Assistant Vice President - Insider Threat Lead

SBI Card

Gurugram District

On-site

INR 1,400,000 - 2,100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SBI Card is seeking a seasoned Insider Threat Program Manager to lead the end-to-end insider threat initiative, focusing on protecting critical information from unauthorized exposure. You will oversee monitoring, alert workflows, and escalations aligned with information security policies.

Responsibilities include metrics, incident handling, DR planning, and collaboration with compliance, HR, and legal teams to enforce disciplinary actions when needed.

Qualifications

  • Bachelor’s Degree or B.Tech. in Computer Science / Information Technology or related discipline.

Responsibilities

  • Define and Manage processes around insider threat management.
  • Manage Insider Threat Monitoring program by ensuring processing security alerts generated by tools to identify data loss/insider threat risk.
  • Prepare and operationalize Alert/Incident metrics as part of the infosec function.
  • Manage escalations of security alerts for review by business and compliance teams.
  • Coordinate with Compliance Team for steering committee reviews and disciplinary actions.
  • Provide feedback to DLP Team after review of alerts/incidents.
  • Review alert classifications to reduce false positives.
  • Lead and maintain internal users' security incidents and trackers.
  • Ensure end-to-end tracking of insider threat alerts and incidents including actions taken.
  • Provide input to ERMC/ISC on incidents and actions taken.
  • Participate in Disaster Recovery planning, testing, troubleshooting and root cause analysis.
  • Manage Service Partner operations from technology perspective.
  • Ensure process documentation and compliance adherence.

Skills

Log management
DLP
CASB
UAM
Data Classification
IRM
Cybersecurity risks
Security controls
NIST/ISO/GDPR
SOC experience
Data breach handling

Education

Bachelor’s Degree or B.Tech. in Computer Science / Information Technology or related discipline

Tools

DLP
CASB
UAM
IRM

Job description

Role Purpose

Responsible for managing all identified/known insider threat vector of information leakage either deliberately or inadvertently with focus on preventing Insider threat in getting exposed. The role is also responsible for leading the complete program to protect SBIC’s critical information from unauthorized exposure.

Role Accountability
  • Define and Manage processes around insider threat management.
  • Manage Insider Threat Monitoring program by ensuring processing security alerts generated by the various monitoring tools and technologies operated by the team in order to identify potential instances of data loss / exfiltration and other activity which may pose a potential Insider Threat risk.
  • Prepare and operationalize the relevant Alert/ Incident metrics, as part of the overall infosec function.
  • Manage escalations of security alerts for review by business line management, seek response and validate vis-a-vis SBI card information security policies and allowed security practices.
  • Manage escalations of security incidents alerts to SBIC Compliance Team and Co-ordinate with them for presentation in the steering committees for formal review and decisioning on the Disciplinary actions.
  • Provide feedback to the DLP (Data Leak prevention) Team basis review of the Alerts, Incidents identified as per the existing DLP rules.
  • Review the classification of alerts raised on a periodic basis to decrease false positives.
  • Lead & maintain internal users (FTEs and NFTEs) related security incidents which could indicate a potential Insider Threat risk and maintain detailed trackers for incidents witnessed and actions taken.
  • +
  • Ensure end to end tracking of Insider threat alerts and incidents, including disciplinary actions taken by responsible business/ Human resource/ legal function.
  • Provide input to the Enterprise risk management committee (ERMC)/Information Security Committee (ISC) as per the prescribed frequency regarding incidents and actions taken on incidents
  • Participate in Disaster Recovery Planning, testing, troubleshooting and root cause analysis and documentation of the root causes.
  • Manage Service Partner operation from technology prospective.
  • Ensure process documentation and compliance adherence.
Measures of Success
  • Successful development and monitoring of insider threat program
  • Increase in maturity of insider threat Programs (Adoption & Capabilities)
  • +
  • Timely delivery of project plans, milestone updates, presentations, assessment reports etc. to relevant stakeholders
  • Security metrics within acceptable threshold
  • +
  • Availability of DLP as a service in line with the enterprise expectations
  • +
  • Resolution of all technical issues reported by users within agreed TAT
  • +
  • Timely updation of DLP related SOPs and other documents
  • +
  • No adverse observations in Internal / External Audits
  • +
  • Process Adherence as per MOU
Technical Skills / Experience / Certifications
  • Knowledge and in-depth understanding of Log management and processing
  • Experience in Technologies like DLP, CASB, UAM, Data Classification, IRM
  • Knowledge of cybersecurity risks and information security standards
  • Understanding of security controls from a people, process and technology perspective.
  • Knowledge of standard security processes and guidelines.
  • Certifications including Security+, CEH, GCIA, GCIH or similar
  • +
  • Knowledge of insider and privacy frameworks such as - NIST, DSCI, ISO, PCI, GDPR, etc.
  • +
  • Prior experience working in a Security Operations Center (SOC)
  • +
  • Experience in managing data incidents and breaches
Competencies critical to the role
  • Detail Orientation
  • Teamwork and Collaboration
  • Stakeholder Management
  • Analytical ability
  • Problem Solving
Qualification

Bachelor’s Degree or B.Tech. in Computer Science / Information Technology or in a related discipline

Preferred Industry

BFSI / NBFC /E-commerce/IT & ITES / Telecom

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager - Data Loss Prevention
Manager - Data Loss Prevention

SBI Card • Gurugram District

On-site
INR 1,800,000 - 4,000,000
Assistant Vice President - Vulnerability Management
Assistant Vice President - Vulnerability Management

SBI Card • Gurugram District

On-site
INR 1,200,000 - 2,400,000
Manager - Senior Incident Analyst
Manager - Senior Incident Analyst

SBI Cards and Payment Services Private Ltd. • Gurugram District

On-site
INR 1,500,000 - 1,900,000
Senior Manager - Data Governance
Senior Manager - Data Governance

SBI Card • Bengaluru

On-site
INR 900,000 - 1,300,000
Assistant Vice President - IT and Information Security Audit
Assistant Vice President - IT and Information Security Audit

SBI Payment Services Pvt. Ltd. • Gurugram District

On-site
INR 4,500,000 - 6,500,000
Manager - Cloud Security
Manager - Cloud Security

SBI Card • Gurugram District

On-site
INR 1,800,000 - 2,600,000
Assistant Manager - Data Privacy
Assistant Manager - Data Privacy

SBI Card • Gurugram District

On-site
INR 1,100,000 - 1,700,000
Wellness program
Rewards and recognition
Diverse and inclusive culture
+2
Technical Security Manager
Technical Security Manager

Pay10 India • New Delhi

On-site
INR 1,300,000 - 2,100,000
Assistant Vice President – Information Security
Assistant Vice President – Information Security

IndiaFirst Life • Mumbai

On-site
INR 1,000,000 - 1,500,000
Assistant Vice President - Platform Compliance Post Acquisition
Assistant Vice President - Platform Compliance Post Acquisition

SBI Cards and Payment Services Private Ltd. • India

On-site
INR 3,000,000 - 6,000,000
Wellness program
Rewards & recognition
Inclusive health benefits
+1