Lead-Governance Risk and Compliance

2 days ago


Mumbai, Maharashtra, India Nayara Energy Full time ₹ 1,00,00,000 - ₹ 3,00,00,000 per year

Job Description

  • DUTIES & RESPONSIBILITIES

AREAS
ACTIVITIES
1
2
3
4
5
6
7
LEADERSHIP
GOVERNANCE
RISK ASSESSMENT
SUPPLY CHAIN RISK MANAGEMENT
AWARENESS & TRAINING
POLICY COMPLIANCE
MISCELLANEOUS

  • Perform other duties as assigned to ensure the smooth functioning of the department.
  • Recommend programmatic and technical inputs and operate with a high degree of independence in matters relating to the investigation, impact, and analysis of security incidents, decisions regarding risk, and measures for computer and network security.
  • Operate with a high degree of independence with regard to project management activities, including development of project plans and resource estimates.
  • Understand, assist and co-ordinate for legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations
  • Develop and share Weekly, Monthly and Yearly reports with Head – Information Security, showcasing status and posture of Information Security Program at Nayara Energy
  • Develop and maintain Information Security Online Dashboard for Information Security
  • Develop & implement Information Security Metrics Program for continuous monitoring and assessing the effectiveness of Information Security controls
  • Co-ordinate with relevant functions to collect required data for the Information Security Metrics Program
  • Assist Head Information Security to design, implement, and maintain Nayara's cybersecurity plan and Information Security Program.
  • Assist Head Information Security for other governance activities.
  • Identify and document asset vulnerabilities and threats (internal and external).
  • Receive cyber threat intelligence from information sharing forums and sources.
  • Identify potential business impacts and likelihoods.
  • Use threats, vulnerabilities, likelihoods, and impacts to determine risk.
  • Identify and prioritize risk responses.
  • Suggest risk mitigations & IT controls and ensuring information security best practices are designed, implemented and monitored.
  • Co-ordinate for Risk Assessment of Business Function's IT systems
  • Benchmark and compare security practices with the industry. Demonstrate knowledge, Implementation, operations and maintenance of information security standards and frameworks like NIST Cyber Security Framework, ISO/IEC 27001, COBIT, ITIL, etc. as applicable.
  • Develop & Implement Information/Cyber Security Supply Chain Risk Management framework
  • Assist Head Information Security to ensure organizational stakeholders identify, establish, assess, manage, & agree to cyber supply chain risk management processes.
  • Use contracts with suppliers and third-party partners to implement appropriate measures designed to meet the objectives of an organization's cybersecurity program and Information / Cyber Security Supply Chain Risk Management Framework.
  • Routinely assess suppliers and third-party partners using audits, test results, or other forms of evaluations to confirm they are meeting their contractual obligations.
  • Conduct response, recovery planning and testing with suppliers and third-party providers.
  • Develop content for Information Security refresher awareness training and New Joiner induction program
  • Assist Head Information Security to ensure all users are informed and trained.
  • Assist Head Information Security to ensure privileged users, senior executives, third-party stakeholders, physical and cybersecurity personnel understand their roles and responsibilities.
  • Lead the system-wide information security compliance program, ensuring IT activities, processes, and procedures meet defined requirements, policies and regulations.
  • Develop and implement effective and reasonable policies and practices to secure protected and sensitive data and ensure information security and compliance with relevant legislation and legal interpretation.
  • Execute strategy for dealing with increasing number of audits, compliance checks and external assessment processes for internal/external auditors based on NIST Cyber Security Framework
  • Assist with forensics, analysis and fact gathering.
  • Record and track Information security incidents, including but not limited to copyright violations, compromised accounts, e-mail threats, and abuse reports from various sources.

