● Develop and finalize policies, procedures, and guidelines related to IT and Infosec domains in alignment with industry best practices (ISO 27001 , GDPR and SOC 2)
● Align internal IT and Infosec processes as per ISO 27001 and SOC 2 standards and security guidelines
● Assist in defining and reviewing the key metrics for management reporting
● Develop of cyber security standards, including incorporating industry practices and applicable compliance requirements
● Maintain the the security risk register and related policies
● Maintain the inventory of IT vendors as per regulatory guidelines.
● Develop review checklists, questionnaire, and manage evidences to assist the IT vendor risk management process
● Perform 3rd party security due-diligence reviews and periodic vendor risk assessments to assess vendor compliance.
● Coordinate with external stakeholders and auditors for IT and Infosec related reviews
● Coordinate for conducting periodic penetration testing exercises on in-scope applications and related infrastructure.
Coordinate with stakeholders for timely closure of open risks.
● Assist in imparting security awareness training and executing phishing simulation exercises to employees.
● Assist IT and Infosec in gathering the metrics data and prepare management dashboards
● Lead the periodic IT and Infosec governance review meetings and gather feedback for improvement
● Assess the existing IT and Infosec processes and provide recommendations to improve
● Identify opportunities for IT and Infosec governance automation and lead the continuous compliance initiatives
● Support cross-entity teams/group entities to mirror the best practices implemented at the parent entity
● Develop templates for incident reporting and manage artifacts. Assist during incident investigation and collaborating with stakeholders.
● Audit Coordination:
○ Coordinate and facilitate SOC 2 audits, acting as the primary point of con