Security Analyst - IT GRC & Audit (CSCRF)

Kotak Alternate Asset Managers Limited

Mumbai

On-site

INR 3,500,000 - 6,000,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Kotak Alternate Asset Managers Limited in Mumbai seeks a Security Analyst / Security Engineer to define, implement, and manage the enterprise information security program. You will work with CISO and leadership to drive risk assessment, compliance, and incident response initiatives, and oversee policy development and SOC readiness.

The role emphasizes governance, risk management, and security operations, with collaboration across IT and business units to safeguard assets and data.

Qualifications

  • Bachelor’s degree in Computer Science, Information Technology, or a related field.
  • Master’s degree is preferred.
  • Extensive experience in information security including risk management, compliance & governance, incident response, security operations, and TPRM – Vendor management.

Responsibilities

  • Develop, implement, and continuously enhance information security strategy aligned with business objectives.
  • Establish security governance frameworks, standards, and operating models.
  • Foster a security-first mindset across the organization through leadership and advocacy.
  • Identify, assess, and mitigate cybersecurity and information security risks.
  • Facilitate risk assessments and ensure timely remediation.
  • Embed security controls into systems and processes with IT teams.
  • Develop, implement, and enforce security policies, standards, and guidelines.
  • Ensure policies align with regulatory, legal, and industry best practices.
  • Lead incident response planning, execution, and post-incident analysis.
  • Oversee investigations of security breaches and coordinate disciplinary and legal actions.
  • Ensure readiness through tabletop exercises and simulations.
  • Ensure compliance with laws, regulations, and standards; support audits.
  • Coordinate remediation of audit findings and control gaps.
  • Knowledge of Cyber CSCRF, DPDP & Digital Accessibility frameworks.
  • Establish and operate a Security Operations Centre (SOC).
  • Oversee monitoring, detection, and response to security incidents.
  • Define SOC processes, metrics, and escalation mechanisms.
  • Design and lead security awareness and training programs for employees.
  • Promote best practices in data protection, phishing prevention, and cyber hygiene.
  • Manage, mentor, and develop security teams; collaborate with stakeholders.
  • Provide regular security posture and risk reports to leadership.
  • Define KPIs and metrics to measure cybersecurity controls; drive continuous improvement.
  • Continuously enhance security tools, processes, and frameworks.

Skills

Information security
Risk management
Compliance & governance
Incident response
Security operations
TPRM – Vendor management
Threat intelligence
Cloud security
Ethical hacking / penetration testing
Vulnerability assessment

Education

Bachelor's degree in Computer Science/Information Technology
Master's degree preferred

Job description

Job Description

Job Title: Security Analyst / Security Engineer

Location: Mumbai

Department: Information Technology

Role Level: Manager / Senior Manager

Reports To: CTO / CISO / VP – Technology

Job Summary

The Security Analyst / Security Engineer will be responsible for defining, implementing, and managing the organization’s enterprise information security vision, strategy, and programs to ensure that information assets and technology systems are adequately protected.

The role will work closely with the CISO, VP, senior leadership, and business units to drive risk assessment, risk management, compliance, and incident response initiatives. The incumbent will oversee the Audit, development and enforcement of security policies, standards, and procedures, while fostering a strong security-first culture across the organization.

Key Responsibilities
Security Strategy & Governance
  • Develop, implement, and continuously enhance a comprehensive information security strategy aligned with business objectives.
  • Establish security governance frameworks, standards, and operating models.
  • Foster a security-first mindset across the organization through leadership and advocacy.
Risk Management
  • Identify, assess, and mitigate cybersecurity and information security risks.
  • Facilitate enterprise-wide risk assessments and ensure timely risk remediation.
  • Work with business and IT teams to embed security controls into systems and processes.
  • Should have knowledge for implement TPRM.
Policy & Standards Development
  • Develop, implement, and enforce security policies, standards, and guidelines.
  • Ensure policies are aligned with regulatory, legal, and industry best practices.
Incident Response & Threat Management
  • Lead incident response planning, execution, and post-incident analysis.
  • Oversee investigations of security breaches, including coordination on disciplinary and legal matters.
  • Ensure readiness through tabletop exercises and incident simulations.
Compliance & Regulatory Management
  • Ensure compliance with applicable laws, regulations, and industry standards.
  • Support internal and external audits and regulatory reviews.
  • Coordinate remediation of audit findings and control gaps.
  • Having knowledge of Cyber CSCRF, DPDP & Digital Accessibility framework
Security Operations Centre (SOC)
  • Establish and operationalize a Security Operations Centre (SOC).
  • Oversee monitoring, detection, and response to security incidents.
  • Define SOC processes, metrics, and escalation mechanisms.
Security Awareness & Training
  • Design and lead security awareness and training programs for employees.
  • Promote best practices related to data protection, phishing prevention, and cyber hygiene.
Team Leadership & Stakeholder Management
  • Manage, mentor, and develop a team of security professionals.
  • Collaborate with IT, business units, vendors, and senior leadership.
  • Provide regular security posture and risk reports to senior management and leadership forums.
Measurement & Continuous Improvement
  • Define KPIs and metrics to measure the effectiveness of cybersecurity controls.
  • Continuously assess and improve security tools, processes, and frameworks.
Technical & Functional Skills
  • Strong understanding of information security frameworks and best practices.
  • Hands-on or oversight experience in:
  • Malware analysis
  • Data analysis
  • Cloud security
  • Ethical hacking / penetration testing
  • Vulnerability assessment
  • Experience with security monitoring, incident handling, and threat intelligence.
  • Ability to bridge technical and non-technical discussions effectively.
Qualifications
Education
  • Bachelor’s degree in Computer Science, Information Technology, or a related field .
  • Master’s degree is preferred.
Experience
  • Extensive experience in information security , including:
  • Risk management
  • Compliance & governance
  • Incident response
  • Security operations
  • TPRM – Vendor management
Certifications (Highly Desirable)
  • CISSP
  • CISM
  • CISA
  • Other relevant cybersecurity certifications
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security GRC Consultant @ Mumbai
Cyber Security GRC Consultant @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,600,000 - 2,800,000
GRC Consultant @ Mumbai
GRC Consultant @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,800,000 - 2,400,000
GRC - Security Analyst
GRC - Security Analyst

Jobgether • India

On-site
INR 1,200,000 - 1,800,000
Fully remote in India
Full-time employment
Exposure to multiple security framesk—
+2
Security Analyst
Security Analyst

Cloudxtreme • Mumbai

On-site
INR 1,800,000 - 2,600,000
SOC Engineer
SOC Engineer

Mintskill HR Solutions LLP • Mumbai

On-site
INR 600,000 - 1,000,000
Information Systems Security Manager
Information Systems Security Manager

Idfc First Bank Limited • Navi Mumbai

On-site
INR 2,500,000 - 3,800,000
Business Continuity Manager @ Mumbai
Business Continuity Manager @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,400,000 - 2,000,000
Chief Information Security Officer
Chief Information Security Officer

Yotta Data Services Private Limited • Mumbai

On-site
INR 6,000,000 - 9,000,000
Governance, Risk & Compliance Analyst
Governance, Risk & Compliance Analyst

Hero Fincorp • India

On-site
INR 1,800,000 - 2,600,000
Cybersecurity - Risk & Compliance Analyst
Cybersecurity - Risk & Compliance Analyst

Scybers • Chennai District

On-site
INR 900,000 - 1,500,000