Roles and Responsibilities:
- Ensure compliance with regulatory requirements related to Information and Cyber Security (e.g., RBI, UIDAI, CIC).
- Identify and develop InfoSec policies, processes, and procedures aligned with industry benchmarks and best practices.
- Monitor and ensure compliance with InfoSec policies, regulatory, legal, and audit requirements.
- Develop and manage InfoSec training and awareness programs.
- Collaborate with stakeholders to ensure understanding and implementation of policies, procedures, and compliance requirements.
- Track and monitor adherence to processes and practices.
- Coordinate with internal and external security audits and assessments (e.g., VAPT, GDPR, ISO 27001).
- Implement continuous improvement processes to address gaps and enhance security maturity.
- Establish security metrics based on KPIs/KGIs to monitor compliance.
- Escalate deviations and violations promptly.
- Stay updated on the latest security trends and regulatory requirements.
- Maintain security posture for cloud environments, primarily AWS and GCP.
- Ensure code security and DevSecOps practices are followed.
- Enhance endpoint security through DLP and data classification practices.
- Review and improve email, application, and network security measures.
- Conduct periodic phishing campaigns.
- Respond to third-party risk assessment questionnaires.
- Perform internal audits and assessments in line with regulatory requirements (e.g., RBI, UIDAI, CIC).
Key Skills and Qualifications:
- Bachelor's degree in Engineering, Computer Science, or equivalent from a recognized university.
- Effective communication and interaction skills.
- 4-6 years of relevant experience in InfoSec governance and compliance management.
- Knowledge of enterprise frameworks, policies, and standards like ISO 27001 and regulatory guidelines.
- Strong analytical and communication skills.
- Experience in compliance management and dashboard/report development (with or without GRC tools).
- Experience in developing and delivering InfoSec awareness programs.
- 2-3 years of IT experience in cloud security is preferred.
- Professional security certifications such as CISA, CISM, or ISO 27001 Lead Auditor are preferred.
- Understanding of cloud security, AWS, and GCP is essential.
- Knowledge of data privacy frameworks like GDPR and India Data Privacy Act.
Disclaimer:
This job description outlines the general responsibilities and may change. Employment is at-will.
Data Utilization Disclaimer:
By applying, you agree that your data may be used for recruitment purposes in accordance with our privacy policy and applicable laws.