Information Security II-SUPPORT SERVICES-CTO - Support services

Kotak Mahindra Bank

Mumbai

On-site

INR 2,500,000 - 4,500,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Kotak Mahindra Bank is seeking a Senior Leader to drive Governance, Risk Management and User Access Governance across IT Infrastructure, Cybersecurity and Cloud Operations. You will define governance frameworks, perform risk assessments and deliver management reporting to ensure regulatory adherence and operational resilience.

The role requires 10–15 years in Information Security or IT Risk, with 5+ years in Governance or UAM/UAR.

Qualifications

  • Bachelor's degree in Engineering, IT, or CS.
  • Master's degree or MBA preferred.
  • Certifications: CISA, CRISC, CISSP, CISM, ISO 27001 Lead Auditor/Lead Implementer, COBIT.
  • 10–15 years in Information Security, IT Risk or Governance.
  • 5+ years in Governance, Risk or UAM.
  • Banking or regulated industry experience preferred.

Responsibilities

  • Define and maintain governance frameworks for IT Infra, Cybersecurity and Cloud.
  • Establish and maintain process documentation, SOPs and governance controls.
  • Develop and monitor KRIs and governance metrics.
  • Evaluate adherence to policies, standards and procedures.
  • Maintain central repository of governance artefacts and control docs.
  • Conduct risk and control assessments for applications and infrastructure.
  • Identify technology, security and operational risks and assess controls.
  • Maintain risk registers, remediation plans and exception tracking.
  • Review risk acceptance requests and compensating controls.
  • Track risks and gaps through closure.
  • Provide risk oversight for new tech deployments and changes.
  • Publish UAR dashboards and governance reports for senior management.

Skills

Governance & Risk
IT Governance Frameworks
Risk Assessments
UAM & UAR
RBAC & SoD
IAM
Leadership
Stakeholder Management

Education

Bachelor's degree in Engineering/IT/CS
Master's degree or MBA preferred
CISA
CRISC
CISSP
CISM
ISO 27001 Lead Auditor/Lead Implementer
COBIT Foundation/Design & Implement.

Job description

Job Purpose To lead Governance, Risk Management and User Access Governance activities across IT Infrastructure, Cybersecurity and Cloud Operations. The role is responsible for establishing governance frameworks, conducting risk and control assessments, overseeing User Access Management (UAM) and User Access Reviews (UAR), monitoring key technology initiatives, and providing management reporting to ensure operational resilience, regulatory adherence and effective control governance.

Key Responsibilities
  • Governance Framework & Policy Management - Define, implement and maintain governance frameworks for IT Infrastructure, Cybersecurity and Cloud Operations.
  • Establish and maintain process documentation, SOPs, standards, operating procedures and governance controls.
  • Develop and monitor Key Risk Indicators (KRIs) and governance metrics.
  • Evaluate adherence to approved policies, standards and operating procedures.
  • Maintain a central repository of governance artefacts, approvals, process notes and control documentation.
  • Risk Management & Control Assessment - Conduct periodic Risk and Control Assessments for applications, infrastructure platforms and operational processes.
  • Identify technology, security and operational risks and assess the effectiveness of existing controls.
  • Maintain and monitor risk registers, remediation plans and exception tracking.
  • Review risk acceptance requests and compensating controls.
  • Track identified risks and control gaps through closure.
  • Provide risk oversight for new technology deployments, infrastructure changes and strategic initiatives.
  • User Access Governance & UAR - Establish governance processes for User Access Management (UAM) across infrastructure and cybersecurity platforms.
  • Define and maintain Access Control Matrices (ACMs) and role-based access models.
  • Govern periodic User Access Reviews (UARs) for all infrastructure applications and platforms.
  • Ensure access certifications are completed within defined timelines and retained for audit purposes.
  • Monitor privileged access, shared IDs, service accounts and segregation of duties controls.
  • Track and report access-related exceptions and remediation actions.
  • Publish UAR dashboards and governance reports for senior management review.
  • Governance Oversight of Technology Functions - Govern key initiatives and projects across Infrastructure, Cybersecurity and Cloud Operations.
  • Monitor compliance with approved governance requirements during the project lifecycle.
  • Assess risks associated with major technology initiatives and recommend mitigation measures.
  • Engage with Technology Leadership Teams (TLTs) to address emerging governance and risk concerns.
  • Support decision-making through risk-based assessments and recommendations.
  • Senior Management Reporting - Prepare periodic dashboards and management reports covering:
  • Risk Assessments
  • Risk Register Status
  • UAR Compliance
  • Access Exceptions
  • Governance Metrics
  • Policy Compliance
  • Control Effectiveness Reviews
  • Present governance and risk updates to senior management committees.
  • Perform trend analysis and highlight emerging risks and areas requiring management attention.
Educational Qualifications

