AVP - Information Security (Goverance, Risk & Compliance) 1

SMBC Group

New Delhi

On-site

INR 1,400,000 - 2,100,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

SMBC Group in Delhi is seeking a senior Information Security professional to drive governance, risk and regulatory compliance within the bank’s IT landscape. You will manage controls, policy education, and incident reporting while coordinating with IT and business teams on risk mitigation.

Required 8–10 years in information security, RBI/regulatory exposure, and strong skills in governance, audits, and security project delivery. A BE/B.Tech degree is expected, with a Master’s preferred.

Qualifications

  • 8–10 years in Information & Cyber Security with RBI exposure.
  • Experience in BFSI or regulated environments preferred.
  • Hands-on in information security governance, risk & compliance.

Responsibilities

  • Lead IT security governance, risk management and regulatory compliance initiatives.
  • Maintain information security policies and conduct awareness training.
  • Execute security controls, monitor compliance and report incidents.
  • Perform IT security risk assessments for processes and projects.
  • Collaborate with IT and business teams on risk mitigation measures.

Skills

IT Security Governance
Regulatory Compliance
IT Risk Management
Incident Response
Data Confidentiality
Security Controls
RBI Guidelines
Audits
Project Management
Stakeholder Collaboration

Education

Bachelor’s degree in BE/B.Tech
Master’s in IT/IS preferred

Tools

Excel
PowerPoint

Job description

Job description
  • The incumbent shall be responsible for the managing, maintaining and enhancing the Information Security Governance & IT Risk Mgmt, and Cyber Compliance posture of the Bank.
  • He /She shall be responsible for maintenance of Information Security policies & procedures and imparting of the policy education, training and awareness.
  • He /She shall be responsible for execution of various Information Security controls and processes, monitoring compliance with the regulatory and organizational regulations, managing data confidentiality & security, conducting investigations and reporting of security incidents. Timely and quality submission of all regulatory returns & reports is a key responsibility.
  • He /She should be able to improve the IT Security KRIs and appropriate reporting thereof.
  • Shall be responsible to perform IT Security Risk assessments of new & existing processes, projects and applications / infrastructure.
  • Shall be responsible to guide and collaborate with IT & business teams on risk mitigation measures, new & existing controls, security procedures, InfoSec / Cyber related regulatory guidelines and related compliance.
  • Shall be responsible for initiating and completing IT Security related projects, especially the ones driven by regulatory requirements.

The incumbent shall be able to continuously analyse bank’s information security program, implementation & execution of defined controls, and work towards sustained compliance to those and improvement of the same.

A & B. Knowledge & Skills
  • Detailed understanding of IT Security and Infrastructure practices, operations, standards and frameworks.
  • Should be well-versed with IT Act, various RBI regulations / guidelines on IT & IS, CERT guidelines etc.
  • Experienced in developing and implementing enterprise security governance, IT risk and compliance strategy and solutions
  • Should be well-versed Information & Cyber security standards and frameworks such NIST, ISO, OWASP, ITGC etc.
  • Hands on in managing Data Confidentiality & Security, Customer Information Protection, Security controls and monitoring processes, and Incident response management.
  • Security project management and planning; Ability to deliver on complex regulatory / technical security projects and initiatives.
  • Good knowledge of performing IT Security risk assessments - risk identification, mitigation measures etc.
  • Knowledge of various IT & Cyber Compliance matters such as Vulnerability Management, System Security Baselines, Hardening reviews /Security Configuration Assessments, Patching etc and appropriate remediations for the same.
  • Good understanding and hand-on experience of handling external /regulatory & internal Audits
  • Good working knowledge on MS Office tools like Excel, Powerpoint would be essential. Should be well versed with various functions and data handling techniques in Excel.
  • Ability to work on routine security activities as well complex technical security projects and initiatives.
  • Proven track record in IS Governance & Regulatory Compliance.
C. Experience
  • Overall 8 to 10 years of progressive experience in the field of Information & Cyber Security, including experience in Data security, IT Security, Network Security and IT Risk Management in a global banking environment. At least 3 years of experience specifically in Information Security Governance / Cyber Risk Management/Regulatory compliance with RBI and other regulatory authorities.
  • Experience in BFSI or Regulated environment would be preferred, but not mandatory.
D. Qualifications
  • Must have completed a Bachelor’s degree (preferably BE / B.Tech.). A Master’s degree in IT/IS will be preferred.

