Prudential s purpose is to be partners for every life and protectors for every future Our purpose encourages everything we do by creating a culture in which diversity is celebrated and inclusion assured for our people customers and partners We provide a platform for our people to do their best work and make an impact to the business and we support our people s career ambitions We pledge to make Prudential a place where you can Connect Grow and Succeed About the Job Prudential s purpose is to be partners for every life and protectors for every future Our purpose encourages everything we do by creating a culture in which diversity is celebrated and inclusion assured for our people customers and partners We provide a platform for our people to do their best work and make an impact to the business and we support our people s career ambitions We pledge to make Prudential a place where you can Connect Grow and Succeed At Prudential Health India PHI we are on a mission to make Indians healthier while bridging the health protection gap This is a Zero-to-One team undertaking a greenfield health insurance deployment in India committed to building journeys that truly empathise with the customer and offer a differentiated bespoke experience To partner us in this mission we are looking for a talented candidate for the role of Tech Risk Lead Note The title will depend on 1 Experience 2 Expertise and 3 Performance So the title could be Tech Risk Lead Senior Tech Risk Lead Associate Director Technology Risk People Manager Role Experience 10-18 years Location Mumbai Work Mode Work from office only Job Profile Summary The Tech Risk Lead will be responsible for establishing and leading the technology Risk function at PHI ensuring compliance with internal policies regulatory frameworks IRDAI GDPR HIPAA and global Prudential standards This role will oversee Risk trails vulnerability management and risk mitigation across PHI s cloud-native infrastructure and applications Develop and implement a comprehensive technology Risk strategy and annual Risk plan aligned with PHI s business and regulatory requirements Conduct risk-based Risks across infrastructure applications data platforms and security controls Ensure complete and tamper-proof Risk trails of user activities data changes and system events Collaborate with InfoSec DevSecOps and AppSec teams to validate remediation of vulnerabilities and ensure patch compliance Lead privacy impact assessments penetration testing reviews and security onboarding for recent applications Monitor and report on the implementation of Risk recommendations and track remediation progress Maintain documentation and Risk logs in accordance with professional standards and Prudential Group policies Support investigations into technology-related incidents control breaches or compliance failures Present Risk findings and risk assessments to senior leadership and the Risk Committee Stay updated on emerging risks regulatory changes and best practices in technology Risk and governance Develop and maintain risk registers and mitigation plans Monitor emerging risks cloud AI third-party integrations Collaborate with architecture and security teams to embed controls Support risk reporting and governance forums Conduct impact analysis and scenario modelling Align risk controls with Prudential Group standards and regulatory expectations Work with product and engineering teams to ensure risk-aware design and delivery Maintain risk dashboards metrics and control effectiveness reports Security Compliance TechnologiesImplement and Risk SAST DAST and SCA scanning tools and processes Ensure secure integration of CI CD pipelines using Checkmarx GitHub GitHub Actions HashiCorp Vault and Azure AD Oversee onboarding and compliance of WAF Web Application Firewall solutions including Imperva API Security and DDoS WAAP protection Validate controls for privileged access management using tools like CyberArk Ensure compliance with data classification encryption standards and endpoint protection policies Who We Are Looking For Technical Skills Work ExperienceBachelor s in Engineering Computer Science or equivalent certifications in CISA CISSP or ISO 27001 are a plus 10-18 years of experience in technology Risk risk management or compliance preferably in insurance or financial services Strong understanding of GCP CI CD pipelines DevSecOps and infrastructure as code Experience with tools such as Checkmarx GitHub Azure AD HashiCorp Vault CyberArk and Imperva Familiarity with SQL and NoSQL databases encryption standards and data classification frameworks Proven ability to lead cross-functional Risk engagements and manage stakeholder expectations Familiarity with enterprise risk frameworks COSO NIST Experience in risk modelling and impact analysis Exposure to cloud risk data privacy and third-party risk domains Understanding of DevSecOps and secure SDLC practices Experience with risk tooling and control libraries Personal TraitsStrategic thinker with strong analytical and investigative skills High integrity and ethical standards Excellent communication and presentation skills Ability to work independently and manage multiple concurrent Risks Strong attention to detail and documentation discipline What Can Make You Extra SpecialExperience in setting up Risk functions in greenfield environments Exposure to IRDAI Risks and regulatory inspections Familiarity with centralised vulnerability dashboards and build breaker enforcement Experience with public-facing application security DDoS WAAP onboarding and penetration testing workflows Language Fluent written and spoken English Equal Opportunity Statement Prudential is an equal opportunity employer We provide equality of opportunity and benefits for all who apply and perform work for our organisation irrespective of sex race age ethnic origin educational social and cultural background marital status pregnancy and maternity religion or belief disability part-time fixed-term work or any other status protected by applicable law Prudential is an equal opportunity employer We provide equality of opportunity of benefits for all who apply and who perform work for our organisation irrespective of sex race age ethnic origin educational social and cultural background marital status pregnancy and maternity religion or belief disability or part-time fixed-term work or any other status protected by applicable law We encourage the same standards from our recruitment and third-party suppliers taking into account the context of grade job and location We also allow for reasonable adjustments to support people with individual physical or mental health requirements