Lead Assistant Manager at EXL Service
Views:401 Applications:11 Rec. Actions:Recruiter Actions:2
EXL Service - Manager - Security Governance & Metrics (5-8 yrs)
Job Description :
Position Title, Responsibility Level : Manager
Function : Global Technology (Information Security)
Span of Control : 1-2
Permanent/ Temporary : Permanent
Reports to : AVP - Information Security
Location : Noida
Basic Function :
Information Security Governance is a means to initially identify and rank the most critical risks to your business and then provide a means to monitor them continuously. A subset of enterprise governance, information security governance is critical to your organization. It provides strategic direction, ensures that objectives are achieved, risk is managed, organizational resources are used responsibly, and the success or failure of the enterprise security program is properly monitored
Security Metrics program is a strategic governance area and is seen as a key enabler for investment making for the management. The Information & Cyber Security Metrics Manager will be responsible for designing and managing the enterprise-wide Security Metrics Program to report to organization CXOs, Clients and the Board.
Essential Functions :
- Help enhance our existing governance framework to achieve risk prioritization and continual monitoring thereby ensuring a risk-managed environment.
- Responsible for ensuring various management and cross-functional governance forum meetings with appropriate agenda design and content from respective stakeholders
- Responsible to help prepare information security updates for the Steering Committee, Board, Audit Committee
- Take ownership role for the establishment of a current and up-to-date Information Security and Cyber Security metrics baseline. Make use of SMART methodology for designing the metrics program.
- Publish Cyber Security metric performance data on weekly, monthly, quarterly and annual basis, and ad hoc reports as requested, in a concise and consistent manner, soliciting input from a number of sources both internal and external stakeholders
- Ensure collection and analysis of key data related Cyber Security metrics, Internal measures KPIs and KRIs reporting that is timely, accurate, consistent, complete and relevant for the purpose of providing comprehensive information for strategic Cyber Security management decisions.
- Play key role in supporting the development of capability to provide current cyber security metric inputs that may be required for regulatory reporting and audit queries
- Based upon the metrics collected the analyst prepares the monthly Cyber readiness report for submission.
- Provides a weekly, monthly, and quarterly metrics/ trend analysis reports to various levels of leadership based upon the trends observed over the review period.
- Through in-depth knowledge of Cyber Security Metrics trends/results, provide support to the SOC and IR team in the early identification of potential risks/impacts that may become apparent through inference, patterns and analysis of Cyber Security metric data, and make
Primary Internal Interactions :
- Organizational Senior Leadership Team - Steering committee, Board, Audit Committee
- 0SOC / VAPT / DLP / Malware Analysis / APT Team
- Proxy / System / AV / SCCM Teams
- Internal Audits Teams
Primary External Interactions :
- Client Counterparts
- Auditors (Big 4s)
Technical Skills : Security Metrics Analysis, ISO 27001, PCI DSS, IOCs, Threats and Vulnerabilities, AV, Patches
Process Specific Skills :
- Security Governance, IT Governance, Risk Compliance, IT Security, Lead Audit, System Audit, SOX Audit, Lead System Auditor
- SMART Metrics Program methodology
Soft skills (Desired) :
- Good Oral and written communication skills
- Good Presentation & Public speaking skills
- Creativity and Problem Solving Skills.
- Self-motivated and Self-driven
Education Requirements : Graduation
One or more of the following certifications is desirable : CISA / CISM / CISSP / ISO27001 / CRISC
Work Experience Requirements :
Total Experience : 5 - 8 years Information Security experience with the relevant experience of 3-4 years running the Security Governance and Metrics program in a multinational company at the organizational level.