
Lead-Governance Risk and Compliance
4 days ago
Job Description
- DUTIES & RESPONSIBILITIES
AREAS
ACTIVITIES
1
2
3
4
5
6
7
LEADERSHIP
GOVERNANCE
RISK ASSESSMENT
SUPPLY CHAIN RISK MANAGEMENT
AWARENESS & TRAINING
POLICY COMPLIANCE
MISCELLANEOUS
- Perform other duties as assigned to ensure the smooth functioning of the department.
- Recommend programmatic and technical inputs and operate with a high degree of independence in matters relating to the investigation, impact, and analysis of security incidents, decisions regarding risk, and measures for computer and network security.
- Operate with a high degree of independence with regard to project management activities, including development of project plans and resource estimates.
- Understand, assist and co-ordinate for legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations
- Develop and share Weekly, Monthly and Yearly reports with Head – Information Security, showcasing status and posture of Information Security Program at Nayara Energy
- Develop and maintain Information Security Online Dashboard for Information Security
- Develop & implement Information Security Metrics Program for continuous monitoring and assessing the effectiveness of Information Security controls
- Co-ordinate with relevant functions to collect required data for the Information Security Metrics Program
- Assist Head Information Security to design, implement, and maintain Nayara's cybersecurity plan and Information Security Program.
- Assist Head Information Security for other governance activities.
- Identify and document asset vulnerabilities and threats (internal and external).
- Receive cyber threat intelligence from information sharing forums and sources.
- Identify potential business impacts and likelihoods.
- Use threats, vulnerabilities, likelihoods, and impacts to determine risk.
- Identify and prioritize risk responses.
- Suggest risk mitigations & IT controls and ensuring information security best practices are designed, implemented and monitored.
- Co-ordinate for Risk Assessment of Business Function's IT systems
- Benchmark and compare security practices with the industry. Demonstrate knowledge, Implementation, operations and maintenance of information security standards and frameworks like NIST Cyber Security Framework, ISO/IEC 27001, COBIT, ITIL, etc. as applicable.
- Develop & Implement Information/Cyber Security Supply Chain Risk Management framework
- Assist Head Information Security to ensure organizational stakeholders identify, establish, assess, manage, & agree to cyber supply chain risk management processes.
- Use contracts with suppliers and third-party partners to implement appropriate measures designed to meet the objectives of an organization's cybersecurity program and Information / Cyber Security Supply Chain Risk Management Framework.
- Routinely assess suppliers and third-party partners using audits, test results, or other forms of evaluations to confirm they are meeting their contractual obligations.
- Conduct response, recovery planning and testing with suppliers and third-party providers.
- Develop content for Information Security refresher awareness training and New Joiner induction program
- Assist Head Information Security to ensure all users are informed and trained.
- Assist Head Information Security to ensure privileged users, senior executives, third-party stakeholders, physical and cybersecurity personnel understand their roles and responsibilities.
- Lead the system-wide information security compliance program, ensuring IT activities, processes, and procedures meet defined requirements, policies and regulations.
- Develop and implement effective and reasonable policies and practices to secure protected and sensitive data and ensure information security and compliance with relevant legislation and legal interpretation.
- Execute strategy for dealing with increasing number of audits, compliance checks and external assessment processes for internal/external auditors based on NIST Cyber Security Framework
- Assist with forensics, analysis and fact gathering.
- Record and track Information security incidents, including but not limited to copyright violations, compromised accounts, e-mail threats, and abuse reports from various sources.
Responsibilities
- DUTIES & RESPONSIBILITIES
AREAS
ACTIVITIES
1
2
3
4
5
6
7
LEADERSHIP
GOVERNANCE
RISK ASSESSMENT
SUPPLY CHAIN RISK MANAGEMENT
AWARENESS & TRAINING
POLICY COMPLIANCE
MISCELLANEOUS
- Perform other duties as assigned to ensure the smooth functioning of the department.
- Recommend programmatic and technical inputs and operate with a high degree of independence in matters relating to the investigation, impact, and analysis of security incidents, decisions regarding risk, and measures for computer and network security.
- Operate with a high degree of independence with regard to project management activities, including development of project plans and resource estimates.
