IT Cybersecurity Manager

2 days ago


Chennai, Tamil Nadu, India BNP Paribas Full time ₹ 8,00,000 - ₹ 12,00,000 per year

Position Purpose

Provide a brief description of the overall purpose of the position, why this position exists and how it will contribute in achieving the teams goal.

Main ScopeRole of Wealth Management India IT Risk and Information Systems Security Manager, being understood this role includes delegations from APAC WM CISO for the team located in India territory and fully participates in overall WMIS Cybersecurity and IT Risk objectives.

Participate to IT project security reviews conducted both on a global and APAC basis across all platforms. Participate in the Security Operation meetings in APAC, EMEA & CH regions. This requires the incumbent to foster close working relationships with other business areas and IT Development/Production/CSIRT/Production Security teams.

The incumbent will work hand in hand with the IT Dev, Prod teams and the business, as an enabler and a facilitator.

Responsibilities

Direct Responsibilities

WM IT Risk and Security Manager

o Manage the WM IT Risk and Security local team in India by managing the recruitment, performances review as well as training and career-path development.

o Coordinate with APAC WM security actors, including India-based resources.

o Coordinate with APAC WM IT teams on risk and security topics, while promoting a secure development and deployment culture

o Assist for a Risk Treatment for any APAC WM issue, based on the WM GAIM generic process.

o Periodic reporting of security status to WM CISO APAC and WM Global CISO

o Contribute to the IT Risk and Cybersecurity Governance including procedural framework, Cybersecurity awareness and communication.

o Ensure the regular reporting for management follow-up

IT Security Compliance (delegation on WM APAC scope)

o Ensure the alignment with the Group and WM GAIM security policies, for both project and production assets.

o Ensure the protection of WM business data with an adequate security level of WM assets, based on project assessment and production review processes.

o Ensure the compliance with regulatory bodies requirements, including for APAC (HKMA, MAS), EU (GDPR), Switzerland (FINMA)

o Leveraging on a deep knowledge of Security standards such as NIST, CIS,ISO2700x , ensure the compliance with the IT security requirements

o Ensure the compliance with the Third-party Technology risks and Cloud security.

o Identify the process gaps and provide solutions.

Application Security

o Ensure the effective implementation of Secure SDL including the DevSecOps and Threat modelling practices.

o Identify and implement the latest security standards for internet facing and internal assets.

o Improve the Vulnerability Management at the application level in terms of efficiency as well as effectiveness (including Static Acceptance Security Testing SAST, Dynamic Acceptance Security Testing DAST and Software Composition Analysis SCA).

Perform Security risk assessments and reviews to be presented to respective committees.

Ensure the adequate security level for all WM GAIM applications, whatever the IT project managers location and hosting provider.

Production Security Oversight (delegation on WM APAC scope)

o Identify the production security requirements and ensure a smooth integration of WM assets within APAC IT Production, including network flow opening and Application Zoning compliance.

o Identify the compliance level of the production environment and contribute to remediation actions definition while keeping the oversight on actions progress.

o Keep an overview and ensure the adequate Vulnerability Management at the server and middleware level leveraging on production scans and liaising with relevant production stakeholders. Contribute to the management of Cybersecurity incidents.

CyberSecurity Program (delegation on WM APAC scope)

o Contribute to the steering and driving of the security initiatives on the APAC scope expected by the WM Cybersecurity Program.

Contributing Responsibilities

Coordination with IT Security actors

o Reporting line to the WM GAIM Global CISO: alignment on the objectives and means, contribution to the different global reporting (WM Cybersecurity Committee, Wholesale Application Security Dashboard)

o Coordination and control of security activities performed by APAC CIB Business Information Security and Production Security teams, including project assessment from production point of view, production security review, user security awareness for the WM scope.

o Coordination with the Swiss Security team concerning integration of WM assets within Swiss IT production.

o Keeping abreast of initiatives by the IT Security community within the Group and other IT Security stakeholders within the Group.

Technical & Behavioral Competencies

Cybersecurity / Technical Value-added Competencies

Cybersecurity Governance: framework (NIST / CIS framework), Security incident management, Logging & Detection (SIEM ELK products)

DevSecOps: CI/CD toolchain knowledge of various tools

o Source code management: sonarQuabe, bibucket, github/gitlab

o Security application scanning (e.g. Sonatype/NexusIQ, Fortify, AppSpider, Qualys, DTR scan)

o Automation/orchestration: Ansible tower, Jenkins

Application Security: Threat modeling, Security architecture key concepts, exposure to various development framework and applicative landscape (Java/Web, Mobile applications, containerization/docker, kubernetes, API management, Cloud security)

Vulnerability Management

o Nexpose, Nessus

Ethical Hacking Knowledge

o Kali Linux knowledge (metasploit, nmap)

Specific Qualifications (if required)

Qualifications and Experience

10 years' experience in information security evaluation and design of technical architectures

Functional as well as technical knowledge of the applications used within BNP Paribas

Knowledge of the Norms and Standards of the BNP Paribas Group, in particular with respect to ITRM & Wholesale IT Security Norms and Policies

