HamburgerMenu
iimjobs
Job Views:  
49
Applications:  23
Recruiter Actions:  0

Posted in

IT & Systems

Job Code

1724080

Lead - Information Security - Governance/Risk & Compliance

Employee Forums.5 - 10 yrs.Mumbai
Posted 5 days ago
Posted 5 days ago

Role Summary:

We are seeking an experienced Information Security professional to support the Governance, Risk, Compliance (GRC), Vulnerability Management, and Security Assurance functions at BillDesk. The ideal candidate will be responsible for developing robust security policies and procedures, conducting risk assessments, managing end-to-end security audits, tracking vulnerabilities, performing infrastructure security gap assessments, and ensuring strict compliance with ISO 27001, PCI DSS, RBI guidelines, and various customer security requirements.

Key Responsibilities:

1. Governance & Compliance:

- Develop, implement, and maintain Information Security Policies, Standards, Procedures, and Guidelines.

- Support, optimize, and enhance the overall Information Security Management System (ISMS).

- Ensure absolute compliance with ISO 27001, PCI DSS, RBI regulations, and internal security requirements.

- Act as the primary coordinator for internal, external, customer, banking partner, and regulatory audits.

2. Risk Management & Security Assessments:

- Conduct comprehensive Information Security Risk Assessments for applications, core infrastructure, cloud, and third-party environments.

- Perform detailed infrastructure and security control gap assessments against regulatory and industry benchmarks.

- Own and maintain the organization's risk registers while rigorously tracking remediation activities.

3. Vulnerability Management:

- Review Vulnerability Assessment and Penetration Testing (VAPT) reports and oversee systematic vulnerability remediation activities.

- Track the closure of vulnerabilities identified through scans, penetration tests, audits, and routine assessments.

- Monitor patch management compliance and ensure strict adherence to security remediation timelines.

- Prepare actionable vulnerability dashboards and high-level management reports.

4. Third-Party Security & Audit Management:

- Conduct rigorous vendor and third-party security risk assessments.

- Review third-party security certifications, audit reports, and compliance evidence.

- Manage audit observations and drive the timely, verified closure of findings.

5. Reporting & Governance:

- Prepare security governance dashboards, audit reports, key risk metrics, and compliance status reports.

- Present the current security posture and compliance updates clearly to management and key stakeholders.

Required Skills & Qualifications:

- Experience: 5-10 years of dedicated experience in Information Security Governance, GRC, IT Audit, or Security Assurance.

- Domain Knowledge: Strong, working knowledge of ISO 27001, PCI DSS, RBI Cyber Security Guidelines, and Digital Payment Security Controls.

- Audit Experience: Proven track record of independently handling bank audits, customer audits, and regulatory assessments.

- Technical Understanding: Good understanding of vulnerability management life cycles, VAPT remediation steps, and core infrastructure security controls.

- Soft Skills: Excellent documentation, communication, and stakeholder management skills.

Didn’t find the job appropriate? Report this Job

Similar jobs that you might be interested in
Job Views:  
49
Applications:  23
Recruiter Actions:  0

Posted in

IT & Systems

Job Code

1724080

Loading chat...