Thecandidate will be responsible for conducting risk and controls assessmentsacross various technology domains and ensuring the implementation of technologycontrols. They will collaborate with IT Partners lead technology-relatedprojects from a risk perspective,TPRM including ISO22301, and will engage withstakeholders to design controls and assess control maturity and gaps.Additionally, the candidate will partner with risk, compliance, and audit teamsto address technology control-related issues, ensuring proper resolution,escalation, and reporting procedures are followed. Their focus will be onenhancing control awareness and effectively managing risks within the globalinformation technology organization.
Roles& Responsibilities :
- Proven experience in technologyrisk management, preferably in a financial service or regulated industry& develop and implement technology risk management strategies andpolicies.
- Conduct regular risk assessments,monitoring of Informational Technology (IT) Infrastructure & ServiceManagement (including access management, capacity management, change &patch management, data migration controls, cloud computing services, cryptographiccontrols, physical & environmental controls, Network, database,metrics, VAPT, identity management, and others), identifying potentialvulnerabilities.
- Collaborate with IT teams toensure that security controls and measures are effectively implemented.
- Stay up to date on emergingtechnology risks and regulatory requirements.
- Prepare and present reports ontechnology risk management activities to senior management andstakeholders
- Developing security requirementsand guidelines, and overseeing the implementation of security controls
- Perform Thematic Reviews on Bank’s Products, Applications andTechnology/Platform services in accordance with Risk calendar plan andreport the findings along with management action plan & recommendation
- Monitor operational Key riskindicators (KRI’s) and elevate any potential breaches or concerns relatedto Technology, BCMS, Third Party Risk and Cyber Security domains
- Understanding of Outsourcing& Third-party Vendor risk related regulatory requirements and risksassociated with outsourcing of services by Payments Bank to Third Partyvendor and possessing experience in conducting Third party Vendor riskassessments including cyber security framework and related risk
- Understanding of ISO 22301 BCPrequirements and support the BIA assessment and development of BCMS andcrisis management plan
- Understanding of RBI and CSITEetc. and related regulatory requirements applicable on Technology, BCMS,Cyber security & Third-party vendors
Education
- Bachelor's degree in ComputerScience, Information Technology, Risk Management, or a related field.Master's degree or professional certifications (e.g., CISA, CRISC, CISSP)are a plus.
- Strong understanding of ITsystems, cybersecurity principles, and risk assessment methodologies.
- Familiarity with regulatoryrequirements such as GDPR, PCI DSS, ISO 27001, and other relevantstandards.