24 Sep
|
Axis Bank
|
Mumbai
Cyber Security Audits
- Execute risk-based cyber security audits covering on-premise and cloud environments.
- Assess security controls across network, endpoint, application, database, cloud, and infrastructure domains.
- Evaluate the effectiveness of security monitoring, SOC operations, threat detection, and incident response processes.
- Conduct thematic reviews on emerging cyber risks and security technologies.
Technology &
- Information Security Reviews
- Review Identity &
- Access Management (IAM), Privileged Access Management (PAM), MFA, and user access governance controls.
- Assess Vulnerability Management, Patch Management and Security Configuration Management.
- Evaluate Data Security and Data Protection controls, including encryption, key management, DLP, and data classification.
- Review application security controls, secure SDLC, DevSecOps, API security, and cloud security implementations.
Regulatory &
- Compliance Assessment
- Assess compliance with RBI, SEBI, NPCI, NCIIPC, CERT-In, and other applicable regulatory requirements.
- Evaluate adherence to the Bank's Information Security Policies, Technology Standards, and Cyber Security Frameworks.
- Support regulatory inspections and external audits by providing audit observations and management responses.
Audit Execution
- Perform planning, risk assessment, fieldwork, testing, reporting, and follow-up activities.
- Review system configurations,
security logs, policies, procedures, and operational evidence.
- Conduct walkthroughs with business, technology, and information security teams.
- Prepare concise and impactful audit reports for senior management and Audit Committee review.
Data Analytics &
- Automation
- Leverage data analytics, AI tools, and automation techniques to enhance audit effectiveness.
- Perform log analysis, security event reviews, and risk trend analysis.
Stakeholder Management
- Engage with Technology, Information Security, Digital Banking, Cloud, Infrastructure, and Business teams.
- Present audit observations and recommendations to senior management.
- Track remediation of audit findings and validate closure evidence.
Technical Knowledge
- Cyber Security Architecture, Network Security, Cloud Security (AWS, Azure, GCP), IAM / PAM, SIEM / SOC Operations, Endpoint Security, Encryption &
- Cryptography, Vulnerability Assessment &
- Penetration Testing, Database Security and Data Protection &
- Privacy Controls
Regulatory &
- Framework Knowledge
- RBI Cyber Security Guidelines, RBI IT Governance Directions, SEBI CSCRF, NPCI Security Requirements, CERT-In Directions, ISO 27001, NIST Cyber Security Framework, CIS Controls. OWASP
Preferred Certifications
- CISA. CISSP, CISM, CRISC, CEH, CCSP, AWS/Azure Security Certifications, CCNA, CCNP
📌 Job opening - Information Security Auditor & Cyber Security Auditor (Mumbai)
🏢 Axis Bank
📍 Mumbai