
We are looking for a CISO for the Risk department in a leading bank in Mumbai.
Position reports to CRO.
This role is responsible for the bank's information and data security, establishing the right security and governance practices, and enabling a framework for risk-free and scalable business operations in the challenging business landscape. This role requires a high degree of technical knowledge in the development and implementation of security controls and compliance across the e-business and working closely with functional business heads to ensure security controls are effective.
A. Key Position Responsibilities:
Direct Responsibilities:
- Place review of cyber security preparedness of the bank before the board or IT sub-committee to the board on a quarterly basis.
- Inform the vulnerabilities/IT risk in the bank to the board members.
- Member secretary of IT Security committee and hold the committee.
- Invitee to IT Strategy committee and IT Steering committee.
- Ensure Information Security Policy is followed in the bank.
- Assessment of Risk in the Information asset and data.
- Manage and monitor the Security Operation Center.
- Strategies for Incident Identification and response.
- Ensure compliance to Circulars, advisory and alerts given by regulators such as RBI/CSITE.
Risk Identification, Assessment and Evaluation:
- Identify, assess, and evaluate risk to enable the execution of the enterprise risk management strategy.
- Collect information and review documentation to ensure that risk scenarios are identified and evaluated.
- Identify legal, regulatory, and contractual requirements and organizational policies and standards related to information systems to determine their potential impact on the business objectives.
- Identify potential threats and vulnerabilities for business processes, associated data and supporting capabilities to assist in the evaluation of enterprise risk.
- Create and maintain a risk register to ensure that all identified risk factors are accounted for.
- Assemble risk scenarios to estimate the likelihood and impact of significant events to the organization.
- Analyze risk scenarios to determine their impact on business objectives.
B. Qualifications and Experience Requirement:
Qualifications:
- Essential: Bachelors Degree required.
- Preferred: Masters degree in IT, Business with an emphasis on banking related disciplines required.
- Relevant certifications such as CISSP, CISM, CISA, or CRISC are highly desirable.
- Essential: Over 15 years of relevant experience in Information Security Risk - both designing the framework and implementing the same in the Banking sector preferably the Consumer and Retail segment.
- Preferred: Strong BFSI Experience.
Didn’t find the job appropriate? Report this Job