04 Aug
|
Aditya Birla Housing Finance
|
Maharashtra
04 Aug
Aditya Birla Housing Finance
Maharashtra
Role & responsibilities
- Develop, maintain and align Information Security policies, standards, SOPs and procedures with regulatory requirements, business objectives and industry best practices; run the policy renewal tracker and secure timely approvals.
- Establish and maintain an Enterprise Information Security Governance and IT Risk Management program with continuous monitoring and risk mitigation, in line with ISO 27001:2022, NIST CSF, CIS and DPDP Act.
- Conduct Information Security assessments and technology due diligence for new/existing projects and applications review solution architecture, data flows and controls on a Secure-by-Design basis, perform threat modelling, assess gaps and residual risk, and provide initial and final production sign-offs.
- Lead the Enterprise Vulnerability Management program govern application security assessments, infrastructure VA, configuration reviews, prioritise by risk/exploitability, manage exceptions and drive timely closure.
- Govern application & API security assess applications against InfoSec/AppSec checklists, oversee VA, PT and secure code reviews, application-layer attack mitigation and DevSecOps integration.
- Review, maintain and govern Minimum Baseline Security Standards (MBSS) / Secure Configuration Documents (SCD) and drive configuration compliance and closure.
- Implement and oversee cloud security best practices across AWS & Azure IAM, encryption, network security, logging and monitor CNAPP tooling (CSPM, CIEM, CWPP); conduct cloud security assessments, gap and compliance reviews for IaaS/PaaS/SaaS.
- Oversee governance and operational management of security tools — SIEM, EDR, DLP, WAF, IDS/IPS — including SIEM asset onboarding, monthly reconciliation, use-case/detection enhancement and alert closure with the SOC.
- Own security incident management — detection, logging, triage, RCA, mitigation, monthly incident reporting and a learning matrix that drives preventive controls.
- Participate in CAB / change management — assess security implications of planned and emergency changes and approve, reject or recommend additional controls.
- Manage internal, statutory, regulatory and certification audits — coordinate evidence, provide management responses and remediation plans, and track observations to closure; address queries from Compliance, Internal/External Audit and Regulators.
- Oversee BCP & DR governance — maintain the annual DR drill calendar, govern drills for critical applications/infrastructure, validate RTO/RPO and close observations (BIA, BCRA, FRP, IT DR drills).
- Drive Vendor Risk Assessment (VRA) and Third-Party Risk Management (TPRM) — vendor inventory & criticality, annual review calendar, assessments, risk ratings and closure.
- Run security awareness & cyber resilience programs — monthly campaigns, annual training, phishing simulations with targeted remediation, and annual CCMP tabletop / incident-response simulations.
- Prepare and present executive & governance reporting for ITSC, IT Strategy Committee, RMC and Board — consolidating InfoSec metrics, risk dashboards, KPI/KRI, compliance status, audit updates and incident summaries; track decisions and action closure.
Preferred candidate profile
- Strong, hands-on experience with security governance frameworks — ISO 27001:2022, NIST CSF, CIS, SOC 2.
- Cloud security (AWS & Azure) — IAM, VPC, Security Groups, KMS, network security best practices and CNAPP (CSPM, CIEM, CWPP).
- Working knowledge / hands-on with security tooling — SIEM (Splunk, ELK, Sentinel), EDR, DLP, WAF and security monitoring.
- Deep understanding of application security — OWASP Top 10, SANS Top 25, API security, mobile app security and DevSecOps.
- Experience in incident response, forensic investigation and security automation.
- Exposure to BFSI/NBFC regulatory setting (RBI, NHB, DPDP Act) and audit management.
- Strong analytical, problem-solving and decision-making ability, with a proven capability to collaborate across cross-functional teams and articulate risk to senior/Board audiences.
📌 Lead : Information Security Governance (Maharashtra)
🏢 Aditya Birla Housing Finance
📍 Maharashtra