Role Summary: We are looking for a cybersecurity and regulatory compliance specialist to support capital markets operations, with a strong focus on international clients, Foreign Institutional Investors (FIIs), and the wider securities market ecosystem. The role will blend capital markets regulatory, client governance, CSCRF compliance, cyber resilience, control assurance, and security project responsibilities across technology platforms, infrastructure, applications, vendors, and business stakeholders. The individual will be responsible for driving cybersecurity governance, audit readiness, incident reporting, regulatory coordination, and client-facing assurance obligations in a highly sensitive and regulated environment.
Scope of Coverage: The specialist will work across the capital markets ecosystem, including FIIs, FPIs, brokers, custodians, clearing and settlement interfaces, exchanges, depositories, market infrastructure institutions, technology service providers, outsourcing partners, and internal IT, Security, Risk, Compliance, Legal, Operations, and Audit stakeholders.
Role Alignment and Operating Context
- The role will combine capital markets regulatory compliance, international client governance, CSCRF readiness, FII/FPI ecosystem coordination, and client-facing assurance activities.
- The role will require close coordination with Security, Risk, Compliance, Operations, Audit, client-servicing teams, external auditors, regulators, international client stakeholders.
Communication, Integrity and Professional Attributes
- Excellent spoken and written English communication skills, with the ability to interact confidently and professionally with international clients, auditors, regulators, senior management, and cross-functional stakeholders.
- Strong ability to draft clear client responses, regulatory updates, audit clarifications, meeting notes, compliance summaries, dashboards, and executive-level status reports.
- High level of integrity, discretion, and professional maturity, given the role's exposure to sensitive data, regulatory information, security findings, incident details, and confidential business information.
- Pragmatic, solution-oriented, and commercially aware mindset with the ability to navigate ambiguity, coordinate with multiple stakeholders, follow through assertively, and drive actions to closure with minimal supervision.
- Strong ownership mindset, attention to detail, responsiveness, and ability to balance regulatory discipline with business and client-service expectations.
Key Responsibilities
- Lead and manage end-to-end execution of SEBI CSCRF compliance assessments for Foreign Institutional Investors (FIIs), including stakeholder coordination, regulatory communication, control assessment, evidence validation, compliance monitoring, and audit readiness activities.
- Prepare and maintain audit-ready documentation, facilitate internal, external, and regulatory audit engagements, address auditor queries, and track compliance status, observations, remediation plans, and closure activities.
- Act as a client-facing cybersecurity and compliance representative for international clients, ensuring timely, clear, and professional communication on CSCRF readiness, audit responses, security controls, incident updates, and regulatory compliance matters.
- Conduct security assessments of critical technology assets, including Network and Security Infrastructure Devices, Endpoints and Servers, Business Applications and Supporting Environments.
- Review and validate Security Information and Event Management (SIEM) log integration and monitoring coverage to ensure adequate visibility across critical systems and security controls.
- Analyse and maintain cybersecurity risk and assurance artefacts, including assessment reports, audit findings, remediation trackers.
- Ensure compliance with SEBI CSCRF requirements and other applicable regulatory circulars, standards, and cybersecurity obligations.
- Handle sensitive client, security, and regulatory information with strict confidentiality, integrity, and adherence to internal information security and data protection requirements.
Required Domain Expertise
- Strong working knowledge of SEBI CSCRF, SEBI cybersecurity circulars, CERT-In requirements, RBI/SEBI cyber expectations, ISO 27001, NIST CSF, CIS Controls, and industry cyber resilience practices.
- Deep understanding of capital markets operations, including trading, clearing, settlement, custody, FII/FPI onboarding, client reporting, third-party connectivity, and regulatory submissions.
- Hands-on experience in cybersecurity governance, risk assessment, control testing, audit coordination, vulnerability management, and regulatory compliance monitoring.
- Ability to interpret regulatory circulars, translate them into actionable controls, prepare compliance roadmaps, and coordinate implementation across technology and business teams.
