10 Sep
|
TVS Credit Services
|
Chennai
10 Sep
TVS Credit Services
Chennai
Key Responsibilities:Security Strategy & Governance
- Develop and implement the organization's comprehensive information security strategy and roadmap.
- Ensure compliance with IRDAI regulations, ISO 27001, and other applicable security standards.
- Define, update, and enforce security policies, procedures, and best practices.
Cloud Security (AWS)
- Design, implement, and continuously monitor security controls within AWS environments.
- Conduct threat modeling, vulnerability assessments, and security audits.
- Manage AWS IAM roles, security groups, encryption mechanisms, and Key Management Services (KMS).
Application Security
- Perform secure code reviews and guide development teams on best practices for secure coding.
- Integrate security testing tools such as SAST and DAST into the SDLC process.
- Conduct manual security assessments and collaborate with product and engineering teams to remediate vulnerabilities proactively.
Endpoint & Network Security
- Deploy, manage, and monitor endpoint detection and response (EDR) and antivirus solutions.
- Implement and maintain network security controls including firewalls, VPNs, IDS/IPS, and segmentation.
- Monitor network configurations and detect anomalous activity.
Email Security
- Implement and manage email security protocols (SPF, DKIM, DMARC) and anti-phishing tools.
- Monitor for email-based threats such as phishing and malware campaigns.
- Conduct phishing simulations and deliver employee training on email security.
Data Loss Prevention & Zero Trust
- Implement DLP solutions to prevent unauthorized data sharing and leaks.
- Design and enforce zero trust security models, focusing on identity-based access and continuous verification.
Vulnerability Management
- Establish and run a vulnerability management program involving regular scans, prioritization, and patching.
- Collaborate with engineering to remediate vulnerabilities promptly.
- Track and report on vulnerability closure and risk mitigation.
Risk Management & Incident Response
- Maintain risk assessment processes and a risk register.
- Develop and execute incident response plans, lead investigations, and ensure timely resolution.
Stakeholder Communication
- Serve as the security liaison for internal teams, external partners, and auditors.
- Report security posture, risks, and mitigation status to senior leadership.
Security Awareness
- Conduct ongoing security training and awareness sessions for employees to foster a security-conscious culture.
Skills: Application Security, Incident Response, Regulatory Compliance
Experience: 7.00-12.00 Years
📌 Chief Information Security Officer (Chennai)
🏢 TVS Credit Services
📍 Chennai