Information Security-grc

7 days ago


Powai Mumbai Maharashtra, India CRISIL Full time

**Role / Designation**: Manager - Information Security Governance, Risk & Compliance Job Level: 12A/13A Job location: Mumbai Employment type: On-Roll Reporting Manager: Chief Information Security Officer Accountabilities: 1. Establishing and maintaining Information security program conforming to ISO/IEC 27001:2015 for uplifting the cyber resilience and incident response for CRISIL in compliance to Information Security and Cybersecurity Policy, Common Security Standards, Technical Security Standards, Industry best practices and CISO Directives. 2. Responsible for assisting CISO in reporting to CRISIL Management and IT Risk Committee the critical cyber security threats and vulnerabilities that CRISIL is exposed to, ensuring emerging cyber threats and the bank’s preparedness in response to these threats are reported and discussed in the CRISIL IT Risk Committee.

3. Be the focal person for CRISIL during various audits, be able to communicate accurately and effectively CRISIL’s security posture and regulatory compliance status. Be the point of contact and interact regularly with regulatory agencies and Computer Emergency Response Team (CERT-In). 4.

Support and manage ISO 27001 and SOC2Type2 external and internal audits. 5. Responsible for driving the regulatory compliance for Cyber Security Framework and all current and future advisory notes received from the regulator. 6.

Being the information security and cyber policy owner, responsible for development of (but not limited to) CRISIL Information Security and Cyber Security Policy, Data Governance and Classification Policy, Access Control Policy, Acceptable use of assets and asset management policy. 7. Keep abreast with country specific cyber threats through maintaining close work relationship with regulatory agencies CERT-In, attend RBI’s cyber events & trainings 8. Establish a Cyber Management Group with representations from CRISIL management and functional heads.

Establish and maintain the Cyber Incident Response Plan (CIRT) which defines the roles and responsibilities amongst key functional stakeholders during a cyber incident. 9. Planning and executing periodic cyber breach simulation exercises, make sure CRISIL Branch is well prepared for any cyber breach incidents with widespread impacts. 10.

Responsible for developing CRISIL cybersecurity KRIs and KPIs and presenting the KRIs and KPIs to CRISIL risk committee for independent challenge and management oversight. 11. Work with the CISO & CIO to develop a holistic risk management framework for CRISIL. 12.

14. Manage risks associated with third party suppliers, conduct third party due diligence and ongoing risk management activities in accordance to the bank’s Third-Party Risk Management Framework. 15. Conduct Information Security awareness training periodically to general staffs and functional leads across the CRISIL.

16. Communication should be expert. Education / Experience / Other Information - Bachelor degree in Engineering or Graduation in Computer Science degree or equivalent degree - 12-15 years’ experience in information security, cybersecurity, technology risk management in large multinational financial / technology institutions environment - ISMS ISO 27001 LI/LA and other Security related certifications viz., CISA / CISM (or equivalent) is an advantage. - Hand-on experience on Process definitions, process drafting, documentation, conducting and managing audits, knowledge of Data privacy laws of various countries - Excellent verbal and written communication skills.

**No. of Openings**: 01



  • Mumbai, Maharashtra, India Black Box Full time

    About Black Box, a trusted IT solutions provider delivering cutting-edge technology solutions and world-class consulting services in Unified Communications, Enterprise Networking, Data Center, Digital Applications and Cyber Security.We are looking for –Position : GRC LeadLocation : Mumbai (Client office)Work Model : Onsite (Work from Office)Job...


  • Mumbai Metropolitan Region, India Priceline Full time

    This role is eligible for our hybrid work model: Two days in-office. Why is this job a big deal: The position is responsible for coordinating Priceline’s risk and compliance projects, elevating our security posture. As a leading tech company, this role requires an understanding of our existing infrastructure, cybersecurity controls and risk profi le, as...


  • Mumbai Metropolitan Region, India Priceline Full time

    This role is eligible for our hybrid work model: Two days in-office.Why is this job a big deal:The position is responsible for coordinating Priceline’s risk and compliance projects, elevating our security posture. As a leading tech company, this role requires an understanding of our existing infrastructure, cybersecurity controls and risk profi le, as well...


  • Mumbai, Maharashtra, India Datavail Full time

    **Job Title: Information Security and Compliance Analyst** **Education: Any Degree** **Location: Mumbai** **Experience: 0 -1 year** **Key Skills: ISMS, PIMS, CISA, ISO 27001:2022 LI/LA, ISO 27701:2019 LI / LA and PCI DSS** Information Security and Compliance Associate Reports to Sr. Director of Information Security. Information Security and Compliance...


  • Mumbai, Maharashtra, India Datavail Full time

    **Job Title: Information Security and Compliance Associate** **Education: Any Degree** **Location: Mumbai** **Experience: 0 -1 year** **Key Skills: ISMS, PIMS, CISA, ISO 27001:2022 LI/LA, ISO 27701:2019 LI / LA and PCI DSS** Information Security and Compliance Associate Reports to Sr. Director of Information Security. Information Security and Compliance...


  • Mumbai, Maharashtra, India Bajaj Electricals Full time

    **Job Title: SAP GRC and Basis Administrator**: Job Summary: The SAP GRC and Basis Administrator is responsible for the configuration, maintenance, and support of SAP systems, with a focus on Governance, Risk, and Compliance functionalities. This role involves ensuring the stability, security, and compliance of SAP systems while providing technical support...


