Executive / Senior Executive-IT GRC & Information Security (Mumbai)

Executive / Senior Executive-IT GRC & Information Security (Mumbai)

15 Sep
|
Vastu Housing Finance
|
Mumbai

15 Sep

Vastu Housing Finance

Mumbai

Summary of the Role:

Support the Information Security and IT GRC function in maintaining regulatory compliance, running control assessments, and keeping policy, risk and audit documentation current across VHFC's IT and business systems. The role is execution-focused - evidence gathering, tracking, follow-up and reporting - working under the direction of the CISO and senior GRC team. The role also carries continuous monitoring of operational and engineering security controls - security operations, vulnerability and patch management, access, cloud posture and incident closure - reporting deviations and driving follow-up rather than owning remediation.

Main Responsibilities:

- Support compliance with RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices (2023), RBI Outsourcing of IT Services Directions (2023), NHB circulars and CERT-In directions.
- Maintain the IT policy and procedure library - track review cycles, consolidate stakeholder inputs and prepare drafts for approval.
- Perform periodic control testing and evidence collection; track internal audit, IS audit and regulatory inspection findings to closure.
- Conduct third-party / vendor security assessments and maintain the vendor risk register.
- Support user access reviews, security exception tracking and risk register upkeep.
- Assist with incident documentation, root cause tracking and regulatory reporting timelines.
- Support DPDP Act 2023 readiness - data inventory, consent records and breach response documentation.
- Prepare MIS and dashboards for the CISO, IT Steering Committee and Board sub-committees.
- Monitor day-to-day security operations - SIEM alerts,



the incident queue and reported phishing - and track triage, escalation and closure with the SOC / managed security service partner.
- Track vulnerability assessment and penetration testing cycles, patch compliance and secure configuration baselines across infrastructure, applications and endpoints, and follow up engineering remediation to closure.
- Monitor operational security hygiene - privileged access usage, backup and restoration testing, log retention, and endpoint, EDR and MDM coverage - and report deviations to the CISO.
- Monitor cloud security posture across OCI and AWS - identity and access, key management, network exposure and logging - and escalate configuration drift to the infrastructure and engineering teams.
- Check security gates in change and release activity - secure SDLC checks, pre-go-live sign-off and DR drill evidence - and maintain the record of exceptions and their compensating controls.

Profile Required: Academic background and certifications, experience:

- Graduate in Computer Science, IT, Engineering or equivalent.
- 3 - 4 years of experience in IT GRC, information security compliance or IS audit preferably in BFSI (bank, NBFC or HFC).
- Certification such as ISO 27001 Lead Auditor, CISA, CRISC, or a privacy certification (DCPP / CIPP) - held or in progress. Preferred, not mandatory.





Operational Skills:

- Working knowledge of RBI and NHB IT and cyber security regulations, and ISO 27001 control structure.
- Basic understanding of data privacy principles and DPDP Act 2023 obligations.
- Familiarity with core security controls - access management, patching, logging and monitoring, backup, network and endpoint security.
- Exposure to cloud environments (AWS / OCI) and third-party risk assessment processes.
- Strong documentation and drafting ability; proficient in Excel and PowerPoint for evidence tracking, trackers and management reporting.
- Able to read a regulatory clause and translate it into a practical control check.
- Able to read SIEM, EDR, PAM, MDM and vulnerability scanner output - dashboards, alerts and scan reports - and follow up meaningfully with infrastructure and application teams.
- Understanding of patch cycles, secure configuration baselines, backup and DR drill evidence, and what constitutes acceptable proof that a technical control is operating.

Behavioural Skills:

- Detail-oriented and deadline-driven; reliable on follow-through and closure.
- Well organised - manages multiple trackers, deadlines and follow-ups in parallel, and keeps documentation and evidence filed and retrievable.
- Transparent written and verbal communication - able to explain a control gap to a non-technical stakeholder.
- Comfortable coordinating across IT, business and vendor teams without direct authority.
- Adaptable to evolving regulatory requirements and willing to learn on the job.
- Discreet and dependable in handling sensitive information.

📌 Executive / Senior Executive-IT GRC & Information Security (Mumbai)
🏢 Vastu Housing Finance
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: executive / senior executive-it grc & information security (mumbai) / mumbai

Subscribe to this job alert:

Get the latest job offers by email for: executive / senior executive-it grc & information security (mumbai) / mumbai