Senior Manager - Risk & Compliance (Hyderabad)

Senior Manager - Risk & Compliance (Hyderabad)

27 Sep
|
Indian Financial Technology And Alliedservices
|
Hyderabad

27 Sep

Indian Financial Technology And Alliedservices

Hyderabad

Summary:

Candidate will lead the IT Risk Management, IT Compliance, DPDPA, BCMS Implementation in IFTAS.

Cloud

Security experience is desirable.

Experience:

- Candidate must have 10+ years of total experience with 7-9 years’ of relevant experience.

- Experience/exposure to infosec/cybersecurity compliance requirements of Indian Banking industry is mandatory

Knowledge:

1. ISO 27001 and PCI DSS Standards & Controls

2. Drafting / implementing Information Security Policy

3. IT Risk Management and IT Compliance

4. IT, Cyber Security best practices, processes, and tools

5. Cloud Security best practices

6. BCP Program Implementation

7. Business Impact Assessment

8. DPDPA / Privacy program implementation

Roles and Responsibilities

1. Lead the ISO 27001 Implementation and ensure its compliance.

2. Based on ISMS monitoring results, evaluate & recommend for Information Security Policy change.

3. Standardization IT and Cyber Security practices as per ISO 27001 and another global standard.

4. Establish acceptable limits for the application, network, or system usage in IFTAS.

5. Ensure security review of the recent requirement / projects are performed to ensure required security controls are incorporated.

6. Is responsible to conduct security review of IT Application / Infrastructure and provide the recommendations for improvement, the review includes hardening, access controls, privilege access, obsolete configuration, etc.

7. Is responsible to conduct risk assessment of Asset / Service and provide recommendation with remediation steps.

8. Review MSA/SoW/NDA, Contractual requirements of customers and vendors and advise on information security compliance.

9. Facilitate Internal and external audit and track the findings for timely closure.

10. Provide advice and input for Disaster Recovery, Contingency, and Continuity of Operations Plans.

11. Monitor and evaluate the effectiveness of IFTAS Information Security controls / safeguards to ensure that they provide the intended level of protection.

12.



Create Policies, Processes, and Standards.

13. Develop methods to monitor and measure risk and compliance.

14. Ensure information security requirements are incorporated in new IT Procurement / Outsourcing.

15. Ensure that Production and Non-Production (UAT, Testing) environments follow Information Security Policy.

16. Ensure that Information / Data Protection controls are implemented as per Information Security Policy.

17. Identify, assess, and recommend cybersecurity controls or cybersecurity-enabled products for IFTAS.

18. Adhere and promote the information security policy awareness and best practices in the company.

19. Conduct periodic information privacy impact assessments and ongoing compliance monitoring activities in coordination with the organization’s other compliance and operational assessment functions

20. Conduct BIA (Business Impact Assessment) exercise and develop Business Continuity Plan

21. Define appropriate levels of system availability based on critical system functions and ensure that system requirements identify appropriate disaster recovery and continuity of operations requirements to include any appropriate fail-over/alternate site requirements, backup requirements, and material supportability requirements for system recover/restoration.

22. Develop Disaster Recovery and Continuity of Operations plans for systems under development and ensure testing prior to systems entering a production environment.

23. Ensure that cybersecurity requirements are integrated into the continuity planning.

24. Ensure the execution of disaster recovery and continuity of operations.

25. Provide advice and input for Disaster Recovery, Contingency, and Continuity of Operations Plans.

26. Identify and prioritize essential system functions or sub-systems required to support essential capabilities or business functions for restoration or recovery after a system failure or during a system recovery event based on overall system requirements for continuity and availability.

27. Prepare the DR Drill and BCP test reports

📌 Senior Manager - Risk & Compliance (Hyderabad)
🏢 Indian Financial Technology And Alliedservices
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior manager - risk & compliance (hyderabad) / hyderabad

Subscribe to this job alert:

Get the latest job offers by email for: senior manager - risk & compliance (hyderabad) / hyderabad