Role - Information Security Officer
Experience - 3-5 yrs
Location - Mumbai
Responsibilitie
- sOwn and drive information security governance, risk management, compliance, and audit readiness
- .Manage the audit and compliance calendar, including bank audits, regulatory reviews, partner reviews, security questionnaires, and external assessments
- .Maintain audit and compliance readiness for ISO 27001, PCI DSS, DL-SAR, CICRA, RBI Cyber Security Framework, Digital Lending Guidelines, DPDP/data privacy, and other applicable requirements
- .Maintain policies, procedures, risk registers, audit evidence, compliance trackers, security documentation, and closure reports
- .Conduct and coordinate internal reviews for access control, privileged access, policy compliance, vendor security, cloud security, and security configurations
- .Coordinate VAPT, source code reviews, cloud security reviews, configuration reviews, SAST/DAST activities, and remediation tracking
- .Work with Technology, DevOps, IT, Compliance, HR/Admin, vendors, and business teams to close vulnerabilities, audit findings, security gaps, incidents, and risks
- .Own and drive security incident response execution, including escalation coordination, RCA tracking, corrective actions, evidence documentation, closure reports, and periodic drills
.Required Skill
- sGood understanding of information security, GRC, IT risk, audits, compliance,
and cybersecurity controls
- .Working knowledge of application security, API security, cloud security, IAM, vulnerability management, incident response, secure SDLC, and vendor security
- .Understanding of ISO 27001, PCI DSS, RBI Cyber Security Framework, Digital Lending Guidelines, banking/fintech requirements, and data protection requirements
- .Ability to assess technical security risks, define controls, and coordinate remediation with technical teams
- .Solid audit handling, evidence management, documentation, communication, follow-up, and ownership
- .Ability to work independently with auditors, banks, vendors, technical teams, and business stakeholders
.Required Qualificatio
- n3–5years of experience in information security, GRC, IT risk, cybersecurity coordination, audit, or compliance
- .Experience handling bank audits, regulatory audits, ISO 27001, PCI DSS, VAPT coordination, access reviews, risk registers, audit evidence, and remediation tracking is preferred
- .Experience in fintech, banking, NBFC, payments, lending, or regulated technology environments is preferred
- .Bachelor’s degree in Computer Science, IT, Information Security, or a related field
- .Relevant certification preferred, such as ISO 27001 LA/LI, CISA, CISM, PCI DSS, ISO 27701, Security+, CEH, or equivalent
.
📌 Information Security Officer (Mumbai)
🏢 Recro
📍 Mumbai