AVP- Information Security Governance & Risk
Position Title:
AVP- Information Security Governance & Risk
Reports to:
CISO
Location:
Chennai
This position is required in information security to conduct the risk
assessment of various aspects of information security. He will be responsible
to conduct risk pertaining to the policy, procedure, third party etc and
update or maintain the risk register as per the risk ratings. He will also be
responsible for preparing and maintain the KRI & thresholds by collect
various data prepare for management reviews and assisting in various other
risk activities as below.
ORGANIZATIONAL OVERVIEW
Northern Arc Capital's mission is to provide efficient and reliable access to
debt capital markets for institutions that impact low-income households. These
include rural & urban micro finance institutions, retail NBFCs, and
housing finance companies. Northern Arc Capital connects these institutions
with capital markets and investors such as banks, insurance companies, and
mutual funds through financial tools such as securitization, credit
enhancement and debt structuring.
ROLES AND RESPONSIBILITIES
-
Review and update of the information asset register in accordance with
RBI
,
SEBI
,
IRDAI
,
UIDAI
,
IT Outsourcing
,
Data Localization
and
ISO 27001:2013
requirements
-
Responsible to manage, track, update and monitor all regulatory
requirements.
-
Review the classification levels of data, maintaining risk register and
tracking.
-
Create and manage the KRI matrix and thresholds as per compliance,
technology, policy and process.
-
Conduct data privacy or PII reviews with intra department for PII protection
for customers and employees.
-
Conduct policy and process risk assessment of vendors, while onboarding,
evaluation and to monitor, and maintaining the same.
-
Provide assistance in IT security product & services risk assessment
during evaluation and procurement.
-
Track the annual review, changes of all policies and procedures, draft and
update/consolidate to policy documents as needed.
-
Assist in preparing decks/updates for committee meetings and other
management review decks.
-
Review the reports and alerts and ensure to close with service groups.
-
Access Control Reviews for cloud, application and infrastructure.
-
Comprehensive risk assessment and control testing to be carried out annually
and sustenance.
-
Assist in conducting the various simulations and campaigns for awareness and
maintain measure the effectiveness.
-
Assist in Information security projects implementation.
-
Conduct access control, change management and other process level reviews.
-
Timely escalation to right stakeholder, if any deliverable is at risk.
-
Working closely with IT and other business function of the organization for
IS assessments and various risk review activities.
SKILLS AND QUALIFICATIONS
-
ISMS implementation
, policy & procedure
-
Risk analysis and assessments
-
Conceptual knowledge of infrastructure technology and services
e.g Server infrastructure, development, Firewalls, NAC, Router etc.
-
Proactive
and ability to handle independently with business functions
-
Understanding of business processes
across all functions.
-
8+ Experience in ISMS and in
ISO 27001
-
CISA
&
ISO 27001 Certification
SPECIFICATIONS: QUALIFICATIONS, EXPERIENCE, & COMPETENCIES
Minimum Qualifications:
Graduate
Minimum Experience:
6-8 Years
Skills Required:
-
Result oriented & Persistent
-
Analytical/planning/Detail Orientation