Head – Information System, Audit and Compliance

Muthoot Fincorp Ltd.

Thiruvananthapuram

On-site

INR 4,000,000 - 7,000,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Muthoot Fincorp Ltd. seeks a Head of Information System, Audit, and Compliance to lead governance, risk management, and regulatory compliance across all units. The role directs strategic audit plans, ensures RBI/ISO27001/PCI DSS/GDPR alignment, and manages a team of auditors to strengthen security controls.

Responsibilities include end-to-end audits, third-party reviews, and reporting to the Board. The incumbent will foster a culture of security awareness, drive efficiency through compliant

Qualifications

  • 12-15 years of proven experience in information security, audit, risk management and compliance, with at least 5 years in BFSI/NBFC leadership.
  • Strong knowledge of RBI guidelines, ISO 27001, PCI DSS, GDPR and related regulatory standards.
  • Proven ability to lead audits across IT systems, infrastructure, applications and processes.
  • Excellent communication with senior management, regulators and external auditors.

Responsibilities

  • Develop and execute a strategic information security audit plan aligned with business objectives and regulatory requirements.
  • Oversee audits, assess risks, and implement controls to ensure compliance across units and regions.
  • Lead third-party and vendor reviews to ensure adherence to security standards.
  • Report findings to the Board and Audit Committee and drive continuous improvement in security controls.

Skills

Information security governance
Risk management
Compliance frameworks
Audit leadership
Regulatory knowledge
Stakeholder management
Team leadership
Vendor management

Education

Bachelor or Master in CS/IS/Risk

Tools

Audit tools
Vulnerability assessment tools

Job description

Head of Information System, Audit, and Compliance

The Head of Information System, Audit, and Compliance is responsible for organization’s information security governance, risk management, and compliance frameworks are robust, aligned with regulatory requirements, and continuously improved to mitigate risks and enhance security controls. The role will be responsible for overseeing and leading the organization's information security audit and compliance functions across all business units and regions.

The Head will be responsible for developing and executing a strategic audit plan for information security, ensuring adherence to industry standards (such as RBI and other relevant guidelines), and managing a team of skilled auditors. Additionally, the role involves driving operational governance related to information security and audit functions, enabling improvements in efficiency through robust compliance frameworks, and fostering a culture of security awareness and innovation within the team. The Head will focus on enhancing the skills and capabilities of the information security team while creating an environment that promotes high performance.

KEY RESPONSIBILITIES
Strategic Direction
  • Develop and implement a comprehensive information security audit strategy aligned with the organization’s business objectives, risk appetite, and regulatory requirements
  • Ensure the development and execution of the audit framework, annual audit plan/calendar, prioritizing audits based on risk assessments and business impact.
  • Review and ensure that information security governance frameworks and policies are well-defined, communicated, and adhered to across MFL.
  • Oversee and ensure compliance with regulatory requirements, such as RBI guidelines, ISO 27001, PCI DSS, GDPR, and other relevant standards specific to the Non-Banking Financial Company (NBFC) sector.
  • Assess and evaluate the information security risk across business units and implement appropriate controls and mitigation strategies.
  • Lead end-to-end audits of the MFL’s IT systems, infrastructure, applications, and business processes, focusing on identifying security vulnerabilities, non-compliance issues, and gaps.
  • Evaluate the effectiveness of existing controls and security measures, providing recommendations for improvements.
  • Ensure periodic reviews of third-party vendors and service providers to ensure they comply with the company’s security standards and regulatory obligations.
  • Provide regular updates to the Board on risk and compliance matters, incorporating their feedback into the overall strategy and operational plan
Stakeholder Management & Reporting
  • Collaborate with various business units, including IT, Risk, Legal, and Compliance, to promote awareness and understanding of security audit findings and best practices.
  • Work with the business units and functions for ISO certification
  • Work with the external auditors, regulators, and other stakeholders to ensure alignment on compliance-related issues.
  • Prepare and present audit reports, findings, and recommendations to senior management and quarterly to the Audit Committee.
Operational Excellence
  • Leverage information security practices effectively while driving innovation for efficiency improvements, ensuring that compliance considerations remain central to all initiatives
  • Lead efforts to enhance security and compliance across all existing and future products, services, and processes to maintain a competitive advantage
  • Develop and lead training programs to enhance awareness and understanding of security and compliance within the organization.
  • Drive the continuous improvement of information security policies, procedures, and audit methodologies, ensuring they remain relevant and effective in addressing emerging risks.
Team management and capability development
  • Develop clear goals for the compliance team and facilitate alignment with broader organizational objectives, regularly reviewing team performance and providing constructive feedback
  • Identify training needs and implement capability-building programs that empower teams to excel and adapt to the evolving regulatory landscape
  • Foster a culture of collaboration, accountability, and excellence within the team
KEY CHALLENGES
  • Driving awareness and building an environment where audit is considered as a priority
  • Internal pace of working and slow pace of approvals
KEY DECISIONS TAKEN
  • Sign off on the IS Audit before sharing with Audit Committee
  • Recommendations across business with respect to risk and compliance in reference to information security
KEY INTERACTIONS
Internal Stakeholders
External Stakeholders

