Roles and Responsibilities:
- Ensure Compliance with the Regulatory requirements w.r.t the Information and Cyber Security requirements - RBI, UIDAI, CIC, etc.
- Identify and develop the InfoSec Policy, Processes, and Procedures to incorporate the industry benchmarks / best practices and the latest trends.
- To identify, track, monitor & ensure compliance with InfoSec Policy, Regulatory, Legal & Audit requirements.
- To develop & manage InfoSec Training & awareness.
- Work with respective stakeholders to ensure that the Policy/Procedures, regulatory, legal & audit requirements for Information and cyber security are understood and implemented on a continual basis.
- Monitor & track the compliance to all relevant processes/practices to ensure that they are followed as desired.
- Liaison with internal and external Security Audits and assessments – VAPT, GDPR/ISO 27001 compliance.
- Establish continual improvement processes to mitigate identified gaps & improve overall maturity to provide adequate assurance.
- Establish security metrics based on agreed KGIs/KPIs to monitor & track compliance.
- Escalate deviations and violations on time.
- Remain updated with the latest security trends and related regulatory & legal requirements.
- To maintain the required security posture for cloud security, primarily AWS & GCP
- To maintain & improve code security & DevopsSec practices
- To maintain & improve the endpoint security, by bringing in DLP and data classification practices.
- To review and improve email, apps & network security.
- To run periodic phishing campaigns.
- To respond third-party risk assessment questionnaire
- Perform Independent Internal Audit and assessment in line with Regulatory requirements - RBI, UIDAI, CIC, V-CIP, DLG, etc.
Key Skills and Qualifications
- Bachelor of Engineering/Computer Science or equivalent from a recognized University
- The ability to interact efficiently with peers and customers is required.
- 4-6 years with relevant experience in est