Any one or more of the below or other similar security related certifications:

  • ISO 27001 Lead Implementer / Auditor Certified from Reputed ISO Certification Body
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP)
Profile description

Knowledge & Skills

  • Detailed understanding of IT Security and Infrastructure practices, operations, standards and frameworks.
  • Should be well-versed with IT Act, various RBI regulations / guidelines on IT & IS, CERT guidelines etc.
  • Experienced in developing and implementing enterprise security governance, IT risk and compliance strategy and solutions
  • Should be well-versed Information & Cyber security standards and frameworks such NIST, ISO, OWASP, ITGC etc.
  • Hands on in managing Data Confidentiality & Security, Customer Information Protection, Security controls and monitoring processes, and Incident response management.
  • Security project management and planning; Ability to deliver on complex regulatory / technical security projects and initiatives.
  • Good knowledge of performing IT Security risk assessments - risk identification, mitigation measures etc.
  • Knowledge of various IT & Cyber Compliance matters such as Vulnerability Management, System Security Baselines, Hardening reviews /Security Configuration Assessments, Patching etc and appropriate remediations for the same.
  • Good understanding and hand-on experience of handling external /regulatory & internal Audits
  • Good working knowledge on MS Office tools like Excel, Powerpoint would be essential. Should be well versed with various functions and data handling techniques in Excel.
  • Ability to work on routine security activities as well complex technical security projects and initiatives.
  • Proven track record in IS Governance & Regulatory Compliance.

Experience

  • Overall 8 to 10 years of progressive experience in the field of Information & Cyber Security, including experience in Data security, IT Security, Network Security and IT Risk Management in a global banking environment. At least 3 years of experience specifically in Information Security Governance / Cyber Risk Management/Regulatory compliance with RBI and other regulatory authorities.
  • Experience in BFSI or Regulated environment would be preferred, but not mandatory.

Qualifications

  • Must have completed a Bachelor’s degree (preferably BE / B.Tech.). A Master’s degree in IT/IS will be preferred.
  • Any one or more of the below or other similar security related certifications:
    • ISO 27001 Lead Implementer / Auditor Certified from Reputed ISO Certification Body
    • Certified Information Systems Auditor (CISA)
    • Certified Information Security Manager (CISM)
    • Certified Information Systems Security Professional (CISSP)
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Technical Security Manager
Technical Security Manager

Pay10 India • New Delhi

On-site
INR 1,300,000 - 2,100,000
Senior Executive Information Security
Senior Executive Information Security

SBI Payment Services Pvt. Ltd. • Mumbai City

On-site
INR 600,000 - 900,000
AVP Information Security
AVP Information Security

Jain International Trade Organisation - India • Mumbai

On-site
INR 3,000,000 - 4,500,000
AVP Information Security
AVP Information Security

JITO • Mumbai

On-site
INR 4,500,000 - 7,000,000
Information Security II-SUPPORT SERVICES-IT Security
Information Security II-SUPPORT SERVICES-IT Security

Kotak Mahindra Bank • Mumbai

On-site
INR 1,800,000 - 3,000,000
IT Risk Analyst
IT Risk Analyst

Sayyam Investments Private Limited • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Senior Auditor-Immediate Joiner
Senior Auditor-Immediate Joiner

Reserve Bank Information Technology • Navi Mumbai

Hybrid
INR 1,500,000 - 2,000,000
IN-Manager_Cyber Security Governance_Strategy, Governance, Risk & Compliance_Advisory_Mumbai
IN-Manager_Cyber Security Governance_Strategy, Governance, Risk & Compliance_Advisory_Mumbai

PwC • Mumbai

On-site
INR 2,500,000 - 3,600,000
Security Risk and Regulatory Tech Compliance
Security Risk and Regulatory Tech Compliance

KreditBee • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Risk Control and governance- Finance SME
Risk Control and governance- Finance SME

NEC Corporation • Navi Mumbai

On-site
INR 1,900,000 - 3,200,000