Associate General Manager - IT Risk & Compliance (India)

Associate General Manager - IT Risk & Compliance (India)

23 Aug
|
Voya Financial
|
India

23 Aug

Voya Financial

India

About Voya:

Voya India (earlier VFISLK) started out as a joint venture between U.S. financial services company Voya Financial and SLK, a software services company and is head quartered at Bangalore. As of Aug 2023, we are a wholly owned subsidiary of Voya Financial. We are a agile technology & business process transformation company that provides world-class technology & business process management services, with an emphasis on quality, speed & optimization driven through automation.

We support and deliver innovative solutions to Voya’s Retirement, Employee Benefits, and Investment Management businesses.

More information about us is available at: https://www.voyaindia.com

Role Summary:

We are seeking a strategic technology risk leader to manage the IT Risk Management function. The role will establish and strengthen enterprise-wide governance across artificial intelligence, cloud security, configuration management, cybersecurity risk, regulatory compliance, and technology assurance. The risk leader will partner with senior business and technology leaders to identify, assess, monitor, and mitigate technology risks while enabling secure innovation and digital transformation

Roles & Responsibility:

a. IT Risk & Governance

Design, implement, and continuously improve the enterprise IT risk management framework, policies, and standards.

Conduct IT risk assessments across infrastructure, applications, third parties, and emerging technologies.Drive risk reporting, dashboards, and heat maps for senior leadership and Board-level committees.

Ensure alignment with regulatory and compliance requirements (ISO 27001, NIST, RBI/SEBI/IRDAI guidelines as applicable, SOX, GDPR, etc.).

Lead internal/external IT audits, regulatory inspections, and remediation tracking.

b. AI Governance & Responsible AI





Define and operationalize an enterprise AI Governance framework covering AI and generative AI use cases.

Establish lifecycle governance for AI solutions, including intake, risk classification, approval, testing, monitoring, and retirement.

Lead assessments covering security, privacy, bias, explainability, model integrity, ethical use, and regulatory compliance.

Partner with Legal, Compliance, Cybersecurity, Data, Technology, and business teams to support responsible AI adoption.

Monitor evolving AI regulations, standards, and industry practices, and translate them into actionable governance requirements.

c. Cloud Security & Technology Risk

Provide risk oversight for public, private, hybrid, and multi-cloud environments, including Azure, AWS, and GCP.

Define cloud security governance requirements for identity and access, encryption, logging, vulnerability management, resilience, and secure configuration.

Oversee cloud risk assessments, architecture reviews, control testing, third-party evaluations, and remediation of security gaps.

Drive adoption of continuous cloud security posture monitoring and risk-based reporting.

d. CMDB Governance & Configuration Management

Own the enterprise CMDB governance framework and configuration management strategy.

Improve the completeness, accuracy, timeliness, ownership, and integrity of configuration item data and relationships.

Establish CMDB health metrics, data quality controls, reconciliation practices, accountability standards, and exception management.

Partner with application, infrastructure,



service management, asset management, change, incident, and resilience teams to strengthen service mapping and risk visibility.

Drive automation of discovery, configuration tracking, reconciliation, and control monitoring.

e. Cybersecurity Risk, Compliance & Assurance

Oversee cybersecurity risk assessments, control evaluations, technology assurance reviews, and remediation governance.

Ensure alignment with applicable laws, regulations, industry standards, contractual obligations, and internal policies.

Support internal and external audits, regulatory examinations, control testing, and evidence-based closure of findings.

Monitor emerging cyber and technology risks and translate insights into prioritized actions.

f. Leadership & Stakeholder Management

Build, lead, and develop a high-performing technology risk team with clear accountability and succession plans.

Partner with CIO, CISO, CRO, Compliance, Internal Audit, Engineering, Architecture, Operations, and business leadership.

Influence strategic decisions through practical, risk-based recommendations that balance protection, compliance, customer outcomes, and innovation.

Promote a proactive risk culture through awareness, challenge, governance, and transparent reporting.

Primary Skill:

IT Risk Management

Qualifications:

Bachelor’s degree in computer science, Information Technology, Cybersecurity, Engineering, Risk Management, or a related discipline; a master's degree or MBA is preferred.

Certification:

CRISC, CISM, CISSP, CGRC, or equivalent risk and security certification.

CCSP, AWS Security Specialty, Azure Security Engineer, or equivalent cloud security certification.

ITIL 4, COBIT, ISO 27001 Lead Implementer / Lead Auditor, or ServiceNow certifications.

Location:

Bangalore/Pune

📌 Associate General Manager - IT Risk & Compliance (India)
🏢 Voya Financial
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: associate general manager - it risk & compliance (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: associate general manager - it risk & compliance (india) / india