HamburgerMenu
iimjobs
Job Views:  
903
Applications:  299
Recruiter Actions:  16

Posted in

IT & Systems

Job Code

1696012

Chief Information Security Officer - NBFC

Dimensions HRD Consultants.15 - 22 yrs.Bangalore
Posted 3 months ago
Posted 3 months ago

CISO (15-22 yrs)

Location Bangalore

Industry : NBFC

About the Role

We are scouting for individuals who will be building, planning and implementing the overall Information Security of the organization.

- You will draft / coordinate / monitor IT process/policies to ensure compliance as per necessity by IT Act/ statutory & regulatory (e.g. RBI, SEBI, GDBR, UIDAI etc.) / info security (ISM) guidelines and circulars with respect to Technology in coordination with internal & external stakeholders

- You will review the regulatory / Indian Govt. Information Technology / data Security guideline as an when it is circulated /published.

- You will be conducting IT committee's as per ISM schedule and necessity advised by regulatory. Drafting/Circulating MOM of IT committee meetings to respective members and business as & when required.

- You will be preparing & updating business wise IT infra details which are largely required for the Compliance/Legal team for regulatory filing.

- You will review and fill out mandatory IT documentation with respective regulatory bodies as necessary.

Manage IT Policies & Procedures :

- You will be responsible for drafting & ensuring implementation of IT Policies and procedures at the operational level.

- You will formalize, conduct vendor risk assessments & audits, ensure implementation of identified gaps.

- You will improvise and keep internal IT / IS manuals updated with all relevant regulations relating to IT. Periodic review of Information Security Manual (ISM) understanding business/regulatory/data security/technology etc.

- You will be introducing and drafting processes/policies based on finding/observation.

- You will be involved in periodic review of IT processes/policies and issue an advisory note to overcome gaps/loops by highlighting risk associated to it.

- You will be introducing new processes/policies by doing market study/survey relevant to our business and info/infra security by highlighting risk and necessity.

- You will be ensuring adherences of key process / policy execution and availability of audit trails. - You will manage Information Systems Risk Assessments & audits :

- You will Plan, Coordinate, review & manage IT / IS Risk Assessments & IT audits, VAPT with relevant stakeholders (internal & external, including vendors)

- You will Plan, Conduct, Review & Manage periodic IT audit and IT Risk Assessments (internal & external)

- You will be responsible for carrying out periodic Internal & External IT, Process, Policy, VAPT, System Audit. Management

- You will be involved in closure of audit findings with amendment to existing process/policy in order to close open loops/gaps or introduce new process/policy to close the risk

Manage IT & Cyber Security :

- You will Plan, formulate, coordinate, implement, monitor & manage the cyber crisis management plan (CCMP).

- You will ensure necessary cyber security safeguards are designed & implemented.

- You will be part of Management of cyber security, related incidents & reporting to management and respective regulatory bodies. Responsible for Incident Management and resolution

- You will be providing relevant data IT information Sector to Partner Function/ Business as and when required.

BCP & DR:

- You will be responsible for formulation, review & monitoring BCP plans and it's implementation. - You will coordinate to conduct BCP / DR drills, present findings

- You will suggest/implement & constantly update BCP / DR plans

What you would possess already:

- Experience in SOC2 Type II implementation and audit (Trust Services Criteria) (This is must to have skill)

- Experience in ISO 27001 readiness and implementation and audit , SOX - ITGC controls

- Excellent understanding of information security concepts, principles, and best practices required

- Excellent communication skills to interact with internal and external contacts required;

- Interpersonal and collaborative skills and the ability to communicate security and risk concepts to technical and non-technical audiences required

- High level of personal integrity and the ability to professionally handle confidential matters with proper judgment required

- 10+ years of professional experience.

Didn’t find the job appropriate? Report this Job

Similar jobs that you might be interested in
Job Views:  
903
Applications:  299
Recruiter Actions:  16

Posted in

IT & Systems

Job Code

1696012

Loading chat...