TymblHub

© 2026 TymblHub

Lead : Information Security Governance

Aditya Birla Housing Finance
Posted on
Aditya Birla Housing Finance logo

Experience
9 - 13 yrs
Job Location
Thane, India
Vacancy
1
Designation
Information Security Lead
Job Type
Not specified

Job Description


Role & responsibilities


  • Develop, maintain and align Information Security policies, standards, SOPs and procedures with regulatory requirements, business objectives and industry best practices; run the policy renewal tracker and secure timely approvals.
  • Establish and maintain an Enterprise Information Security Governance and IT Risk Management program with continuous monitoring and risk mitigation, in line with ISO 27001:2022, NIST CSF, CIS and DPDP Act.
  • Conduct Information Security assessments and technology due diligence for new/existing projects and applications review solution architecture, data flows and controls on a Secure-by-Design basis, perform threat modelling, assess gaps and residual risk, and provide initial and final production sign-offs.
  • Lead the Enterprise Vulnerability Management program govern application security assessments, infrastructure VA, configuration reviews, prioritise by risk/exploitability, manage exceptions and drive timely closure.
  • Govern application & API security assess applications against InfoSec/AppSec checklists, oversee VA, PT and secure code reviews, application-layer attack mitigation and DevSecOps integration.
  • Review, maintain and govern Minimum Baseline Security Standards (MBSS) / Secure Configuration Documents (SCD) and drive configuration compliance and closure.
  • Implement and oversee cloud security best practices across AWS & Azure IAM, encryption, network security, logging and monitor CNAPP tooling (CSPM, CIEM, CWPP); conduct cloud security assessments, gap and compliance reviews for IaaS/PaaS/SaaS.
  • Oversee governance and operational management of security tools — SIEM, EDR, DLP, WAF, IDS/IPS — including SIEM asset onboarding, monthly reconciliation, use-case/detection enhancement and alert closure with the SOC.
  • Own security incident management — detection, logging, triage, RCA, mitigation, monthly incident reporting and a learning matrix that drives preventive controls.
  • Participate in CAB / change management — assess security implications of planned and emergency changes and approve, reject or recommend additional controls.
  • Manage internal, statutory, regulatory and certification audits — coordinate evidence, provide management responses and remediation plans, and track observations to closure; address queries from Compliance, Internal/External Audit and Regulators.
  • Oversee BCP & DR governance — maintain the annual DR drill calendar, govern drills for critical applications/infrastructure, validate RTO/RPO and close observations (BIA, BCRA, FRP, IT DR drills).
  • Drive Vendor Risk Assessment (VRA) and Third-Party Risk Management (TPRM) — vendor inventory & criticality, annual review calendar, assessments, risk ratings and closure.
  • Run security awareness & cyber resilience programs — monthly campaigns, annual training, phishing simulations with targeted remediation, and annual CCMP tabletop / incident-response simulations.
  • Prepare and present executive & governance reporting for ITSC, IT Strategy Committee, RMC and Board — consolidating InfoSec metrics, risk dashboards, KPI/KRI, compliance status, audit updates and incident summaries; track decisions and action closure.


Preferred candidate profile


  • Strong, hands-on experience with security governance frameworks — ISO 27001:2022, NIST CSF, CIS, SOC 2.
  • Cloud security (AWS & Azure) — IAM, VPC, Security Groups, KMS, network security best practices and CNAPP (CSPM, CIEM, CWPP).
  • Working knowledge / hands-on with security tooling — SIEM (Splunk, ELK, Sentinel), EDR, DLP, WAF and security monitoring.
  • Deep understanding of application security — OWASP Top 10, SANS Top 25, API security, mobile app security and DevSecOps.
  • Experience in incident response, forensic investigation and security automation.
  • Exposure to BFSI/NBFC regulatory environment (RBI, NHB, DPDP Act) and audit management.
  • Strong analytical, problem-solving and decision-making ability, with a proven capability to collaborate across cross-functional teams and articulate risk to senior/Board audiences.