- Understand, assist and co-ordinate for legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations
- Develop and share Weekly, Monthly and Yearly reports with Head – Information Security, showcasing status and posture of Information Security Program at Nayara Energy
- Develop and maintain Information Security Online Dashboard for Information Security
- Develop & implement Information Security Metrics Program for continuous monitoring and assessing the effectiveness of Information Security controls
- Co-ordinate with relevant functions to collect required data for the Information Security Metrics Program
- Assist Head Information Security to design, implement, and maintain Nayara's cybersecurity plan and Information Security Program.
- Assist Head Information Security for other governance activities.
- Identify and document asset vulnerabilities and threats (internal and external).
- Receive cyber threat intelligence from information sharing forums and sources.
- Identify potential business impacts and likelihoods.
- Use threats, vulnerabilities, likelihoods, and impacts to determine risk.
- Identify and prioritize risk responses.
- Suggest risk mitigations & IT controls and ensuring information security best practices are designed, implemented and monitored.
- Co-ordinate for Risk Assessment of Business Function's IT systems
- Benchmark and compare security practices with the industry. Demonstrate knowledge, Implementation, operations and maintenance of information security standards and frameworks like NIST Cyber Security Framework, ISO/IEC 27001, COBIT, ITIL, etc. as applicable.
- Develop & Implement Information/Cyber Security Supply Chain Risk Management framework
- Assist Head Information Security to ensure organizational stakeholders identify, establish, assess, manage, & agree to cyber supply chain risk management processes.
- Use contracts with suppliers and third-party partners to implement appropriate measures designed to meet the objectives of an organization's cybersecurity program and Information / Cyber Security Supply Chain Risk Management Framework.
- Routinely assess suppliers and third-party partners using audits, test results, or other forms of evaluations to confirm they are meeting their contractual obligations.
- Conduct response, recovery planning and testing with suppliers and third-party providers.
- Develop content for Information Security refresher awareness training and New Joiner induction program
- Assist Head Information Security to ensure all users are informed and trained.
- Assist Head Information Security to ensure privileged users, senior executives, third-party stakeholders, physical and cybersecurity personnel understand their roles and responsibilities.
- Lead the system-wide information security compliance program, ensuring IT activities, processes, and procedures meet defined requirements, policies and regulations.
- Develop and implement effective and reasonable policies and practices to secure protected and sensitive data and ensure information security and compliance with relevant legislation and legal interpretation.
- Execute strategy for dealing with increasing number of audits, compliance checks and external assessment processes for internal/external auditors based on NIST Cyber Security Framework
- Assist with forensics, analysis and fact gathering.
- Record and track Information security incidents, including but not limited to copyright violations, compromised accounts, e-mail threats, and abuse reports from various sources.
Qualifications
- SKILLS & KNOWLEDGE
- Educational Qualifications & Allied Skills:
- Bachelor's or master's degree in computer science, information systems, or equivalent work experience. An M.B.A. or M.S. in information security is preferred.
- Minimum of 9-13 years of experience in a combination of risk management, information security and IT jobs.
- Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate security and risk-related concepts to technical and nontechnical audiences.
- Proven track record and experience in developing information security policies and procedures, as well as successfully executing programs that meet the objectives of excellence in a dynamic en vironment
- Knowledge and understanding of relevant legal and regulatory requirements, such as IT Act 2000, and Payment Card Industry/Data Security Standard, NIST Cyber Security Framework, etc.
- Exhibit excellent analytical skills, the ability to manage multiple projects under strict timelines, as well as the ability to work well in a demanding, dynamic environment and meet overall objectives
- Project management skills: financial/budget management, scheduling and resource management
- Professional security management certification, such as a Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified Ethical Hacker (CEH) or other similar credentials, is desired
- Knowledge of common information security management frameworks, such as ISO/IEC 27001, ITIL, COBIT and ones from NIST
- Audit of financial systems
- Audit of SAP system
-
Credit Risk Model Governance
2 weeks ago
Mumbai, Maharashtra, India Risk Inn Full time ₹ 6,00,000 - ₹ 18,00,000 per yearApply Now:Join a top-tier firm and contribute to high-impact projects in a rapidly evolving risk and analytics landscape. Please Read the Job Description and apply if you fulfil the criteria. Click this link to submit your application after reviewing the details below: We are currently supporting our client in India, a leadingRisk Analytics and Consulting...