– Bachelor's degree in Engineering, Information Technology, Computer Science or a related discipline.

  • Master's degree or MBA preferred.
  • Professional certifications preferred:
  • CISA
  • CRISC
  • CISSP
  • CISM
  • ISO 27001 Lead Auditor / Lead Implementer
  • COBIT Foundation / Design & Implementation
Experience

10-15 years of experience in Information Security, IT Risk Management, Governance or Technology Compliance.

  • Minimum five years of experience in Governance, Risk Management, Internal Controls or User Access Governance.
  • Experience in banking, financial services or another highly regulated industry is preferred.
  • Strong understanding of technology infrastructure, cybersecurity controls and access governance practices.
Key Skills & Competencies

Category Competencies Governance & Risk IT Governance Frameworks; Risk & Control Assessment; Enterprise Risk Management; Technology Risk Assessment; Policy & Standards Management; Control Design & Effectiveness Review User Access Governance User Access Management (UAM); User Access Review (UAR); Role-Based Access Control (RBAC); Segregation of Duties (SoD); Privileged Access Governance; Identity & Access Management (IAM) Leadership & Management Stakeholder Management; Executive Communication; Presentation Skills; Analytical Thinking; Problem Solving; Team Leadership; Cross-functional Coordination

Key Performance Indicators (KPIs) - Completion of UARs within prescribed timelines.

  • Percentage reduction in access governance exceptions.
  • Timely closure of identified risk and control gaps.
  • Completion of periodic risk assessments.
  • Accuracy and timeliness of governance dashboards.
  • Compliance with governance and control review schedules.
  • Reduction in overdue remediation actions.
  • Improvement in overall governance and risk maturity.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Engineer
Information Security Engineer

Kotak Mahindra Bank • Mumbai Suburban, Navi Mumbai, Mumbai

On-site
INR 1,800,000 - 3,000,000
Information Technology Governance Manager
Information Technology Governance Manager

Flipkart • Bengaluru

On-site
INR 3,000,000 - 5,000,000
Senior Manager – Cyber Security
Senior Manager – Cyber Security

Tata Consumer Products • Bengaluru

On-site
INR 4,000,000 - 6,000,000
Senior Manager – Digital, Cyber Security (GRC)
Senior Manager – Digital, Cyber Security (GRC)

Tata Consumer Products • Bengaluru

On-site
INR 1,500,000 - 1,900,000
Assistant Manager - IT Security
Assistant Manager - IT Security

Techture • Greater Noida

On-site
INR 2,400,000 - 4,800,000
Sr Engineer, Governance, Risk & Compliance
Sr Engineer, Governance, Risk & Compliance

NextGen Healthcare India • Bengaluru

On-site
INR 1,600,000 - 2,800,000
Governance, Risk & Compliance Analyst
Governance, Risk & Compliance Analyst

Hero Fincorp • India

On-site
INR 1,800,000 - 2,600,000
Cybersecurity & Compliance Advisor
Cybersecurity & Compliance Advisor

Siemens Mobility • Gurugram District

On-site
INR 2,500,000 - 4,000,000
Lead - Information Security and GRC
Lead - Information Security and GRC

ABC - Aditya Birla Housing Finance Limited • Maharashtra

On-site
INR 1,200,000 - 1,800,000
Information Security Manager
Information Security Manager

Dmi Finance • Dadri, Delhi

On-site
INR 1,200,000 - 1,800,000