Job Description
We are seeking an experienced Information Security & Risk Management Leader to support the CISO in driving the organization's Information Security, Risk Management, Compliance, Governance, and Cyber Resilience initiatives. The role will be responsible for implementing and maintaining a robust security framework that safeguards enterprise information assets, ensures regulatory compliance, manages cyber risks, and supports business objectives.
The ideal candidate will bring deep expertise across Information Security Governance, Risk & Compliance (GRC), Security Operations, Secure Architecture, Third-Party Risk Management, Incident Response, Business Continuity, and Regulatory Compliance. Banking and Financial Services experience will be highly preferred.
Key Responsibilities A. Strategic Security Leadership & Governance- Assist the CISO in defining, implementing, and monitoring the enterprise Information Security and IT Risk Management program.
- Develop, maintain, and publish Information Security policies, standards, procedures, and client-specific security requirements.
- Drive Risk-Based Access Control (RBAC), Third-Party Risk Management (TPRM), and enterprise risk assessment programs.
- Establish and manage security awareness and training initiatives across the organization.
- Conduct IT risk assessments and facilitate risk treatment plans with business stakeholders.
- Provide regular MIS, dashboards, KPIs, and risk reports to executive leadership.
- Ensure compliance with regulatory, legal, contractual, and industry requirements.
- Oversee Business Continuity Management (BCM), Disaster Recovery (DR), and Work-from-Home (WFH) security frameworks.
- Monitor emerging cyber threats and advise management on mitigation strategies.
- Act as the key liaison between Information Security, Compliance, Audit, Legal, HR, and Business Units.
- Support internal, external, customer, and regulatory audits.
- Coordinate responses to security observations, audit findings, and non-conformities.
- Engage with law enforcement agencies, regulators, customers, and advisory bodies when required.
- Support problem management, change management, and security governance forums.
- Drive asset classification and data protection initiatives across the organization.
- Provide security guidance for infrastructure, applications, cloud platforms, and technology projects.
- Ensure security requirements are embedded within enterprise architecture and project lifecycles.
- Evaluate, recommend, and implement security technologies and controls.
- Collaborate with IT teams to strengthen platform security, technical controls, and secure configurations.
- Drive security reviews and assessments for new and existing systems.
-
Lead critical security processes, including:
- Incident Management & Response
- Change Management
- Vulnerability Management
- Exception Management
- Infosec Ticket Management
- Threat Management
- Platform Security & Compliance
-
Oversee:
- PII Data Purging Programs
- Dark Web Monitoring
- Social Media Threat Monitoring
- Email DLP Monitoring
- Security Event Management
-
Conduct:
- Security Reviews & Assessments
- Source Code Reviews (SAST & SCA)
- Vulnerability Assessments & Penetration Testing (VAPT)
- Red Team Exercises
- Ransomware Readiness Assessments
-
Review and manage:
- Active Directory Security
- User Access Management
- Windows Server & System Audits
- Firewall & Security Device Configurations
- CIS Benchmark Compliance
- Network Device Security Reviews
-
Manage outsourced security vendors and ensure adherence to SLAs.
- Bachelor’s Degree in Information Technology, Information Systems, Cyber Security, Computer Science, or related discipline.
- Information Security specialization preferred.
- Minimum 10+ years of Information Security experience.
- Minimum 8 years in a leadership role managing enterprise security, risk, governance, and compliance functions.
- Banking/Financial Services industry experience preferred.
- Information Security Governance, Risk & Compliance (GRC)
- IT Risk Management
- Enterprise Security Architecture
- Third-Party Risk Management (TPRM)
- Security Operations & Incident Response
- Vulnerability Management & VAPT
- Business Continuity & Disaster Recovery
- Security Audits & Compliance
- Security Metrics & Reporting
- Vendor Security Management
- Regulatory Compliance & Data Privacy
Strong expertise in:
- ISO 27001
- ISO 42001
- ISO 27701
- ISO 9001
- ISO 17025
- SOC 2
- DPDP Act
- GDPR
- COBIT
- ITIL
- Information Security Risk Frameworks
- CISSP – Certified Information Systems Security Professional
- CISA – Certified Information Systems Auditor
- CISM – Certified Information Security Manager
- ISO 27001 Lead Auditor / Lead Implementer
- ISO 9001 Lead Auditor
- ISO/IEC 17025 Auditor
- ISO 22301 Business Continuity Certification
- ISO 27701 PIMS Lead Auditor
- SOC 2 Certification
- DPDP / GDPR Related Certifications
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
