Pune
9 days ago
Lead I - Cloud Infrastructure Services (Risk & Compliance Lead)

Job Purpose:
The Cybersecurity function enables businesses and functions to manage information security and cybersecurity risks, ensuring that risks and controls are assessed and implemented appropriately, objectively, and independently by subject matter experts.

The Cybersecurity Lead – Risk and Compliance IT supports the Chief Information Security Officer for Enterprise Technology as part of the 1st Line of Defence (1LoD). This role focuses primarily on Cybersecurity for Enterprise Technology, specifically Risk and Compliance IT, and to a lesser extent covers other parts of Enterprise Technology and supports the CTO CISO Team.

Key Responsibility Areas:

Governance & Reporting

Collate cybersecurity monitoring and risk data, translating technical findings into stakeholder-ready reports.

Represent Cybersecurity in relevant governance and management forums.

Ensure security requirements from Risk and Compliance IT are communicated to central Cybersecurity functions for adequate coverage and prioritisation.

Collaborate with Enterprise Technology, Cybersecurity, and business functions (e.g., CCO, Enterprise Risk Management, BIRO).

Information Security Risk Management & Remediation

Understand and address cybersecurity risks, threats, vulnerabilities, and critical assets in Risk and Compliance IT.

Drive risk management and remediation activities, ensuring timely completion.

Ensure adherence to cybersecurity controls and enable access to cybersecurity services for business projects.

Support resolution of major security incidents across Enterprise Technology.

Regulatory Compliance

Support Regional Information Security Officers (RISO) in meeting local regulatory cybersecurity requirements.

Collaborate with central Cybersecurity teams on compliance with industry standards (e.g., PCI-DSS, SWIFT).

Assist with regulatory, audit, and external security engagements (e.g., SOX/EARS).

Specific Requirements:

Bachelor’s degree and/or experience in IT security governance and operational processes, preferably in financial services or global corporate environments.

Desirable (but not essential) background in risk management, audit, or ISR.

Desirable certifications: ISO 27001, CISA, CISM, CISSP, CRISC.

Willingness to travel domestically and internationally as required.

Strong stakeholder communication skills, able to adapt technical language for non-technical audiences.

Demonstrated experience in customer service delivery, relationship building, and collaborative working.

Self-motivated, adaptable, and proactive in personal and professional development.

Core Competencies:

Cybersecurity Risk & Compliance: Proven experience in governance, reporting, risk management, remediation, and regulatory compliance within enterprise technology, specifically in Risk and Compliance IT.

Technical Skills: Ability to represent cybersecurity in governance forums, interpret technical data for business audiences, manage security risks, lead remediation efforts, and ensure regulatory/audit readiness.

Por favor confirme su dirección de correo electrónico: Send Email