  • Mumbai Metropolitan Region, India Priceline Full time

    Priceline is a leading online travel company with a US subsidiary that offers a hybrid work model. This role is eligible for two days of in-office work.We are looking for a skilled Information Security Compliance Specialist to join our team.Responsibilities:Coordinate security GRC projects and initiatives to improve our security posture.Maintain security...


  • Mumbai, India TAC Security Full time

    Job Title: Information Security Analyst Location: Lower Parel, Mumbai (On-site) Job Description: We are seeking a skilled Information Security Analyst to join our team in Lower Parel, Mumbai. In this role, you will play a critical part in monitoring and enhancing our cybersecurity posture. Key Responsibilities: Monitor security alerts and events using...


  • Mumbai, India TAC Security Full time

    Job Title: Information Security AnalystLocation: Lower Parel, Mumbai (On-site)Job Description:We are seeking a skilled Information Security Analyst to join our team in Lower Parel, Mumbai. In this role, you will play a critical part in monitoring and enhancing our cybersecurity posture.Key Responsibilities:- Monitor security alerts and events using SIEM...


  • mumbai, India TAC Security Full time

    Job Title: Information Security AnalystLocation: Lower Parel, Mumbai (On-site)Job Description:We are seeking a skilled Information Security Analyst to join our team in Lower Parel, Mumbai. In this role, you will play a critical part in monitoring and enhancing our cybersecurity posture.Key Responsibilities:Monitor security alerts and events using SIEM tools...


  • Mumbai, Maharashtra, India Priceline Full time

    This role plays a pivotal part in elevating our security posture through the coordination of risk and compliance projects at Priceline, a US subsidiary of the world's biggest online travel company.Key Responsibilities:The Security Risk & Compliance Associate will be an integral member of a high-performing and diverse information security team. As part of a...

  • Open Pages Grc

    2 months ago


    Pune, Maharashtra, India Cognizant Full time

    **Job Summary** **Responsibilities** **Responsibilities**: Develop and maintain custom solutions using IBM OpenPages GRC REST API and Java API Implement solutions for OpenPages GRC platform deployments Write reports and programs to support governance risk and compliance GRC initiatives Deliver highquality technical deliverables Utilize triggers to...


  • Mumbai, India TAC Security Full time

    Job Title: Information Security Analyst Location: Lower Parel, Mumbai (On-site)Job Description:We are seeking a skilled Information Security Analyst to join our team in Lower Parel, Mumbai. In this role, you will play a critical part in monitoring and enhancing our cybersecurity posture.Key Responsibilities:Monitor security alerts and events using SIEM tools...


  • mumbai, India TAC Security Full time

    Job Title: Information Security Analyst Location: Lower Parel, Mumbai (On-site) Job Description: We are seeking a skilled Information Security Analyst to join our team in Lower Parel, Mumbai. In this role, you will play a critical part in monitoring and enhancing our cybersecurity posture. Key Responsibilities: Monitor security alerts and events using...


  • Mumbai, India VISTRA Full time

    It’s never been a more exciting time to join Vistra. At Vistra our purpose is progress. We believe that our clients have the power to change the world and to do great things for global progress, and we exist to remove the friction that comes from the complexity of global business – to help our clients achieve progress without friction. But...


  • Mumbai, India VISTRA Full time

    It’s never been a more exciting time to join Vistra. At Vistra our purpose is progress. We believe that our clients have the power to change the world and to do great things for global progress, and we exist to remove the friction that comes from the complexity of global business – to help our clients achieve progress without friction. But progress...

  • IT Audit Grc

    1 week ago


    Mumbai, India AMBC Technologies Full time

    **Experience and Qualifications Required** MUST HAVE - 2 to 6 years experience in **Governance Risk and Compliance**, Information & cyber Security in a large organization, preferably Financial Services and having a good know-how of: - Management of Information Security Policies, Procedures and Controls - Detailed working experience of information security...


  • Mumbai, Maharashtra, India Clover Infotech Pvt Ltd Full time

    Clover Infotech Pvt Ltd is seeking a highly skilled Information Security Delivery Lead to join our team. As a key member of our cybersecurity team, you will be responsible for managing cybersecurity services delivery teams and handling deliveries to customers. You will also be required to plan, lead change management, work in a fast-paced environment, and...


  • Mumbai, India inMorphis Full time

    Skill required to perform the duty : - 5 years of experience in more than one of the following disciplines : operational risk management, enterprise risk management, business continuity and disaster recovery, vendor management, audit management, corporate compliance, and policy management.- Support implementation of GRC strategies- Conduct risk assessments,...


  • Sion, Mumbai, Maharashtra, India Anzen Technologies Pvt Ltd Full time

    We are looking for in-house trainers with experience in below areas **:Ethical Hacking and Penetration testing ** Digital Forensics Incident Response ( DFIR ), Incident Handling and Response, Computer Hacking & Forensic Investigations, SOC / IR **GRC - ISO 27001 ** Security Solutions - Firewalls, Proxy, Active Directory, IPS / IDS, Threat Modelling, Attack...