Security Analyst - IT GRC & Audit (CSCRF)

Kotak Alternate Asset Managers Limited

Mumbai

On-site

INR 3,000,000 - 5,500,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Kotak Alternate Asset Managers Limited is seeking a Security Analyst / Security Engineer to define, implement, and manage the organization’s enterprise information security vision, strategy, and programs. The role collaborates with the CISO, CTO, VP - Technology, and leadership to drive risk assessment, compliance, and incident response initiatives.

The incumbent will oversee policy development, security governance, and enforcement, ensuring a security-first culture and readiness through

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, or a related field.
  • Master's degree is preferred.

Responsibilities

  • Develop and implement enterprise information security strategy and program.
  • Oversee security policies, standards, and procedures.
  • Lead risk assessments, compliance initiatives, and incident response.
  • Establish and operate the SOC; monitor, detect, and respond to incidents.
  • Drive security awareness and training across the organization.

Skills

Information security
Risk assessment
Incident response
Security governance
Leadership
Communication
Vulnerability management
Threat intelligence

Education

Bachelor's degree in Computer Science/IT
Master's degree (preferred)

Tools

SIEM
Vulnerability Scanning
Penetration Testing

Job description

Job Title: Security Analyst / Security Engineer

Department: Information Technology

Role Level: Manager / Senior Manager

Reports To: CTO / CISO / VP - Technology

Job Summary

The Security Analyst / Security Engineer will be responsible for defining, implementing, and managing the organization’s enterprise information security vision, strategy, and programs to ensure that information assets and technology systems are adequately protected.

The role will work closely with the CISO, VP, senior leadership, and business units to drive risk assessment, risk management, compliance, and incident response initiatives. The incumbent will oversee the Audit, development and enforcement of security policies, standards, and procedures, while fostering a strong security-first culture across the organization.

Key Responsibilities
Security Strategy & Governance
  • Develop, implement, and continuously enhance a comprehensive information security strategy aligned with business objectives.
  • Establish security governance frameworks, standards, and operating models.
  • Foster a security-first mindset across the organization through leadership and advocacy.
  • Identify, assess, and mitigate cybersecurity and information security risks.
  • Facilitate enterprise-wide risk assessments and ensure timely risk remediation.
  • Work with business and IT teams to embed security controls into systems and processes.
  • Should have knowledge for implement TPRM.
Policy & Standards Development
  • Develop, implement, and enforce security policies, standards, and guidelines.
  • Ensure policies are aligned with regulatory, legal, and industry best practices.
  • Lead incident response planning, execution, and post-incident analysis.
  • Oversee investigations of security breaches, including coordination on disciplinary and legal matters.
  • Ensure readiness through tabletop exercises and incident simulations.
Compliance & Regulatory Management
  • Ensure compliance with applicable laws, regulations, and industry standards.
  • Support internal and external audits and regulatory reviews.
  • Coordinate remediation of audit findings and control gaps.
  • Having knowledge of Cyber CSCRF, DPDP & Digital Accessibility framework
Security Operations Centre (SOC)
  • Establish and operationalize a Security Operations Centre (SOC).
  • Oversee monitoring, detection, and response to security incidents.
  • Define SOC processes, metrics, and escalation mechanisms.
Security Awareness & Training
  • Design and lead security awareness and training programs for employees.
  • Promote best practices related to data protection, phishing prevention, and cyber hygiene.
Team Leadership & Stakeholder Management
  • Manage, mentor, and develop a team of security professionals.
  • Collaborate with IT, business units, vendors, and senior leadership.
  • Provide regular security posture and risk reports to senior management and leadership forums.
Measurement & Continuous Improvement
  • Define KPIs and metrics to measure the effectiveness of cybersecurity controls.
  • Continuously assess and improve security tools, processes, and frameworks.
Technical & Functional Skills
  • Strong understanding of information security frameworks and best practices.
  • Hands-on or oversight experience in:
  • Malware analysis
  • Data analysis
  • Ethical hacking / penetration testing
  • Vulnerability assessment
  • Experience with security monitoring, incident handling, and threat intelligence.
  • Ability to bridge technical and non-technical discussions effectively.
Qualifications
Education
  • Bachelor's degree in Computer Science, Information Technology, or a related field.
  • Master's degree is preferred.
Experience
  • Extensive experience in information security, including:
  • Compliance & governance
  • Security operations
Certifications (Highly Desirable)
  • CISSP
  • CISM
  • CISA
  • Other relevant cybersecurity certifications
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Analyst
Senior Information Security Analyst

Quantiphi • Bengaluru Urban

On-site
INR 900,000 - 1,500,000
Senior Manager
Senior Manager

Calpion Software Technologies • Bengaluru Urban

On-site
INR 2,500,000 - 3,000,000
Cyber Security Analyst
Cyber Security Analyst

thehivecareers.co • Bengaluru

On-site
INR 800,000 - 1,200,000
Senior Analyst – GRC & Privacy
Senior Analyst – GRC & Privacy

TechDefence Labs • Mumbai

On-site
INR 1,400,000 - 2,100,000
Cyber security Analyst
Cyber security Analyst

Stefanini North America and APAC • Maharashtra

On-site
INR 900,000 - 1,500,000
Lead Security GRC Analyst
Lead Security GRC Analyst

Providence India • Hyderabad

On-site
INR 2,500,000 - 4,000,000
Security Engineer / Analyst
Security Engineer / Analyst

Lodha • Mumbai City

On-site
INR 1,200,000 - 1,800,000
Senior GRC Analyst
Senior GRC Analyst

3M HEALTHCARE • Hyderabad

On-site
INR 1,500,000 - 2,200,000
GRC Engineer
GRC Engineer

Indian Institute of Technology Delhi (IIT Delhi) • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Cyber Security Analyst
Cyber Security Analyst

Vidal Health Insurance • Bengaluru

On-site
INR 180,000 - 300,000