Lead - Information Security and GRC (Thane)

Lead - Information Security and GRC (Thane)

02 Oct
|
Financial services
|
Thane

02 Oct

Financial services

Thane

Job Description

Key Result Areas
Supporting Actions
4) Key Result Areas
Key results expected from the job and the supporting actions for each key result area.
ISMS & Security Governance
- Own and operate the Enterprise Information Security Governance & IT Risk Management program aligned to ISO 27001:2022, NIST CSF and DPDP Act.
- Develop, review and renew policies, standards and SOPs; maintain the policy renewal tracker and secure stakeholder/management approvals.
- Evaluate the organization’s security posture periodically and report to stakeholders.

Security Assessment & Technology Due Diligence
- Conduct InfoSec assessments for recent/existing projects and applications on a Secure-by-Design basis — review architecture, data flows and controls, and perform threat modelling.
- Assess controls, identify gaps, provide residual-risk assessments and track risk-treatment actions.
- Validate implementation (controls, VAPT, secure code review, logging/monitoring) and provide initial and final production sign-offs.

Application, API & Infrastructure Security




- Govern application & API security — assess against InfoSec/AppSec checklists, oversee VA, PT and secure code reviews, and drive DevSecOps integration and application-layer attack mitigation.
- Maintain MBSS / Secure Configuration Documents (SCD); oversee configuration VA and compliance reviews.
- Maintain infrastructure security baselines, assess assets periodically, track and close observations with stakeholders.

Enterprise Vulnerability Management
- Lead the Enterprise Vulnerability Management program across applications, infrastructure and configurations.
- Prioritise vulnerabilities by severity, business impact and exploitability; manage exceptions and escalate overdue items.
- Monitor remediation progress and ensure timely closure and reporting.

Cloud Security Governance
- Implement and oversee cloud security best practices across AWS & Azure — IAM, encryption, network security and logging.
- Conduct cloud secur

📌 Lead - Information Security and GRC (Thane)
🏢 Financial services
📍 Thane

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: lead - information security and grc (thane) / thane

Subscribe to this job alert:

Get the latest job offers by email for: lead - information security and grc (thane) / thane