Responsibilities

  • DUTIES & RESPONSIBILITIES

AREAS
ACTIVITIES
1
2
3
4
5
6
7
LEADERSHIP
GOVERNANCE
RISK ASSESSMENT
SUPPLY CHAIN RISK MANAGEMENT
AWARENESS & TRAINING
POLICY COMPLIANCE
MISCELLANEOUS

  • Perform other duties as assigned to ensure the smooth functioning of the department.
  • Recommend programmatic and technical inputs and operate with a high degree of independence in matters relating to the investigation, impact, and analysis of security incidents, decisions regarding risk, and measures for computer and network security.
  • Operate with a high degree of independence with regard to project management activities, including development of project plans and resource estimates.
  • Understand, assist and co-ordinate for legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations
  • Develop and share Weekly, Monthly and Yearly reports with Head – Information Security, showcasing status and posture of Information Security Program at Nayara Energy
  • Develop and maintain Information Security Online Dashboard for Information Security
  • Develop & implement Information Security Metrics Program for continuous monitoring and assessing the effectiveness of Information Security controls
  • Co-ordinate with relevant functions to collect required data for the Information Security Metrics Program
  • Assist Head Information Security to design, implement, and maintain Nayara's cybersecurity plan and Information Security Program.
  • Assist Head Information Security for other governance activities.
  • Identify and document asset vulnerabilities and threats (internal and external).
  • Receive cyber threat intelligence from information sharing forums and sources.
  • Identify potential business impacts and likelihoods.
  • Use threats, vulnerabilities, likelihoods, and impacts to determine risk.
  • Identify and prioritize risk responses.
  • Suggest risk mitigations & IT controls and ensuring information security best practices are designed, implemented and monitored.
  • Co-ordinate for Risk Assessment of Business Function's IT systems
  • Benchmark and compare security practices with the industry. Demonstrate knowledge, Implementation, operations and maintenance of information security standards and frameworks like NIST Cyber Security Framework, ISO/IEC 27001, COBIT, ITIL, etc. as applicable.
  • Develop & Implement Information/Cyber Security Supply Chain Risk Management framework
  • Assist Head Information Security to ensure organizational stakeholders identify, establish, assess, manage, & agree to cyber supply chain risk management processes.
  • Use contracts with suppliers and third-party partners to implement appropriate measures designed to meet the objectives of an organization's cybersecurity program and Information / Cyber Security Supply Chain Risk Management Framework.
  • Routinely assess suppliers and third-party partners using audits, test results, or other forms of evaluations to confirm they are meeting their contractual obligations.
  • Conduct response, recovery planning and testing with suppliers and third-party providers.
  • Develop content for Information Security refresher awareness training and New Joiner induction program
  • Assist Head Information Security to ensure all users are informed and trained.
  • Assist Head Information Security to ensure privileged users, senior executives, third-party stakeholders, physical and cybersecurity personnel understand their roles and responsibilities.
  • Lead the system-wide information security compliance program, ensuring IT activities, processes, and procedures meet defined requirements, policies and regulations.
  • Develop and implement effective and reasonable policies and practices to secure protected and sensitive data and ensure information security and compliance with relevant legislation and legal interpretation.
  • Execute strategy for dealing with increasing number of audits, compliance checks and external assessment processes for internal/external auditors based on NIST Cyber Security Framework
  • Assist with forensics, analysis and fact gathering.
  • Record and track Information security incidents, including but not limited to copyright violations, compromised accounts, e-mail threats, and abuse reports from various sources.

Qualifications

  • SKILLS & KNOWLEDGE
  • Educational Qualifications & Allied Skills:
  • Bachelor's or master's degree in computer science, information systems, or equivalent work experience. An M.B.A. or M.S. in information security is preferred.
  • Minimum of 9-13 years of experience in a combination of risk management, information security and IT jobs.
  • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate security and risk-related concepts to technical and nontechnical audiences.
  • Proven track record and experience in developing information security policies and procedures, as well as successfully executing programs that meet the objectives of excellence in a dynamic en vironment
  • Knowledge and understanding of relevant legal and regulatory requirements, such as IT Act 2000, and Payment Card Industry/Data Security Standard, NIST Cyber Security Framework, etc.
  • Exhibit excellent analytical skills, the ability to manage multiple projects under strict timelines, as well as the ability to work well in a demanding, dynamic environment and meet overall objectives
  • Project management skills: financial/budget management, scheduling and resource management
  • Professional security management certification, such as a Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified Ethical Hacker (CEH) or other similar credentials, is desired
  • Knowledge of common information security management frameworks, such as ISO/IEC 27001, ITIL, COBIT and ones from NIST
  • Audit of financial systems
  • Audit of SAP system


  • Mumbai, Maharashtra, India NAYARA Energy Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    DUTIES & RESPONSIBILITIESAREASACTIVITIES1234567LEADERSHIPGOVERNANCERISK ASSESSMENTSUPPLY CHAIN RISK MANAGEMENTAWARENESS & TRAININGPOLICY COMPLIANCEMISCELLANEOUSPerform other duties as assigned to ensure the smooth functioning of the department.Recommend programmatic and technical inputs and operate with a high degree of independence in matters relating to...


