10 Sep
|
tvs credit services
|
Chennai
10 Sep
tvs credit services
Chennai
Key Responsibilities:
Security Strategy & Governance
Develop and implement the organization's comprehensive information security strategy and roadmap.
Ensure compliance with IRDAI regulations, ISO 27001, and other applicable security standards.
Define, update, and enforce security policies, procedures, and best practices.
Cloud Security (AWS)
Design, implement, and continuously monitor security controls within AWS settings.
Conduct threat modeling, vulnerability assessments, and security audits.
Manage AWS IAM roles, security groups, encryption mechanisms, and Key Management Services (KMS).
Application Security
Perform secure code reviews and guide development teams on best practices for secure coding.
Integrate security testing tools such as SAST and DAST into the SDLC process.
Conduct manual security assessments and collaborate with product and engineering teams to remediate vulnerabilities proactively.
Endpoint & Network Security
Deploy, manage, and monitor endpoint detection and response (EDR) and antivirus solutions.
Implement and maintain network security controls including firewalls, VPNs, IDS/IPS, and segmentation.
Monitor network configurations and detect anomalous activity.
Email Security
Implement and manage email security protocols (SPF, DKIM, DMARC)
and anti-phishing tools.
Monitor for email-based threats such as phishing and malware campaigns.
Conduct phishing simulations and deliver employee training on email security.
Data Loss Prevention & Zero Trust
Implement DLP solutions to prevent unauthorized data sharing and leaks.
Design and enforce zero trust security models, focusing on identity-based access and continuous verification.
Vulnerability Management
Establish and run a vulnerability management program involving regular scans, prioritization, and patching.
Collaborate with engineering to remediate vulnerabilities promptly.
Track and report on vulnerability closure and risk mitigation.
Risk Management & Incident Response
Maintain risk assessment processes and a risk register.
Develop and execute incident response plans, lead investigations, and ensure timely resolution.
Stakeholder Communication
Serve as the security liaison for internal teams, external partners, and auditors.
Report security posture, risks, and mitigation status to senior leadership.
Security Awareness
Conduct ongoing security training and awareness sessions for employees to foster a security-conscious culture.
📌 Chief Information Security Officer Chennai
🏢 tvs credit services
📍 Chennai