Security Analyst - IT GRC & Audit (CSCRF)

Kotak Alternate Asset Managers Limited

Maharashtra

On-site

INR 2,500,000 - 4,000,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Security training

Job summary

Kotak Alternate Asset Managers Limited is seeking a Security Analyst / Security Engineer to define and manage the organization's information security vision, strategy, and programs from Mumbai. You will drive risk assessment, governance, and incident response while aligning with business objectives and regulatory requirements.

The role partners with the CISO, CTO and senior leadership to enforce security policies, manage threats, and foster a security-first culture across IT and business units.

Qualifications

  • Extensive experience in information security governance, risk and compliance.
  • Strong incident response and security operations capabilities are required.
  • Experience with risk assessments, audits, and regulatory programs.
  • Knowledge of TPRM (vendor management) and security controls across IT systems.

Responsibilities

  • Lead security strategy, governance and policy development.
  • Oversee incident response planning, investigations and post-incident reviews.
  • Establish and operate a Security Operations Centre (SOC) and metrics.
  • Coordinate audits, regulatory reviews and remediation of findings.
  • Mentor security team and report security posture to leadership.

Skills

Information security
Cloud security
Incident response
Vulnerability assessment
Threat intelligence
Security monitoring
Data analysis
Malware analysis
Governance & risk
TPRM / vendor management

Education

Bachelor's degree in Computer Science, Information Technology, or a related field
Master's degree preferred

Job description

Job Title: Security Analyst / Security Engineer

Location: Mumbai

Department: Information Technology

Role Level: Manager / Senior Manager

Reports To: CTO / CISO / VP – Technology

Job Summary

The Security Analyst / Security Engineer will be responsible for defining, implementing, and managing the organization’s enterprise information security vision, strategy, and programs to ensure that information assets and technology systems are adequately protected.

The role will work closely with the CISO, VP, senior leadership, and business units to drive risk assessment, risk management, compliance, and incident response initiatives. The incumbent will oversee the Audit, development and enforcement of security policies, standards, and procedures, while fostering a strong security-first culture across the organization.

Key Responsibilities
Security Strategy & Governance
  • Develop, implement, and continuously enhance a comprehensive information security strategy aligned with business objectives.
  • Establish security governance frameworks, standards, and operating models.
  • Foster a security-first mindset across the organization through leadership and advocacy.
Risk Management
  • Identify, assess, and mitigate cybersecurity and information security risks.
  • Facilitate enterprise-wide risk assessments and ensure timely risk remediation.
  • Work with business and IT teams to embed security controls into systems and processes.
  • Should have knowledge for implement TPRM.
Policy & Standards Development
  • Develop, implement, and enforce security policies, standards, and guidelines.
  • Ensure policies are aligned with regulatory, legal, and industry best practices.
Incident Response & Threat Management
  • Lead incident response planning, execution, and post-incident analysis.
  • Oversee investigations of security breaches, including coordination on disciplinary and legal matters.
  • Ensure readiness through tabletop exercises and incident simulations.
Compliance & Regulatory Management
  • Ensure compliance with applicable laws, regulations, and industry standards.
  • Support internal and external audits and regulatory reviews.
  • Coordinate remediation of audit findings and control gaps.
  • Having knowledge of Cyber CSCRF, DPDP & Digital Accessibility framework
Security Operations Centre (SOC)
  • Establish and operationalize a Security Operations Centre (SOC).
  • Oversee monitoring, detection, and response to security incidents.
  • Define SOC processes, metrics, and escalation mechanisms.
Security Awareness & Training
  • Design and lead security awareness and training programs for employees.
  • Promote best practices related to data protection, phishing prevention, and cyber hygiene.
Team Leadership & Stakeholder Management
  • Manage, mentor, and develop a team of security professionals.
  • Collaborate with IT, business units, vendors, and senior leadership.
  • Provide regular security posture and risk reports to senior management and leadership forums.
Measurement & Continuous Improvement
  • Define KPIs and metrics to measure the effectiveness of cybersecurity controls.
  • Continuously assess and improve security tools, processes, and frameworks.
Technical & Functional Skills
  • Strong understanding of information security frameworks and best practices.
  • Hands-on or oversight experience in:
  • Malware analysis
  • Data analysis
  • Cloud security
  • Ethical hacking / penetration testing
  • Vulnerability assessment
  • Experience with security monitoring, incident handling, and threat intelligence.
  • Ability to bridge technical and non-technical discussions effectively.
Qualifications
Education
  • Bachelor’s degree in Computer Science, Information Technology, or a related field.
  • Master’s degree is preferred.
Experience
  • Extensive experience in information security, including:
  • Risk management
  • Compliance & governance
  • Incident response
  • Security operations
  • TPRM – Vendor management
Certifications (Highly Desirable)
  • CISSP
  • CISM
  • CISA
  • Other relevant cybersecurity certifications
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst - IT GRC & Audit (CSCRF)
Security Analyst - IT GRC & Audit (CSCRF)

Kotak Alternate Asset Managers Limited • Mumbai

On-site
INR 3,000,000 - 5,500,000
Cybersecurity Specialist – Governance, Risk & Compliance (GRC)
Cybersecurity Specialist – Governance, Risk & Compliance (GRC)

TalaKunchi Networks Pvt Ltd • Mumbai

On-site
INR 800,000 - 1,200,000
Opportunity to shape InfoSec practices
Work on cutting-edge cybersecurity initiatives
Be part of a forward-thinking team
Governance, Risk & Compliance Analyst
Governance, Risk & Compliance Analyst

Hero Fincorp • India

On-site
INR 1,800,000 - 2,600,000
Info/Security - Analyst
Info/Security - Analyst

Ascendion Engineering • Hyderabad

Hybrid
INR 2,500,000 - 3,800,000
Information Security Analyst
Information Security Analyst

MRO • Pune District

On-site
INR 180,000 - 240,000
IN_Associate_SOC - SIEM_Cyber in Emerging Technology_Advisory_Mumbai
IN_Associate_SOC - SIEM_Cyber in Emerging Technology_Advisory_Mumbai

PwC India • Mumbai

On-site
INR 900,000 - 1,300,000
Chief Information Security Officer
Chief Information Security Officer

Yotta Data Services Private Limited • Mumbai

On-site
INR 4,000,000 - 7,000,000
Security Analyst
Security Analyst

Cloudxtreme • Mumbai

Hybrid
INR 1,800,000 - 2,600,000
SOC Engineer
SOC Engineer

Mintskill HR Solutions LLP • Mumbai

On-site
INR 600,000 - 1,000,000
Cybersecurity - Risk & Compliance Analyst
Cybersecurity - Risk & Compliance Analyst

Scybers • Chennai District

On-site
INR 900,000 - 1,500,000