Team management experience is a must

Preferred Master level in Computer science and Information Security

Skills Referential

Behavioural Skills: (Please select up to 4 skills)

Communication skills - oral & written

Ability to collaborate / Teamwork

Decision Making

Ability to deliver / Results driven

Transversal Skills: (Please select up to 5 skills)

Ability to set up relevant performance indicators

Ability to develop and adapt a process

Ability to manage a project

Ability to develop others & improve their skills

Ability to manage / facilitate a meeting, seminar, committee, training

Education Level:

Master Degree or equivalent

Experience Level

At least 10 years

Other/Specific Qualifications (if required)

Other Value-added Competencies

  • Advanced IT security certifications may be advantageous (such as CISM, CCSP, CSK, CEH, CISSP).
  • Operational Risk and Permanent Control
  • Data Analytics solutions (Tableau, PowerBI) and strong expertise in Dashboard/reporting


  • Chennai, Tamil Nadu, India Intelspot Cybersecurity Company Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Company DescriptionIntelspot Cybersecurity Company is dedicated to building a comprehensive InfoSec portfolio. We focus on creating and developing security-based solutions tailored to various business domains. Our commitment is to serve businesses by providing reliable and robust cybersecurity solutions that meet their unique needs.Role DescriptionThis is a...


  • Chennai, Tamil Nadu, India Altraize Full time ₹ 10,00,000 - ₹ 25,00,000 per year

    Enterprise Cybersecurity Sales Manager — India (On-site)Industry: System Integration.Sector: Enterprise security solutions, managed security services, networking solutions and cloud security deployments serving mid-market and large enterprise customers across India. This role is fully on-site and focused on accelerating revenue growth through strategic...


  • Chennai, Tamil Nadu, India We are CyberSec Full time ₹ 4,00,000 - ₹ 8,00,000 per year

    Company DescriptionWe are bringing peace to the chaotic cyber world by providing cybersecurity solutions to businesses. Our team of professionals works on cutting-edge projects involving active threat detection, incident response, and cybersecurity management. We are passionate about protecting digital assets through advanced security practices, hands-on...

  • IT / Cybersecurity

    7 days ago


    Chennai, Tamil Nadu, India ti Steps Full time ₹ 6,00,000 - ₹ 12,00,000 per year

    Key Responsibilities:Configure, manage, and monitor network firewalls (e.g., Palo Alto, Fortinet, Cisco, Check Point).Implement and maintain IPsec VPNs for secure remote access and site-to-site connectivity.Administer and optimize Web Application Firewalls (WAF) to protect application traffic.Deploy and manage reverse proxy solutions for secure internal...


  • Chennai, Tamil Nadu, India Hitachi Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Location:Chennai, Tamil Nadu, IndiaJob ID: R0092140Date Posted: Company Name:HITACHI ENERGY TECHNOLOGY SERVICES PRIVATE LIMITEDProfession (Job Category):Engineering & ScienceJob Schedule: Full timeRemote:NoJob Description:The opportunityLeading development of new solutions for complex projects and challenges. Driving completion of all engineering activities...


  • Chennai, Tamil Nadu, India Hitachi Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Location:Chennai, Tamil Nadu, IndiaJob ID: R0092140Date Posted: Company Name:HITACHI ENERGY TECHNOLOGY SERVICES PRIVATE LIMITEDProfession (Job Category):Engineering & ScienceJob Schedule: Full timeRemote:NoJob Description:The opportunityAs an AI/ML Engineer, you will be part of Operation Center, India (INOPC-PG), aiming to develop a global value chain,...


  • Chennai, Tamil Nadu, India Scybers Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    As an ambitious mid-career professional with 5 years of deep technical experience, you will play a crucial role in leading global CIOs and CISOs to build world-class security programs at Scybers. Your responsibilities will include: - Demonstrating proven hands-on expertise in cloud security, threat detection & response, and infrastructure management -...


  • Chennai, Tamil Nadu, India Aptiv Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Help shape the future of mobilityImagine a world with zero vehicle accidents, zero vehicle emissions, and wireless vehicle connectivity all around us. Every day, we move closer to making that world a reality. Aptiv's passionate team of engineers and developers creates advanced safety systems, high-performance electrification solutions and data connectivity...


  • Chennai, Tamil Nadu, India Aptiv Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Help shape the future of mobilityImagine a world with zero vehicle accidents, zero vehicle emissions, and wireless vehicle connectivity all around us. Every day, we move closer to making that world a reality. Aptiv's passionate team of engineers and developers creates advanced safety systems, high-performance electrification solutions and data connectivity...


  • Chennai, Tamil Nadu, India StrongBox IT Full time ₹ 4,50,000 - ₹ 9,00,000 per year

    StrongBox IT is a leading cybersecurity services company dedicated to providing top-notch solutions to safeguard businesses against evolving digital threats. With a commitment to innovation and excellence, we help organizations fortify their digital infrastructure and protect sensitive information from cyberattacks. Job Description: We are seeking dynamic...