Job Title:Head ofTechnologyRisk & Info Sec Governance
Job Summary:The Head ofTechnologyRisk& Info Sec governance will be responsible for overseeing and managing thetechnologyriskframework within the organization and governance matters around Information Security. This role involves
- identifying, assessing, and mitigatingrisks associated with the use oftechnologyin business operations
- providing an integrated risk framework around all aspects of cyber & tech risk including resilience, continuity, vendors, security etc. through governance on these matters
- ensuring compliance to internal policy and regulatory aspects of cyber security and technology risk
- This includes ensuring Compliance tracking support to infosec teams by tracking regulatory guidelines, ensuring data collation, review and timely submission of daily / monthly / quarterly returns.
- This includes ensuring handling regulatory, compliance and audit interactions and addressing key actionables from such processes and closure of observations that may come from such interactions.
- ensuring risks are reviewed and escalated
The ideal candidate will have a strong background inoperations & technologyriskmanagement, cybersecurity, and compliance, with the ability to lead a team and collaborate with various stakeholders to ensure the organization'stechnologyinfrastructure is secure and resilient.
Key Responsibilities: overseeing the following three aspects of technology risk & information security governance
- Technology Risk
- Develop and implement a comprehensivetechnologyriskmanagement framework.
- Identify, assess, and prioritizetechnologyrisks across the organization.
- Collaborate with IT, cybersecurity, and business units to developriskmitigation strategies.
- Monitor and report on the effectiveness ofriskmanagement initiatives.
- Ensure compliance with relevant regulations and industry standards.
- Lead and mentor a team oftechnologyriskprofessionals.
- Conduct regularriskassessments and audits.
- Stay updated on emergingtechnologyrisks and trends.
- Communicateriskmanagement strategies and policies to senior management and stakeholders.
- IS Compliance
- Coordinating with various infosec teams and stakeholders to collect and verify the necessary data for regulatory advisories, s, circulars, questionnaires, and correspondences
- Maintaining the Advisory Digest document and updating it regularly with the latest information on cyber security incidents, best practices, and recommendations from regulators and authorities
- Ensuring timely and accurate submission of daily, monthly, and quarterly returns to the relevant regulators and authorities, such as CERT-In, NCIIPC, SEBI, PFRDA, etc.
- Tracking and managing the NCIIPC correspondences and compliance requirements, and communicating with them on any issues or queries - Gathering the metrics related to Key Risk Indicators (KRI) and ensuring they are aligned with the infosec framework and objectives
- Responding to the CERT-In technical advisory correspondences and compliance requirements, and implementing the suggested actions and measures
- Coordinating for the CII-ISSC meeting activities and handling adhoc data requirements from various regulators and authorities
- Acting as the infosec spoc for Business Continuity Planning (BCP) and Functional Recovery Planning (FRP), and conducting periodic infosec BIA and coordinating for planned/unplanned BCP
- Tracking all ATRs from all the committees (ITDSC, ISSC, AOP, ITSC, etc.), where ISS is the action owner, and ensuring the action plans are adequately documented, executed, and reported
- Tracking the infosec deliverable calendar across the unit and proactively identifying and resolving any delays or issues, and ensuring the delivery of all activities within timeline
- Compliance, Audit and Risk office
- Respond to RBI queries during annual RBS audit.
- Co-ordinate for all the activities related to Risk Based Supervision / other regulatory inspections including the submission of data / documents and represent the department for all the queries raised during the RBI inspections.
- Formulate responses to RAR observations from RBI
- Keep abreast with the regulatory changes and ensure dissemination and Implementation of regulations / amendments / actionable/ compliance communication in line with the milestones committed and within the timelines prescribed by regulators / internal timelines.
- Design new processes/ controls to address gaps highlighted by Operational Risk after risk assessment exercise and IAD after audit review
- Review of Policies pertaining to Information Security and Technology Risk in alignment with the regulatory guidelines
- Monitoring the Compliance Risk / Operational risk dashboards / risk movements of assessment units and flagging of the concerns to Head of the Department.
- Provide regular updates to Segment Heads and Senior Management on status of implementation of Risk Mitigation Plan advised by RBI through weekly dashboards and bi-monthly RMP meeting with all Department Heads and MANCOM members.
Qualifications:
- MBA from a reputed institution
- Bachelor's degree in InformationTechnology, Computer Science, or a related field., and certifications around information security would be an additional benefit.
- Proven experience of 15 - 20 years inoperational risk management, technologyriskmanagement, cybersecurity, and compliance.
- Strong understanding of regulatory requirements and industry standards.
- Excellent leadership and team management skills.
- Strong analytical and problem-solving abilities.
- Effective communication and interpersonal skills.
- Ability to work collaboratively with cross-functional teams.
Preferred Skills:
- 15-20 years Experience in financial services or a related industry.
- Knowledge ofoperational, technology and cyber security riskmanagement frameworks
- Familiarity with cloud computing, data privacy, and emerging technologies