Audit Committee: Present audit findings to the committee every quarter

Senior Leadership: Provide insights on the key findings from the audits conducts and gaps identified

All functional heads to seek alignment on the audit process and ensure compliance as per set standards

Vendors Audit Partners – Provide necessary support to carry out auditing process

Regulatory Authorities such as RBI to ensure compliance with external regulations and directives

KEY ROLE DIMENSIONS

Team Size: 2 direct reports

EDUCATION / EXPERIENCE

Bachelor’s or Master’s degree in Computer Science, Information Security, Audit, Risk Management, Business Management or a related field.

Nature of Experience:
  • At least 12-15 years of proven experience in information security, audit, risk management, and compliance, with at least 5 years in a leadership role in BFSI or NBFC.
  • Strong background in compliance frameworks, risk management, and security strategy.
  • Professional certifications such as CISA (Certified Information Systems Auditor), CISSP (Certified Information Systems Security Professional), or equivalent are highly desirable.
  • Proven track record in implementing effective security solutions that enhance operational efficiency and ensure regulatory compliance.
  • In-depth knowledge of regulatory frameworks, standards, and best practices for information security (e.g., RBI Guidelines, ISO 27001, NIST, GDPR).
  • Strong background in conducting internal audits related to information security, risk management, and IT governance within the financial services or NBFC sector.
  • Proven track record of successfully leading audits, driving compliance, and implementing corrective actions.
  • Strong understanding of the information security landscape, including risk management, vulnerability management, incident response, data protection, and business continuity planning.
  • Experience with tools and technologies used for security auditing and vulnerability assessment.
  • Excellent communication and interpersonal skills, with the ability to interact with senior management, regulators, and external auditors.
  • High degree of integrity, professionalism, and ethical standards.
  • Strong analytical and problem-solving skills.
  • Ability to handle multiple priorities and work under pressure to meet deadlines.
  • Strong leadership and team management skills, with a collaborative approach to achieving organizational objectives.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Associate Manager - Information Security and Compliance
Associate Manager - Information Security and Compliance

Finnable • Bengaluru

On-site
INR 800,000 - 1,200,000
IT Risk & Compliance Manager
IT Risk & Compliance Manager

TVS Credit Services Ltd • Chennai District

On-site
INR 1,500,000 - 2,000,000
Internal Auditor-Information Security/System Audits:Audit & Process_AFL
Internal Auditor-Information Security/System Audits:Audit & Process_AFL

Axis Finance Limited • Navi Mumbai

On-site
INR 600,000 - 900,000
AVP/VP - Regulatory Compliance (RBI - NBFC)
AVP/VP - Regulatory Compliance (RBI - NBFC)

DMI Finance Private Limited • Delhi

On-site
INR 6,000,000 - 9,000,000
Senior Manager - Information Security And Governance
Senior Manager - Information Security And Governance

HDB Financial Services Ltd. • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Associate Auditor-Cybersecurity-Immediate joiner
Associate Auditor-Cybersecurity-Immediate joiner

Reserve Bank Information Technology • Navi Mumbai

On-site
INR 800,000 - 1,400,000
Assistant Vice President - Platform Compliance Post Acquisition
Assistant Vice President - Platform Compliance Post Acquisition

SBI Cards and Payment Services Private Ltd. • India

On-site
INR 3,000,000 - 6,000,000
Wellness program
Rewards & recognition
Inclusive health benefits
+1
IT Risk Analyst
IT Risk Analyst

Sayyam Investments Private Limited • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Information Security Manager
Information Security Manager

Dmi Finance • Dadri, Delhi

On-site
INR 1,200,000 - 1,800,000
Senior Auditor-Immediate Joiner
Senior Auditor-Immediate Joiner

Reserve Bank Information Technology • Navi Mumbai

Hybrid
INR 1,500,000 - 2,000,000