Job Description
Job Title Manager / Asst Manager Information Security
1. JOB PURPOSE
(Summarize in one statement why the job exists; and how it contributes to the overall objective of the company)
Assist, Analyse and improve in securing organizations sensitive information for DMI Finance . Needs to work across the
group to identify and correct flaws in the company’s security systems, solutions, and programs while recommending specific
measures that can improve the company’s overall security posture. Gather information and create attack surface with
offensive security metrics and able to defend the loopholes.
3. PRINCIPAL ACCOUNTABILITIES
A. Information Security Risk & Control Assessment
Perform periodic information security risk assessments, control-gap assessments and inherent/residual risk
analysis.
Identify critical information assets, business services, customer data and associated security risks; maintain
risk registers and treatment plans.
2
Evaluate security controls for design and operating effectiveness and recommend risk-based remediation.
Track remediation of high and critical risks and escalate overdue or unacceptable risks to management.
B. Vulnerability Assessment, Penetration Testing & Attack Surface Management
Coordinate and/or perform VA/PT activities covering on-premises infrastructure, cloud environments,
networks, servers, endpoints and relevant applications.
Maintain an enterprise attack-surface view and track externally exposed assets, vulnerabilities and security
weaknesses.
Validate remediation through evidence and retesting, and provide management reporting on exposure, trends
and closure.
Coordinate with technology teams and external security partners to address identified weaknesses.
C. Security Incident, RCA & Resilience
Support security incident investigation, containment, remediation and closure in coordination with SOC, IT
and business teams.
Document root-cause analysis (RCA), corrective/preventive actions and lessons learned.
Continuously review and update incident response, disaster recovery and cyber-resilience plans based on
emerging threats, incidents and business changes.
Support security aspects of BCP/DR exercises and track closure of identified gaps.
D. Third-Party / Vendor Security
Perform or coordinate information security assessments of third-party vendors and service providers.
Validate adherence to contractual, regulatory and organizational security requirements.
Track vendor security risks, remediation commitments, exceptions and periodic reassessments.
E. Audit, GRC & Regulatory Compliance
Coordinate internal and external information security audits, certifications and regulatory assessments.
Maintain audit evidence, action trackers, control documentation and closure status.
Support compliance with applicable RBI, ISO 27001 and organizational information security requirements, as
applicable to the role.
Prepare inputs and management reporting for Information Security Committee, IT Steering Committee, Board
and other governance forums.
Report regulatory/standards-related security violations and material risks through the defined governance
mechanism.
F. Security Monitoring, Metrics & Reporting
Develop and maintain information security KPIs/KRIs covering vulnerabilities, incidents, risks, audit findings,
compliance, third parties and security controls.
Prepare periodic management dashboards highlighting high risks, inherent risks, control gaps, trends, ageing
and remediation status.
Support security awareness initiatives and targeted communication based on identified risk themes.
G. Cloud Security, Automation & Technology Enablement
Identify opportunities to automate security controls, evidence collection, monitoring and compliance activities,
particularly in cloud environments.
Assess security architecture and controls for new technology deployments and business initiatives.
Collaborate with IT/Cloud/DevOps teams to embed security controls into technology delivery and operational
processes.
H. Governance, Documentation & Continuous Improvement
Review and update information security policies, standards, procedures, guidelines and control
documentation based on business and regulatory requirements.
Support security reviews for new projects, technologies and significant changes.
• Identify opportunities to improve security processes, control maturity, operational efficiency and risk
visibility.
4. MAJOR CHALLENGES
(Challenges faced on an on-going basis in carrying out the job)
Managing cyber and technology risks arising from rapid business growth, digital transformation, cloud adoption
and new IT deployments.
Identifying unknown, emerging and interconnected risks across applications, infrastructure, third parties and
the external attack surface.
Driving timely remediation of high-risk findings across multiple technology and business stakeholders.
Maintaining effective incident readiness and ensuring timely escalation of material security events.
Balancing regulatory/security requirements with business enablement, operational feasibility and risk appetite.
5. DECISIONS
Identify and escalate high/critical information security risks, control failures, material audit observations and
security incidents.
Prioritize security remediation based on business criticality, risk exposure, threat intelligence and regulatory
requirements.
Recommend risk treatment, compensating controls and security improvements for management approval.
Determine when issues require escalation to senior management, governance committees or other defined
stakeholders.
Educational Qualifications
a) Qualifications
Minimum Qualification required: Graduate.
Technical certification: Understanding of ISO, Cloud Security, GRC, Dash Boards
b) Work Experience
Minimum 5 years of relevant experience in Information Security, Cyber Security, IT Risk, GRC, VAPT, Security
Operations or a comparable role.
Communication skills : Expert
Collaboration skills : Expert
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