-
Lead-Governance Risk and Compliance
4 days ago
Mumbai, Maharashtra, India NAYARA Energy Full time ₹ 20,00,000 - ₹ 25,00,000 per yearDUTIES & RESPONSIBILITIESAREASACTIVITIES1234567LEADERSHIPGOVERNANCERISK ASSESSMENTSUPPLY CHAIN RISK MANAGEMENTAWARENESS & TRAININGPOLICY COMPLIANCEMISCELLANEOUSPerform other duties as assigned to ensure the smooth functioning of the department.Recommend programmatic and technical inputs and operate with a high degree of independence in matters relating to...
-
Manager IT Governance Risk and Compliance
7 days ago
Mumbai, Maharashtra, India Indusind Bank Full time ₹ 15,00,000 - ₹ 25,00,000 per yearRole & responsibilitiesCompliance Oversight: Ensure that all IT operations, systems, and processes adhere to relevant regulatory requirements, including RBI/SEBI guidelines, and cybersecurity standards.Regulatory Reporting: Strong knowledge in KRI, Public Facing App & DB, Tranche reporting.End to end management of Regulatory submissions: Assign, co-ordinate...
-
Mumbai, Maharashtra, India Ares Management Full time ₹ 12,00,000 - ₹ 36,00,000 per yearOver the last 20 years, Ares' success has been driven by our people and our culture. Today, our team is guided by our core values – Collaborative, Responsible, Entrepreneurial, Self-Aware, Trustworthy – and our purpose to be a catalyst for shared prosperity and a better future. Through our recruitment, career development and employee-focused programming,...
-
Governance Risk And Compliance Analyst- Grc
1 week ago
Navi Mumbai, Maharashtra, India Mizuho Global Services Full time ₹ 12,00,000 - ₹ 36,00,000 per yearPosition: Governance Risk & Compliance - GRC AnalystJob location :- GhansoliNo of vacancy :- 2Walkin drive date and time :- 11th & 12th Sept at 2pm to 5pm13th Sept at 9am to 12pmWe are seeking a skilled and vigilant L2 for handling Governance Risk and Compliance for MGS. The Ideal candidate will ensure that an organizations operations and procedures meet...
-
Testing - Engineers & Lead - Risk & Compliance
4 weeks ago
Mumbai, Maharashtra, India AQM Technologies Full timeWe are hiring at AQM Technologies Pvt. LtdWe are seeking a skilled Tester s with Risk and Compliances with 2-7 years of experienceThe ideal candidate will be based at Chennai location – Work from office mode.Job Description:Job Title: Engineers / Senior Test Engineers - Risk and CompliancesLocation: Mumbai ( Work From Office)Experience: 4+ yrsReporting To:...
-
Testing - Engineers & Lead - Risk & Compliance
4 weeks ago
Mumbai, Maharashtra, India AQM Technologies Full timeWe are hiring at AQM Technologies Pvt. Ltd We are seeking a skilled Tester s with Risk and Compliances with 2-7 years of experience The ideal candidate will be based at Chennai location – Work from office mode. Job Description: Job Title: Engineers / Senior Test Engineers - Risk and Compliances Location: Mumbai ( Work From Office) Experience: 4+ yrs ...
-
HR governance compliance
2 weeks ago
Mumbai, Maharashtra, India Weekday AI Full time ₹ 9,00,000 - ₹ 12,00,000 per yearThis role is for one of Weekday's clientsMin Experience: 3 yearsLocation: mumbaiJobType: full-timeRequirementsWe are seeking a detail-oriented and proactive HR Governance & Compliance Specialist to join our Human Resources team. This role is critical in ensuring that all HR practices, policies, and procedures are compliant with applicable laws, regulations,...
-
Head Risk And Compliance
4 days ago
Mumbai, Maharashtra, India Stay Ahedge Full time ₹ 20,00,000 - ₹ 25,00,000 per yearRole SummaryAs key member of the leadership team, report into the Board/Designated Director and work closely with business headsServe as the Principal Officer (PO) for the companyManage end-to-end compliance with regulatory requirements (RBI, FIU-IND, PMLA, SEBI/IRDAI), enterprise-wide risk management and strong governance in digital financial services...
-
Risk Compliance Manager
1 day ago
Mumbai, Maharashtra, India SUN INFOSYSTEMS Full time ₹ 15,00,000 - ₹ 25,00,000 per yearWe're Hiring: Risk & Compliance ManagerLocation:BKC Mumbai, MaharashtraWe're looking for an experienced professional with a strong background ininvestment riskorpension fund risk managementto take on aRisk Officer role. The ideal candidate will bring deep expertise in regulatory compliance, risk assessment, and governance across financial and pension...