methodologies, privacy impact assessments, and compliance frameworks (e.g., ISO 27001, GDPR, NIST, SOC 2).
- Strong knowledge of cybersecurity principles, threat modeling, and vulnerability management.
- Experience with security tools and technologies (e.g., SIEM, GRC platforms, encryption, IAM).
- Excellent analytical, problem-solving, and communication skills, with the ability to articulate complex security concepts to non-technical stakeholders.
- Relevant certifications such as CISSP, CISM, CRISC, CIPP/E, or ISO 27001 Lead Auditor are highly desirable.
- Ability to work independently in a remote/hybrid environment with a high degree of self-motivation and accountability.