- Experience working with international clients, global control expectations, cross-border data considerations, outsourcing oversight, and client due-diligence questionnaires.
- Strong client-facing communication capability, practical judgment, professional maturity, and ability to manage sensitive conversations with international clients and senior stakeholders.
Key Skills
- Strong understanding of SEBI CSCRF, cybersecurity governance, regulatory compliance, technology risk management, and audit assurance in capital markets.
- Ability to assess and validate controls across IAM, PAM, SIEM, vulnerability management, patch governance, endpoint security, network security, application security, BCP/DR, and third-party risk.
- Strong documentation and reporting skills, including preparation of client responses, audit evidence, compliance dashboards, remediation trackers, risk registers, executive summaries, and regulatory submissions.
- Excellent spoken and written English with the ability to communicate clearly with international clients, auditors, regulators, senior management, and cross-functional teams.
- Strong stakeholder-management skills with the ability to coordinate across IT, Security, Risk, Compliance, Legal, Operations, Audit, vendors, custodians, brokers, exchanges, depositories, client-servicing teams, and internal technology teams.
- Practical problem-solving ability, follow-up discipline, attention to detail, ownership mindset, and ability to work independently in a fast-paced and regulated environment.
- High integrity, confidentiality, and professional maturity in handling sensitive client data, security evidence, incident information, regulatory documents, and internal control observations.
Preferred Certifications
- CISSP, CISM, CISA, CRISC, or equivalent cybersecurity governance, audit, and risk management certification.
- ISO 27001 Lead Auditor or ISO 27001 Lead Implementer certification.
- CEH, CompTIA Security+, or equivalent foundational / practitioner-level cybersecurity certification.
- Cloud security certifications such as CCSP, AWS Security Specialty, Azure Security Engineer Associate, or equivalent will be an added advantage.
- Privacy, data protection, third-party risk, business continuity, or cyber resilience certifications will be preferred for roles involving international client data and regulatory assurance.
Qualifications and Experience
- Bachelors or Masters degree in Information Technology, Computer Science, Cybersecurity, Engineering, or related discipline; postgraduate qualification preferred.
- 5-7 years of experience in cybersecurity, technology risk, regulatory compliance, IT audit, or security governance, preferably within capital markets, broking, custody, investment management, banking, or financial services.
- Professional certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor/Implementer, CEH, or equivalent are preferred.
- Prior experience in SEBI-regulated environments, FII/FPI servicing, regulatory inspections, cyber audits, client due diligence, or third-party risk assessments will be highly valued.
- Excellent written and spoken English is mandatory, given the regular interaction with international clients, auditors, regulators, and senior stakeholders.
Key Deliverables and Success Measures
- Complete periodic SEBI CSCRF compliance assessments within agreed timelines, including control mapping, evidence collection, validation, gap identification, and management sign-off.
- Maintain an audit-ready CSCRF compliance repository covering policies, procedures, architecture diagrams, asset inventories, control evidence, risk registers, remediation trackers, incident records, BCP/DR evidence, and regulatory submissions.
- Ensure timely closure of audit observations, cyber control gaps, vulnerability findings, privileged access exceptions.
- Deliver accurate regulatory and management reporting, including compliance dashboards, exception reports, remediation status, and senior management updates.
- Coordinate effectively with international clients, FIIs/FPIs, custodians, brokers, exchanges, depositories, auditors, regulators, technology vendors, and internal governance teams to ensure smooth compliance execution.
- Build effective working relationships with Technology, Application, Infrastructure, ISG, and Network teams to ensure timely evidence submission, control validation, issue resolution, and implementation of agreed remediation actions.
- Maintain consistently professional, accurate, and timely written and verbal communication with international clients and internal stakeholders, including client responses, audit clarifications, status updates, and governance reports.
- Demonstrate high integrity and zero-tolerance discipline in handling client data, security evidence, confidential documents, regulatory information, and incident-related details.