Information Security Risk Management Lead

3 weeks ago


Hyderabad, Telangana, India SMARTWORK IT SERVICES Full time

Information Security Risk Management (IRM) Lead

Location : Bangalore, Chennai, Hyderabad

Experience : 11-15 Years

Employment Type : Full-time

Job Overview :

We're seeking a highly experienced and strategic Information Security Risk Management (IRM) professional to develop, manage, and execute the IRM program across Mashreq Bank. This mid-senior level role is critical in enhancing the bank's resilience by effectively identifying, assessing, and mitigating information security risks, both internal and external. You'll bring sound expertise in information security, robust project management skills, and a proven ability to engage with senior and executive management.

Job Description :

- Develop, implement, and continuously mature the Information Security Risk Management program across the entire organization.

- Play a critical role in effectively identifying, assessing, and mitigating information security risks, stemming from both internal operations and external third parties.

- Manage enterprise-level projects with multiple stakeholders, providing advisory support and ensuring successful outcomes.

- Possess strong experience and knowledge across the broader Information Security and Cyber Security domains, including governance frameworks, policy and procedure development, compliance management, risk management, and security incident response.

- Conduct comprehensive risk assessments, including business impact analysis, threat modeling, and vulnerability assessments.

- Implement and manage Third-Party Risk Management (TPRM) programs, performing detailed supplier risk assessments.

- Maintain and enhance the bank's Information Security Management System (ISMS), ensuring alignment with industry best practices and regulatory requirements.

- Drive the prioritization of security risks and mitigation efforts, making sound, data-driven decisions.

- Collaborate effectively with various internal teams (e.g., IT operations, legal, compliance, business units) and external partners.

- Prepare and present detailed risk reports, findings, and recommendations to senior management and executive leadership.

- Stay updated on emerging information security threats, industry trends, and regulatory changes, integrating new insights into the IRM program.

- Contribute to the development and enforcement of information security policies and standards.

Required Skills & Experience :

- 11-15 years of total experience in the Information Security domain, with a strong focus on risk management.

- Minimum 4+ years of experience in project management of complex engagements, involving multiple stakeholder interactions and advisory support to clients.

- Expertise in TPRM (Third-Party Risk Management), supplier risk assessment, and overall risk management frameworks.

- Proven experience in managing and enhancing an ISMS (Information Security Management System).

- Sound knowledge and practical expertise in conducting various types of risk assessments.

- Strong understanding and practical experience across Information Security and Cyber Security domains, including governance, policy procedures, compliance management, risk management, and security incident response.

- Experience working in the banking domain or with banking/payment industry clients is essential.

- Strong interpersonal, analytical, and technical skills.

- Demonstrated strong decision-making and prioritization skills.

- At least one of the following industry certifications: CISM, CISA, CISSP, CRISC.

(ref:hirist.tech)

  • Hyderabad, Telangana, India Citratech IT Services Private Limited Full time

    Job DescriptionClient's Digital Assets is seeking an experienced Information Security Risk Analyst to support the implementation and ongoing compliance of ISO27001 and SOC2 frameworks. This role will be responsible for conducting risk assessments, identifying control gaps, and collaborating with cross-functional teams to develop and monitor remediation...


  • Hyderabad, Telangana, India NTT DATA Business Solutions Full time ₹ 8,00,000 - ₹ 20,00,000 per year

    As part of the global NTT DATA Group, one of the most successful IT service providers in the world, we specialize in value-added SAP solutions as NTT DATA Business Solutions. With over 16,000 employees in more than 30 countries, we design, implement, and develop custom-fit SAP solutions for our global customers.Would you like to take the next step in your...


  • Hyderabad, Telangana, India NTT DATA North America Full time US$ 1,50,000 - US$ 2,00,000 per year

    Req ID:327098NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Lead information Security engineer to join our team in Hyderabad, Telangana (IN-TG), India (IN)."NTT DATA Services...


  • Hyderabad, Telangana, India CUBE CONSULTANCY SERVICES Full time

    With a growing workforce of 170 employees, we are committed to maintaining the highest standards of security and integrity in all our operations. We are seeking a dynamic and experienced Chief Information Security Officer (CISO) to join our team and lead our cybersecurity initiatives.Job Responsibilities :- Develop, implement, and monitor a strategic,...


  • Hyderabad, Telangana, India Amazon Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Do you want to be instrumental in the success of some of Amazon's strategic and high impact projects and programs. Risk Manager, Vendor Security works as an individual contributor, capable of contributing to the delivery of technical global programs and projects, managing stakeholders, assessing the security risk of vendors by partnering with multiple...


  • Hyderabad, Telangana, India Cube Consultancy Services Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Job Responsibilities:Develop, implement, and monitor a strategic, comprehensive enterprise information security and IT risk management program to ensure the integrity, confidentiality, and availability of information owned, controlled, or processed by the organization.Manage the enterprise's information security organization, consisting of direct reports and...


  • Hyderabad, Telangana, India Amazon Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    DESCRIPTIONDo you want to be instrumental in the success of some of Amazon's strategic and high impact projects and programs. Risk Manager, Vendor Security works as an individual contributor, capable of contributing to the delivery of technical global programs and projects, managing stakeholders, assessing the security risk of vendors by partnering with...


  • Hyderabad, Telangana, India Transcend Full time

    About us: Transcend Street Solutions ( ) is a global Fintech company headquartered in New Jersey, USA, with a global technology center in Hyderabad. We are on an exciting journey to help capital market participants improve financial performance, operational efficiency, and risk management. With game-changing technology solutions deployed at world-leading...


  • Hyderabad, Telangana, India iBASIS Full time

    The Chief Information Security Officer (CISO) will serve as the executive owner of the companys information and cyber security strategy, overseeing all aspects of security operations, governance, and risk management.The CISO will be responsible for protecting iBASISs critical telecom infrastructure, customer data, intellectual property, and global services...


  • Hyderabad, Telangana, India iBASIS Full time

    Chief Information Security Officer Location : Hyderabad India. Department : IT/IS.ABOUT iBASIS : iBASIS is the leading communication solutions provider enabling operators and digital players worldwide to perform and transform. iBASIS is the first independent international communications specialist, ranking as the third largest global wholesale voice operator...