  • Mumbai, Maharashtra, India Indusind Bank Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Role & responsibilitiesCompliance Oversight: Ensure that all IT operations, systems, and processes adhere to relevant regulatory requirements, including RBI/SEBI guidelines, and cybersecurity standards.Regulatory Reporting: Strong knowledge in KRI, Public Facing App & DB, Tranche reporting.End to end management of Regulatory submissions: Assign, co-ordinate...


  • Mumbai, Maharashtra, India Bytewise Techlabs Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Looking for a Manager – Governance, Risk & Compliance (GRC) with 7–9 yrs experience in BFSI. Must have hands-on exposure to SEBI/RBI regulations, ISO 27001, ITGC, audits, and cybersecurity governance. Certifications like CISA/CISM preferred.


  • Navi Mumbai, Maharashtra, India Hexaware Technologies Full time ₹ 1,20,000 - ₹ 3,00,000 per year

    Key Responsibilities:Plan and conduct regular Fraud Risk Assessment and assess risks to determine the Fraud Risk ProfileIdentify the potential Fraud risks and suggest appropriate controls for the sameEvaluate outcomes using risk based approach and adapt activities to improve FRMFollow the Fraud reporting process and coordinated approach to investigation and...


  • Mumbai, Maharashtra, India Bytewise Techlabs Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Hiring Assistant Manager – Governance, Risk & Compliance (GRC) with 4–6 yrs experience in BFSI/NBFC. Must have hands-on exposure to SEBI/RBI/IRDAI compliance, ISO 27001, ITGC, audits, and cybersecurity risk management. CISA/CISM preferred.


  • Mumbai, Maharashtra, India Ares Management Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Over the last 20 years, Ares' success has been driven by our people and our culture. Today, our team is guided by our core values – Collaborative, Responsible, Entrepreneurial, Self-Aware, Trustworthy – and our purpose to be a catalyst for shared prosperity and a better future. Through our recruitment, career development and employee-focused programming,...


  • Navi Mumbai, Maharashtra, India Mizuho Global Services Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Position: Governance Risk & Compliance - GRC AnalystJob location :- GhansoliNo of vacancy :- 2Walkin drive date and time :- 11th & 12th Sept at 2pm to 5pm13th Sept at 9am to 12pmWe are seeking a skilled and vigilant L2 for handling Governance Risk and Compliance for MGS. The Ideal candidate will ensure that an organizations operations and procedures meet...


  • Mumbai, Maharashtra, India Stay Ahedge Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Role SummaryAs key member of the leadership team, report into the Board/Designated Director and work closely with business headsServe as the Principal Officer (PO) for the companyManage end-to-end compliance with regulatory requirements (RBI, FIU-IND, PMLA, SEBI/IRDAI), enterprise-wide risk management and strong governance in digital financial services...


  • Mumbai, Maharashtra, India SUN INFOSYSTEMS Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    We're Hiring: Risk & Compliance ManagerLocation:BKC Mumbai, MaharashtraWe're looking for an experienced professional with a strong background ininvestment riskorpension fund risk managementto take on aRisk Officer role. The ideal candidate will bring deep expertise in regulatory compliance, risk assessment, and governance across financial and pension...


  • Mumbai, Maharashtra, India N53 Tech Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Location:MumbaiFunction:TechnologyExperience Required:Assistant Manager -4–6 years (with 2+ years relevant in BFSI/NBFC)Manager - 7–9 years (with 5+ years relevant in BFSI/NBFC)We're seeking an Assistant Manager/Manager – Governance, Risk & Compliance (GRC) to play a vital role in leading information security governance, regulatory compliance...