23 Sep
|
SBI Payments
|
Mumbai
23 Sep
SBI Payments
Mumbai
Position
Senior Executive Information Security
Grade - Senior Executive
Reporting to Manager – Information Security
Location Mumbai
About the Company
SBI Payment Services Pvt. Ltd. is a Joint Venture between SBI & Hitachi Payment Services Pvt. Ltd. which combines the unparalleled distribution network, customer trust of SBI with cutting edge technology and services of the Hitachi Group. SBI Payments has been in acquiring business since 2010 and currently has over 33 lakh merchant payment acceptance touch points and processes transaction value of over Rs.1 lakh Crore per annum. The Company envisages to be the market leader in digital payments acceptance solutions to merchants in India as well as in Asia.
Qualification
Bachelor’s degree: (B. Tech) degree in computer science, Information Technology, or Cybersecurity.
Preferred Certification: CISSP, CEH, CompTIA Security+ or equivalent.
Experience
0-2 years of experience in Information Security or IT Security Operations.
Domain Knowledge Competencies
Technical Competencies:
- Solid knowledge of network security, endpoint security, Application Security.
- Understanding of Cloud Security and Cloud Security Posture Management.
- Familiarity with SIEM, IAM, DLP, vulnerability scanners, and firewalls.
- Understanding of secure software development lifecycle (SDLC)and DevSecOps practices.
- Vulnerability Assessment Process, Penetration Testing Techniques & Mobile Security Testing Strong
- Understanding of Enterprise AI/ML Security and AI Risk Management.
Regulatory & Compliance Competencies:
- Knowledge of ISO 27001, PCI-DSS, SOC 2, RBI, DPDPA and local data protection laws.
- Experience in audit preparation and compliance reporting.
Risk Management Competencies:
- Ability to conduct risk assessments and business impact analyses.
- Knowledge of threat modelling and incident response frameworks.
Position Objective / Responsibilities
Position Objective:
Senior Executive – InfoSec will support the organization in safeguarding its information assets, ensuring compliance with regulatory frameworks, and mitigating cybersecurity risks. The role focuses on managing day-to-day security operations, implementing security policies, and providing domain-specific expertise to strengthen the organization’s overall security posture.
Key Responsibilities:
- Security Operations
- Monitor and respond to security incidents, vulnerabilities and threats.
- Manage SIEM, IDS/IPS, endpoint protection, and DLP solutions.
- Coordinate incident response and forensic investigations.
- Perform Internal VAPT on Network, Mobile, Cloud and Web Applications.
- Perform Security and Risk Assessments on Enterprise AI/ML Workloads and implement Security Controls.
- Conducting DevSecOps Activity and performing SDLC Security Assessments.
- Governance, Risk & Compliance (GRC)
- Ensure adherence to ISO 27001, NIST, PCI-DSS, DPDPA,RBI or industry-specific standards.
- Conduct risk assessments and internal audits.
- Support regulatory inspections and compliance reporting.
- Understanding of cloud security posture management & cloud audit.
- Policy & Awareness
- Draft, update, and enforce information security policies and procedures.
- Conduct employee awareness and training programs on cybersecurity best practices.
- Collaboration & Leadership
- Work with IT, legal, and business teams to align security with organizational goals.
- Report security metrics and incidents to senior management.
- Project Support:
- Review new applications, systems, and infrastructure for security risks.
- Conduct vendor risk assessments and third-party security reviews.
Behavioural Competencies
- A high level of commitment and self-motivation.
- Proven work experience in handling the portfolio.
- Strong integrity, trustworthiness and accountability
- Excellent written and verbal communication skills.
📌 Senior Executive Information Security (Mumbai)
🏢 SBI Payments
📍 Mumbai