Search by job, company or skills

ISS:Head - Information Security Governance & Technology Risk

15-20 Years
Early Applicant
  • Posted 12 hours ago
  • Be among the first 10 applicants

Job Description

Job Title:Head ofTechnologyRisk & Info Sec Governance

Job Summary:The Head ofTechnologyRisk& Info Sec governance will be responsible for overseeing and managing thetechnologyriskframework within the organization and governance matters around Information Security. This role involves

  • identifying, assessing, and mitigatingrisks associated with the use oftechnologyin business operations
  • providing an integrated risk framework around all aspects of cyber & tech risk including resilience, continuity, vendors, security etc. through governance on these matters
  • ensuring compliance to internal policy and regulatory aspects of cyber security and technology risk
    • This includes ensuring Compliance tracking support to infosec teams by tracking regulatory guidelines, ensuring data collation, review and timely submission of daily / monthly / quarterly returns.
    • This includes ensuring handling regulatory, compliance and audit interactions and addressing key actionables from such processes and closure of observations that may come from such interactions.
  • ensuring risks are reviewed and escalated

The ideal candidate will have a strong background inoperations & technologyriskmanagement, cybersecurity, and compliance, with the ability to lead a team and collaborate with various stakeholders to ensure the organization'stechnologyinfrastructure is secure and resilient.

Key Responsibilities: overseeing the following three aspects of technology risk & information security governance

  1. Technology Risk
  • Develop and implement a comprehensivetechnologyriskmanagement framework.
  • Identify, assess, and prioritizetechnologyrisks across the organization.
  • Collaborate with IT, cybersecurity, and business units to developriskmitigation strategies.
  • Monitor and report on the effectiveness ofriskmanagement initiatives.
  • Ensure compliance with relevant regulations and industry standards.
  • Lead and mentor a team oftechnologyriskprofessionals.
  • Conduct regularriskassessments and audits.
  • Stay updated on emergingtechnologyrisks and trends.
  • Communicateriskmanagement strategies and policies to senior management and stakeholders.
  1. IS Compliance
  • Coordinating with various infosec teams and stakeholders to collect and verify the necessary data for regulatory advisories, s, circulars, questionnaires, and correspondences
  • Maintaining the Advisory Digest document and updating it regularly with the latest information on cyber security incidents, best practices, and recommendations from regulators and authorities
  • Ensuring timely and accurate submission of daily, monthly, and quarterly returns to the relevant regulators and authorities, such as CERT-In, NCIIPC, SEBI, PFRDA, etc.
  • Tracking and managing the NCIIPC correspondences and compliance requirements, and communicating with them on any issues or queries - Gathering the metrics related to Key Risk Indicators (KRI) and ensuring they are aligned with the infosec framework and objectives
  • Responding to the CERT-In technical advisory correspondences and compliance requirements, and implementing the suggested actions and measures
  • Coordinating for the CII-ISSC meeting activities and handling adhoc data requirements from various regulators and authorities
  • Acting as the infosec spoc for Business Continuity Planning (BCP) and Functional Recovery Planning (FRP), and conducting periodic infosec BIA and coordinating for planned/unplanned BCP
  • Tracking all ATRs from all the committees (ITDSC, ISSC, AOP, ITSC, etc.), where ISS is the action owner, and ensuring the action plans are adequately documented, executed, and reported
  • Tracking the infosec deliverable calendar across the unit and proactively identifying and resolving any delays or issues, and ensuring the delivery of all activities within timeline
  1. Compliance, Audit and Risk office
  • Respond to RBI queries during annual RBS audit.
  • Co-ordinate for all the activities related to Risk Based Supervision / other regulatory inspections including the submission of data / documents and represent the department for all the queries raised during the RBI inspections.
  • Formulate responses to RAR observations from RBI
  • Keep abreast with the regulatory changes and ensure dissemination and Implementation of regulations / amendments / actionable/ compliance communication in line with the milestones committed and within the timelines prescribed by regulators / internal timelines.
  • Design new processes/ controls to address gaps highlighted by Operational Risk after risk assessment exercise and IAD after audit review
  • Review of Policies pertaining to Information Security and Technology Risk in alignment with the regulatory guidelines
  • Monitoring the Compliance Risk / Operational risk dashboards / risk movements of assessment units and flagging of the concerns to Head of the Department.
  • Provide regular updates to Segment Heads and Senior Management on status of implementation of Risk Mitigation Plan advised by RBI through weekly dashboards and bi-monthly RMP meeting with all Department Heads and MANCOM members.

Qualifications:

  • MBA from a reputed institution
  • Bachelor's degree in InformationTechnology, Computer Science, or a related field., and certifications around information security would be an additional benefit.
  • Proven experience of 15 - 20 years inoperational risk management, technologyriskmanagement, cybersecurity, and compliance.
  • Strong understanding of regulatory requirements and industry standards.
  • Excellent leadership and team management skills.
  • Strong analytical and problem-solving abilities.
  • Effective communication and interpersonal skills.
  • Ability to work collaboratively with cross-functional teams.

Preferred Skills:

  • 15-20 years Experience in financial services or a related industry.
  • Knowledge ofoperational, technology and cyber security riskmanagement frameworks
  • Familiarity with cloud computing, data privacy, and emerging technologies

About Company

Job ID: 152204555

Beware of Scammers

We don’t charge money for job offers