Role Description
LIBERTY GENERAL INSURANCE COMPANY LIMITED
Role:
IT Security Lead Band Professional
Division:
Information Technology
Location:
Thane
Professional Know-how
Academic:
BE IT/BCA/MCA preferred or/and Certified Course from reputed IT institutes
(ISO 27001, CGRC, CRISC)
Experience:
Minimum 8 years in Information Security domain (preferably in BFSI industry).
Competencies
-
Subject knowledge & expertise on Information, Cyber & Data security domains.
- Good understanding of evolving technologies.
- Practical/hands-on experience managing security projects.
- Understanding Business landscape and security applicability.
-
O365 controls, Cloud security, Multi-cloud hybrid environment security, GRC
(Governance, risk & compliance), Information Security Officer, ISO 27001
Implementation or Auditor, Risk management, Risk gap Analysis, Risk
Assessment, ITGC Controls, Control Review, Control Testing.
- Policy development, maintenance, and audits for IRDAI compliance.
- Threat intel and monitoring, TPRM.
-
Oversight on Technology Risk assessment, DLP implementation, Big ID project.
- Manage DPDPA requirements from technology perspective.
Primary Responsibilities
-
Develop, implement and maintain IT governance strategies, policies and
framework to ensure effective management of IT system and processes.
-
Monitoring all IT related processes to ensure compliance with laid down
local and global IT policies.
-
Provide advisory to other verticals of IT on any IT policy compliance
related matters.
-
Drive continuous improvement initiatives to enhance the effectiveness and
efficiency of IT governance processes and controls.
-
Handling security governance including Contract review, Security Control
Identification, Risk Assessment, Monitoring compliance etc.
-
Conduct regular assessments of IT governance practices, identify gaps, and
recommend improvements to enhance efficiency, effectiveness and compliance.
-
Monitoring and evaluating IT Governance related risks and compliance issues,
and develop mitigation plans and controls.
-
Ensure compliance with relevant ISO standards and industry regulations.
-
Conduct gap analysis to identify areas of non-compliance and develop action
plans.
-
Develop and maintain ISO documentation, including procedures, work
instructions, and records.
-
Monitor changes in ISO standards and update company policies accordingly.
-
Develop and deliver training programs to employees on ISO standards and
procedures.
- Communicate ISO requirements and updates to relevant stakeholders.
-
Identify and implement process improvement initiatives to enhance ISO
management system effectiveness.
-
Monitor key performance indicators (KPIs) related to the ISO management
system.
-
Assist in the development and implementation of corrective and preventative
actions.
- Daily monitoring of threat intel and Forti recon platform.
- Oversight of technical project and key IT implementation projects.
- Manage DPDPA requirements from tech perspective.