Aditya Birla Capital in Maharashtra seeks a skilled compliance professional to lead regulatory audits and ensure adherence to compliance requirements. The role involves conducting assessments, documenting findings, and coordinating with stakeholders on risk management strategies. Candidates should have solid experience in managing audits, implementing data protection policies, and performing third-party risk assessments. Join a dynamic team focused on upholding high standards in regulatory compliance and data governance.
Qualifications
Experience in regulatory and compliance audits in the payment industry.
Ability to manage audit activities and stakeholder coordination.
Strong understanding of Data Loss Prevention policies.
Experience in conducting risk assessments and compliance monitoring.
Responsibilities
Lead and coordinate payment industry regulatory audits.
Identify all regulatory compliance requirements.
Review, implement, and maintain DLP and Proxy policies.
Perform control validation for compliance with policies.
Conduct third-party risk assessments and submit reports.
Job description
Key Result Areas
Regulatory & Compliance Audits for Payments
Lead and coordinate payment industry regulatory audits such as RBI, NPCI, PCI DSS, CERT-INC, etc.
Manage end-to-end audit activities including audit calendar management, documentation preparation, evidence collection, and stakeholder coordination.
Track audit observations/findings and ensure timely closure with respective control owners.
Regulatory compliances
Identify all regulatory compliance requirements.
Review and update the policies to ensure identified regulatory requirements are incorporated.
Conduct assessments to ensure implemented controls meet regulatory compliances.
Data Loss Prevention (DLP) & Proxy Governance
Review, implement, and maintain DLP and Proxy policies across the organization.
Perform DLP and Proxy exception reviews, ensuring justification, approval, and tracking.
Conduct ongoing monitoring and analysis of high and medium severity DLP incidents.
Collaborate with IT/security teams to fine‑tune policies and reduce false positives.
Control Validation & Compliance Monitoring
Perform control validation to ensure compliance with internal policies, procedures, and regulatory guidelines.
Execute periodic checks on access management, data protection controls, endpoint security, and network controls.
Document deviations and drive corrective action plans with respective teams.
Conduct Third‑Party Risk Assessments
Understand business requirements from proposed solution, connect with vendor and functional/data/IT SPOCs to understand architecture of the proposed solution’s integration and data movement.
Conduct the InfoSec/cyber risk assessment to identify InfoSec/cyber related risks and regulatory requirements’ compliance.
Submit the risk assessment report to concerned stakeholders, highlighting residual InfoSec/cyber risks and providing mitigation recommendations.
Track with businesses to ensure that recommendations are accepted and implemented; if not, risk is accepted for the same.
Track open vendor risks at ABC level along with recommended controls to mitigate the risk.
Present risk to concerned team and ABCD CISO senior management for their knowledge and support.
Review the MSA/NDA, ensuring that required Information Security clauses such as Information Security and Data Protection, Data Purging requirements, Right to Audit clause, SLA, Penalty, etc., are prepared.