Chief Information Security Officer
Confidential · Mumbai Metropolitan Region
Apply & track with Apply EdgeChief Information Security Officer Role BU: Risk & Management
About the Role
We are scouting for individuals who will be building, planning and implementing the overall Information Security of the organization. If you want to start small, impact large - this is the place for you.Some high level things you would own but not limited to: ● You will draft / coordinate / monitor IT process/policies to ensure compliance as per necessity by IT Act/ statutory & regulatory (e.g. RBI, SEBI, GDBR, UIDAI etc.) / info security (ISM) guidelines and circulars with respect to Technology in coordination with internal & external stakeholders● You will review the regulatory / Indian Govt. Information Technology / data Security guideline as an when it is circulated /published.● You will be conducting IT committee's as per ISM schedule and necessity advised by regulatory.- Drafting/Circulating MOM of IT committee meetings to respective members and business as & when required.● You will be preparing & updating business wise IT infra details which are largely required for the Compliance/Legal team for regulatory filing.● You will review and fill out mandatory IT documentation with respective regulatory bodies as necessary.Manage IT Policies & Procedures :● You will be responsible for drafting & ensuring implementation of IT Policies and procedures at the operational level.● You will formalize, conduct vendor risk assessments & audits, ensure implementation of identified gaps.● You will improvise and keep internal IT / IS manuals updated with all relevant regulations relating to IT. Periodic review of Information Security Manual (ISM) understanding business/regulatory/data security/technology etc.● You will be introducing and drafting processes/policies based on finding/observation.● You will be involved in periodic review of IT processes/policies and issue an advisory note to overcome gaps/loops by highlighting risk associated to it.● You will be introducing new processes/policies by doing market study/survey relevant to our business and info/infra security by highlighting risk and necessity.● You will be ensuring adherences of key process / policy execution and availability of audit trails. ● You will manage Information Systems Risk Assessments & audits● You will Plan, Coordinate, review & manage IT / IS Risk Assessments & IT audits, VAPT with relevant stakeholders (internal & external, including vendors)● You will Plan, Conduct, Review & Manage periodic IT audit and IT Risk Assessments (internal & external)● You will be responsible for carrying out periodic Internal & External IT, Process, Policy, VAPT, System Audit Management● You will be involved in closure of audit findings with amendment to existing process/policy in order to close open loops/gaps or introduce new process/policy to close the riskManage IT & Cyber Security : ● You will Plan, formulate, coordinate, implement, monitor & manage the cyber crisis management plan (CCMP).● You will ensure necessary cyber security safeguards are designed & implemented.● You will be part of Management of cyber security, related incidents & reporting to management and respective regulatory bodies. Responsible for Incident Management and resolution● You will be providing relevant data IT information Sector to Partner Function/ Business as and when required.BCP & DR● You will be responsible for formulation, review & monitoring BCP plans and it's implementation. ● You will coordinate to conduct BCP / DR drills, present findings● You will suggest/implement & constantly update BCP / DR plansWhat you would possess already:● Experience in SOC2 Type II implementation and audit (Trust Services Criteria) (This is must to have skill)● Experience in ISO 27001 readiness and implementation and audit , SOX – ITGC controls● Excellent understanding of information security concepts, principles, and best practices required ● Excellent communication skills to interact with internal and external contacts required● Interpersonal and collaborative skills and the ability to communicate security and risk concepts to technical and non-technical audiences required● High level of personal integrity and the ability to professionally handle confidential matters with proper judgment required