About us:
We are a highly successful 190-year-old, Fortune 500 commercial property insurance company of 6,000+ employees with a unique focus on science and risk engineering. Businesses worldwide trust our expertise to protect their assets, relying on our comprehensive risk assessments and robust, engineering-based insurance solutions to safeguard against fire, natural disasters, and other perils. Serving over a quarter of the Fortune 500 and major corporations globally, we deliver data-driven strategies that enhance resilience, ensure business continuity, and empower organizations to thrive.
FM India is a strategic location for driving our global operational efficiency. Our presence in India allows us to leverage the country’s talented workforce and advance our capabilities to serve our clients better. We have diverse corporate functions that emphasize research, advanced technologies like AI and analytics, risk engineering, research, finance, marketing, HR, etc. working together to provide innovative solutions and nurture lasting relationships – from co-workers to clients.
Role Title: Prin Info Security Risk Engineer IND
Position Summary:
FM is seeking a Principal Information Security Risk Engineer with deep expertise in cybersecurity regulatory compliance and oversight. In this role, you will lead evaluation of global cybersecurity regulatory requirements, assess their applicability to FM's technology and business setting, and help ensure effective implementation of controls that align with regulatory obligations and FM's risk appetite.
You will serve as a subject matter expert and trusted advisor across technology, risk, legal, and business teams, providing risk-based guidance on cybersecurity regulatory matters. You will lead complex regulatory assessments, identify control gaps and associated risks, oversee remediation efforts, and support interactions with regulators, auditors, and clients.
Job Responsibilities:
- Lead the end-to-end cybersecurity regulatory compliance function, including governance activities, processes, reporting, and continuous improvement initiatives.
- Coordinate and lead responses to regulatory examinations, client cybersecurity questionnaires, audits, and other external information requests. Partner with Information Security, IT, Risk Management, Legal, and business stakeholders to gather, validate, and communicate accurate and consistent responses.
- Proactively monitor and evaluate emerging cybersecurity regulations, standards, and guidance globally. Conduct impact assessments to determine applicability and identify required changes to FM's control environment.
- Lead regulatory gap assessments and control evaluations. As necessary, partner with technical and business teams to define remediation actions and track remediation progress, validate closure of gaps, and escalate risks as needed.
- Develop and maintain compliance metrics, dashboards, and status reporting to communicate compliance posture, risks, trends, and remediation progress. Provide clear, concise updates to senior leadership and governance committees.
- Provide regulatory compliance guidance and advisory support to IT, security, and business stakeholders. Provide guidance on control design, risk treatment, and regulatory alignment. Influence decisions to ensure alignment with FM’s risk appetite and regulatory obligations.
- Promote regulatory compliance program maturity through process optimization, automation opportunities, and adoption of industry-leading practices.
- Lead complex initiatives and provide guidance to cross-functional teams while fostering accountability, transparency, and continuous improvement.
Skill and Experience:
TECHNICAL KNOWLEDGE:
SOFT SKILLS:
- 8+ years of experience required to perform essential job functions.
- Additional Experience Qualifier (optional): Minimum of six (5) years of experience in information security, risk, audit, or regulatory compliance.
- Hands-on experience responding to regulatory exams, audits, or client security assessments, including evidence collection, control mapping, and response coordination.
- Experience supporting or participating in IT general controls (ITGC) or cybersecurity control audits, with an understanding of audit expectations, testing approaches, and evidence requirements.
- Strong understanding of cybersecurity control frameworks such as NIST CSF 2.0 and CIS v 8.1, including experience mapping controls to regulatory requirements.
- Familiarity with global regulatory requirements across regions (e.g., APAC, EU, US), including regulatory bodies such as APRA, IRDAI, OFSI, or MAS.
- Experience identifying control gaps, assessing compliance against regulatory expectations, and supporting remediation tracking.
- Ability to develop and maintain clear, accurate, and audit-ready control documentation and supporting evidence.
- Strong verbal and written communication skills, with the ability to translate technical security concepts into clear, concise responses for regulators, clients, and business stakeholders.
- Strong organizational and time management skills, with the ability to manage multiple concurrent requests and deadlines.
- High attention to detail, particularly in documentation quality and accuracy of responses.
- Strong stakeholder management and collaboration skills, with the ability to work effectively across Information Security & Risk Management, IT, Risk, Legal, and business teams.
- Ability to work independently, prioritize competing demands, and deliver high-quality outputs with minimal supervision.
- Robust problem-solving and analytical skills, with the ability to interpret regulatory requirements and apply them in a practical, risk-based manner.
Must Have Skills:
- Cybersecurity Regulatory and Client Compliance
- Hands-on experience responding to regulatory exams, audits, and client security assessments, including coordinating evidence collection and developing clear, defensible written responses.
- Global Regulatory Familiarity
- Practical experience supporting or interpreting regional cybersecurity regulations, with emphasis on APAC frameworks such as APRA, MAS, and IRDAI.
- Control Framework Mapping and Evidence Management
- Strong ability to map security controls to industry frameworks (for example NIST CSF, CIS 8.1, SOC-aligned controls), assess effectiveness, and manage supporting documentation.
- Independent Execution and Judgment
- Proven ability to manage work independently, prioritize competing demands, and deliver accurate, timely outputs with minimal supervision.
- Clear Written and Verbal Communication
- Ability to translate security and control information into clear, concise responses suitable for regulators, auditors, clients, and internal stakeholders.
Education and Certifications:
- 4 Year/ bachelor’s degree required.
Preferred certifications: CISA, CISM
Work location: Bengaluru
📌 Principal Info Security Risk Engineer IND-29476] (Bengaluru)
🏢 Fm
📍 Bengaluru