15 Aug
|
Reserve Bank Information Technology
|
Navi Mumbai
15 Aug
Reserve Bank Information Technology
Navi Mumbai
Role & responsibilities.
Perform data flow and architecture review of application and identify threats (may use threat modelling)
Review multiple documents related to application such as SRS, BCP, HLD, LLD and should be able to identify security control gaps as per global standards (OWASP/ ITGC / NIST CSF)
Prepare platform, COTS, API, AI, Microservices and application security assessment control checklist to be considered and aligned to global standards and industry best practices.
Prepare risk reports and project tracking for risk observations and compliance.
Should be able to provide recommendation and compensatory controls to reduce cyber security risk level.
Communicate effectively with project managers, application owners, customers and stakeholders.
Advises management of critical issues that may affect the overall project deliverables and risk posture of application.
Demonstrate skills with upgrading knowledge quickly and transferring it to peers.
Preferred candidate profile.
A minimum experience of 7 - 9 years in cyber security with relevant of 5 years in web application, mobile application, Artificial intelligence (AI), API, COTS, Platform, Microservices security risk assessment.
In depth understanding of existing global standards for information / cyber security such as ITGC, ISO, NIST CSF, OWASP and BCP
Understanding of application, database, API and zero trust architecture
Holistic risk approach and security control proficiency with respect to people, process and technology aspects
Valuable hold and understanding of security practices in application and microservices product development
Ability to identify cyber security risk and threats based on overall workplace,platform of application and third-party vendor security risk.
Should be proficient in identifying security control implementation gaps in application authentication, authorisation and data security.
Excellent verbal and written communication skills is mandatory with customer or stakeholder interaction exposure.
Must be able to articulate risk observation in detail and easy understandable language and explain the security risk observations and reason for severity mapping to customer.
Should be able to provide solution and remediation for non-compliance observations to development team and support closure.
Desirable if candidate has experience in auditing roles.
📌 Cyber Security Lead Navi Mumbai
🏢 Reserve Bank Information Technology
📍 Navi Mumbai