Sr Lead - IT Risk & GRC

Star Union Dai-ichi Life Insurance Company Limited

Navi Mumbai

On-site

INR 1,500,000 - 2,500,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

A leading insurance firm in Navi Mumbai is seeking a Security Operations Center (SOC) Governance professional. This role involves managing 24x7 SOC services and overseeing risk management and incident response activities. The ideal candidate will have a strong understanding of industry standards such as NIST and ISO 27001, coupled with proven experience in security operations. The position offers opportunities to define security architecture standards and promote a security-aware culture across the organization.

Qualifications

  • Proven experience in managing 24x7 Security Operations Centers (SOC).
  • Strong understanding of NIST, ISO 27001, and industry best practices.
  • Ability to produce executive dashboards and reports.

Responsibilities

  • Govern SOC services and define operating models.
  • Oversee risk management and vulnerability processes.
  • Lead security incident response activities.

Skills

Security operations management
Risk assessment
Incident response
Vulnerability management
Security governance
Security awareness
Identity and access management

Job description

Security Operations Center (SOC) Governance
  • Own and govern 24x7 Security Operations Center (SOC) services delivered by external vendors.
  • Define SOC operating model, SLAs, KPIs, escalation procedures, and reporting mechanisms.
  • Oversee monitoring, detection, triage, and response activities across endpoints, networks, servers, cloud, and applications.
  • Act as the primary point of contact for SOC vendors and security service providers.
  • Define and maintain security architecture standards aligned with NIST, ISO 27001, IRDAI, and BFSI best practices.
  • Establish baseline security controls across infrastructure (on-prem, cloud, network, endpoints).
  • Lead and coordinate security incident response activities for high and critical incidents.
  • Act as a senior technical advisor during cyber incidents, including ransomware, phishing, malware, and data leakage events.
  • Ensure incident containment, eradication, recovery, root‑cause analysis, and post‑incident reviews.
Vulnerability & Risk Management
  • Oversee vulnerability management processes driven by vendors and internal teams.
  • Ensure infrastructure risk assessments are performed and remediated in a timely manner.
  • Track, prioritize, and report cyber risks to senior management and risk forums.
  • Produce meaningful metrics on vulnerabilities, threats, and remediation effectiveness.
Metrics, Reporting & Governance
  • Define security operations KPIs and KRIs for SOC, incidents, vulnerabilities, and recovery readiness.
  • Provide executive dashboards and quarterly reports on security posture to CIO, CISO, and senior leadership.
  • Support audits, regulatory assessments, and compliance reporting (IRDAI, ISO).
Secondary Responsibilities
Identity & Access Management (IAM)
  • Define and enforce MFA, RBAC, segregation of duties, and just‑in‑time / just‑enough‑access models.
  • Coordinate with IAM and PAM vendors (e.g., One Identity) for implementation and operations.
Security Awareness & Culture
  • Promote a strong security‑aware culture within IT and across the organization.
  • Support security awareness and phishing simulation programs driven by internal teams or vendors.
Personal Data Discovery & Classification (DPDP‑Tool Implementation)
  • Ensure tools and processes are implemented to discover, classify, and label personal and sensitive personal data across:
  • Core insurance applications
  • Document management systems
  • Email, endpoints, databases, and cloud storage (Azure)
  • Work with IT and vendors to implement data tagging and classification policies (PII, financial data, medical data).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead - Information Security and GRC
Lead - Information Security and GRC

ABC - Aditya Birla Housing Finance Limited • Maharashtra

On-site
INR 1,200,000 - 1,800,000
Lead - Information Security and GRC
Lead - Information Security and GRC

ABC - Aditya Birla Housing Finance Limited • Maharashtra

On-site
INR 2,400,000 - 4,200,000
SOC / Security Operations Lead
SOC / Security Operations Lead

Paytm • Dadri

On-site
INR 3,500,000 - 7,000,000
Manager - IT Security - SCO
Manager - IT Security - SCO

DP World • Maharashtra

On-site
INR 1,500,000 - 2,100,000
Manager - IT Security - SCO
Manager - IT Security - SCO

DP World • Navi Mumbai

On-site
INR 1,200,000 - 1,800,000
Information Technology Security Specialist
Information Technology Security Specialist

Senvion India • Mumbai

On-site
INR 2,500,000 - 4,200,000
Cyber Security Operations Analyst
Cyber Security Operations Analyst

Spigot Software • Ahmedabad District

On-site
INR 900,000 - 1,500,000
Technical Security Manager
Technical Security Manager

Pay10 India • New Delhi

On-site
INR 1,300,000 - 2,100,000
Assistant Vice President – Information Security
Assistant Vice President – Information Security

IndiaFirst Life • Mumbai

On-site
INR 1,000,000 - 1,500,000
Team Lead - SOC
Team Lead - SOC

Indian Financial Technology And Alliedservices • Hyderabad

On-site
INR 1,800,000 - 2,500,000