
Key responsibilities:
Regulatory compliance and governance:
- Keep technology processes and policies compliant with the IT Act and with regulatory and statutory requirements, including RBI, SEBI, UIDAI and GDPR, working with internal and external stakeholders.
- Track new government and regulatory guidelines on information technology and data security, and translate them into action for the business.
- Run the IT committee calendar as required by the regulator and the Information Security Manual, and circulate minutes to members and business heads.
- Maintain business-wise IT infrastructure records that the Compliance and Legal teams need for regulatory filings.
- Review and complete mandatory IT submissions to regulatory bodies.
IT policies and procedures:
- Draft IT and information security policies and make sure they are followed at the operating level.
- Keep the Information Security Manual and internal IT manuals current with regulation, business needs and technology changes.
- Review processes periodically, flag the risks behind any gaps, and issue advisories to close them.
- Introduce new policies based on audit observations and on industry benchmarking relevant to the business.
- Set up and run vendor risk assessments and audits, and follow through on remediation.
- Ensure key controls are executed consistently and that audit trails are available.
Risk assessments and audits:
- Plan and manage IT and information security risk assessments, IT audits and VAPT with internal teams, external auditors and vendors.
- Lead periodic internal and external audits covering systems, processes and policies.
- Close audit findings by amending existing controls or introducing new ones.
Cyber security and incident management:
- Design, implement and maintain the Cyber Crisis Management Plan.
- Make sure the right cyber security safeguards are designed and in place.
- Lead incident management and resolution, and report incidents to management and the relevant regulators.
- Provide IT and security information to partner functions and business teams when needed.
Business continuity and disaster recovery:
- Formulate, review and monitor business continuity plans and their implementation.
- Coordinate BCP and DR drills and present the findings to management.
- Keep BCP and DR plans updated as the business and technology landscape changes.
What we are looking for:
Must have:
- 10+ years of professional experience in information security, IT risk or IT governance.
- Hands-on experience implementing and auditing SOC 2 Type II (Trust Services Criteria).
Experience and skills:
- ISO 27001 readiness, implementation and audit.
- SOX IT general controls (ITGC).
- Strong command of information security concepts, principles and best practices.
- Clear communication with internal and external stakeholders, and the ability to explain security and risk to both technical and non-technical audiences.
- A collaborative working style across technology, compliance, legal and business teams.
- High personal integrity and sound judgement in handling confidential matters
Didn’t find the job appropriate? Report this Job