08 Oct
|
Atrina Technologies
|
Goregaon
08 Oct
Atrina Technologies
Goregaon
Company: Marwadi Chandrana Group
Job Title: Business Security Officer
Position: 2
Experience Level: 6-7 Years
Location: Goregaon
Work Type: Work From Office
Job Type: Full-Time
Job brief:
We are looking for a Business Security Officer to own the governance, risk, and compliance backbone of our information security program. This role sits at the intersection of security, regulation, and business translating cyber risk into decisions leadership and the board can act on, while ensuring the organisation stays audit-ready across ISO 27001, RBI/SEBI/IRDAI (as applicable), and DPDPA requirements.
Job Responsibilities:
- Own and maintain the organisation's information security policy suite write, review, and version-control policies, standards, and SOPs aligned to ISO 27001, NIST, and RBI/SEBIregulatory frameworks.
- Drive DPDP Act (DPDPA) compliance: data mapping, consent management alignment, data principal rights processes, and coordination with legal/privacy teams.
- Manage the end-to-end ISO 27001 (and related, e.g. ISO 27701, PCI-DSS if applicable) certification lifecycle gap assessments, ISMS documentation, internal audits, and external audit liaison.
- Lead third-party/vendor security risk assessments and due diligence for fintech partners, payment processors, and cloud/SaaS vendors.
- Own the security risk register: identify, assess, track, and report business risk in language relevant to executives and board/audit committees.
- Prepare and present security posture, risk, and compliance reports to CXOs, board committees, and regulators.
- Run the security awareness and training program across the organisation.
- Coordinate regulatory reporting and examinations (RBI IT circulars, cyber security frameworks for banks/NBFCs/fintech)
- Partner with Legal, Compliance, and Product teams to embed security/privacy requirements into new products and business initiatives.
- Manage business continuity/disaster recovery (BCP/DR) documentation and testing cadence.
- Support incident management from a regulatory-disclosure and business-impact standpoint (breach notification timelines, stakeholder communication).
Job Requirements:
- 6-8 years in information security governance, risk & compliance (GRC), preferably within fintech, banking, NBFC, or insurance.
- Working knowledge of ISO 27001 (Lead Implementer/Auditor certification preferred), DPDPA, RBI cyber security frameworks, and PCI-DSS.
- Certifications such as CISA, CRISC, ISO 27001 LA/LI, CIPP/E or CIPM (privacy) are strongly preferred.
- Demonstrated experience managing external/regulatory audits and certification cycles.
- Robust stakeholder management comfortable presenting to CXOs and board/audit committees.
- Excellent policy-writing and documentation skills.
- Familiarity with vendor risk management and third-party assessment frameworks.
Benefits:
- Medical Insurance
- Paid Leaves
- Flexible work schedules
- Development and career growth opportunities
- GTI
- Open Time Off
Pay: Up to ₹300,000.00 per month
Benefits:
- Food provided
- Health insurance
- Life insurance
- Provident Fund
Work Location: In person
📌 BSO (Goregaon)
🏢 Atrina Technologies
📍 Goregaon