Job Description & Scope
Job description ZS is a place where passion changes lives. As a management consulting and technology firm focused on improving life and how we live it , our most valuable asset is our people. Here you’ll work side-by-side with a powerful collective of thinkers and experts shaping life-changing solutions for patients, caregivers and consumers, worldwide. ZSers drive impact by bringing a client first mentality to each and every engagement. We partner collaboratively with our clients to develop custom solutions and technology products that create value and deliver company results across critical areas of their business. Bring your curiosity for learning; bold ideas; courage an d passion to drive life-changing impact to ZS. Our most valuable asset is our people . At ZS we honor the visible and invisible elements of our identities, personal experiences and belief systems—the ones that comprise us as individuals, shape who we are and make us unique. We believe your personal interests, identities, and desire to learn are part of your success here. Learn more about our diversity, equity, and inclusion efforts and the networks ZS supports to assist our ZSers in cultivating community spaces, obtaining the resources they need to thrive, and sharing the messages they are passionate about. We seek an Audit & Compliance Associate to join our Pune, India office. As a member of the ZS Software as a Service (SaaS) Hosting Team, the Information Security and Compliance Associate Associate will perform (and participate in) the planning, execution, and reporting on technology infrastructure and application security and compliance audits in support of various internal compliance requirements and initiatives as well as client directed compliance mandates. What you’ll do Perform audits in accordance with the plan based on various control frameworks and standards; Establish, monitor, document, and update compliance controls and findings; Create remediation plans based on findings and initiate projects, as necessary, in order to meet commitments made within remediation plans; Participate in client directed audit and compliance initiatives, including but not limited to, SAS 70 (SSAE 16) audits, client SOX audit assistance requests and Vendor Data Security and Privacy assessments; Develop and update IT Policies, process maps, templates and supporting change management tools, as often as needed; Assist in the development of training material in support of IT Policy adoption enterprise wide; participate in compliance training workshops, as needed; Monitor compliance with existing IT Policies and supporting tools; Liaison with ZS Client Teams and the ZS SaaS Hosting Team Manager to ensure that all mutually agreed upon business operations SLAs are met; Plan and participate in DR planning and testing; Assist with vendor review and selection in support of on-going internal and client directed compliance initiatives; Assist the Legal team with the review of client contracts as it relates to technology specific compliance requirements; Assist the Legal team with the interpretation of various US and EU laws and technical compliance directives and determine potential impact to the organization. Assist with the completion of client RFPs and RFIs as it relates to compliance; Work with IT, consulting, SD Group and legal teams on compliance standards; Security and compliance projects as assigned. What you’ll bring 2 years of information systems experience with audit planning, risk assessment, and reporting/documentation Hardware, software, and networking information technologies IT security, controls, practices, and procedures Working knowledge of various control frameworks like mentioned below are desirable COBIT – Control Objectives for Information and Related Technology ISO/IEC 27002:2005 – Code of Practice for Information Security Management ITIL – Information Technology Infrastructure Library SOX – Sarbanes-Oxley HIPAA HITECH – Health Insurance Portability and Accountability SAS 70 – Statement of Auditing Standar