AVP - Cyber Security
Job Description:
|
Position Title |
Associate Vice President - Cyber Security |
|
Role |
Assist VP Cloud Security & Cyber Security |
|
Reporting To |
Vice President & Lead Cyber Security |
|
Key Responsibilities |
Handling the Cloud Security infrastructure planning, architecture & security operations of SBIL. Drawing up and implementing new Cloud security initiatives, preparing cyber security architecture of the SBIL to meet its projected needs and to remain abreast of times in terms of Cyber Security Standards & Procedures. Guiding and monitoring Vulnerability & Threat Management program, Red team exercises, Cyber Resilience exercises etc. Initiating pro-active compliance measures to comply with legal & regulatory as well as group guidelines.
Key Performance Areas:
ICT Security Infrastructure / Cyber Security Planning & Testing Ø Draw and update periodically Cloud Security program for SBIL Ø Analyse and establish security requirements for SBIL's systems/networks including Cloud setups. Ø Defend systems against unauthorized access, modification and / or destruction. Ø Design Offensive and Defensive cloud Security practices Ø Design vulnerability & threat management program and plan to conduct various types of cloud security compliance assessments / Vulnerability testing, risk analysis etc. to ensure operational security Ø Defining security standards for different areas like technology Cloud risk assessment, access privileges, control structures and resources Ø Oversee and monitor routine Cloud security administration Ø Manage various Cloud security compliance assessments / reviews like Container Security assessment, VA, PT, Application Security, Secure Code review, Secure Configuration review, Secure Network Architecture review, Firewall Rule base review, Security solution review etc. and ensure that periodic security compliance assessments are completed in defined time frame Ø Comprehensive technical security compliance assessments including Cloud Infra VA, PT, secure config review, cloud architecture review, digital forensic readiness review etc. for all new applications & related infrastructure components and providing go ahead for production move Ø Evaluation of all requests pertaining to changes undertaken in the existing applications & infrastructure components including cloud related applications and to identify the risks in context of regulatory InfoSec requirements, SBIL InfoSec policies, industry best practices and accordingly advise/recommend team to adhere the security practices and providing go ahead for production move Ø Coordination with IT and ISSP (Information Security Service Provider) teams to undertake the cyber security testing / review / assessment and risk mitigation activity smoothly. Ø Review / Presentation of Dashboards and Action Taken Reports of all types of security assessments / reviews (planned periodic or changes) related to pertaining to applications including APIs, infrastructure, solutions etc. to senior management Ø Pursue with IT teams for closer / mitigation of reported vulnerabilities Ø To review and provide inputs, recommend compensatory controls during the exceptions/deviations process.
Ø Review / Recommend /Approve Firewall Access Rules and other Rules / Policies of Cyber Security Solutions Ø Manage Cyber Security Maturity Assessment initiatives Ø Research and recommend security upgrades, new security solutions etc. Ø Provide technical advice to colleagues Ø Management reporting Ø Co-ordinate with external/regulatory agencies
Vendor Management Ø Maintain relationships with SBIL's partners who support various IT security infrastructure components, reviews / assessments etc. Ø Ensure that all the testing activity undertaken by ISSP as per the agreed scope and completed in the defined time frame. Ø Enhance the level of monitoring mechanisms for these partners' performance and delivery standards / SLAs Ø Negotiate contracts with vendors and manage costs and schedule of deliverables. Ø Work with multi department and multi vendor situations.
Compliance Ø Ensure implementation of proper standards for cyber risk governance as well as regulatory compliance Ø Be responsible for cyber security management and compliance with Information and Cyber Security policy framework as well as legal /regulatory (IRDAI, CERT-In, etc.) prescriptions and Group guidelines
Provide Expertise Ø Provide industry expertise in all aspects of the SBIL's Cyber security needs/program. Ø Track a broad range of emerging cyber security technologies to determine their maturity and applicability to the SBIL. Ø Map current and future cyber security standards Ø Develop standards and benchmarking for IT & Cyber Security being used in the SBIL. Ø Evaluate the cost efficiency of emerging security related technologies and assess their applicability to current needs of the SBIL. |
|
Critical competencies |
· Professional degree /certifications · Knowledge in the areas of Information and Cyber Security · Team building, Coordination, Follow-up, Persuasive |
|
Person Profile |
(i)Engineering Graduate/ Management Graduate with CCSP/ CCSK / GCP / AWS Certified and having minimum 12 to 15 years of total experience, out of which minimum 6 to 8 years’ extensive experience in the areas of managing Cloud Security planning & assessments / testing / reviews. (ii)eWPT (eLearn Security Web Application Penetration Testing) would be an added advantage (iii)CISSP / OSCP certifications are preferable
Preference will be given to candidates having professional certifications of CISSP / OSCP and having knowledge as well as job experience in system administration/management of application software development & support apart from the above cyber security mgmt. experience
Key Skills - · Keen interest in Information and Cyber Security relate developments in the BFSI sector • Attention to detail, analytical abilities and the ability to recognize trends in data • Creativity and patience; Logic and objectivity; Inquisitive nature • Proactive approach with the confidence to make decisions • Methodical and well-organised approach to work • Ability to work under pressure and meet deadlines • Good communication skills and the ability to interact effectively with a range of people • Understanding of confidentiality issues and the law relating to them |
Company Profile
‘The Company’), one of the most trusted --- --- companies in India, was incorporated in October 2000 & is registered with the --- Regulatory & Development Authority of India (IRDAI) in March 2001. Serving millions of families across India, --- ---’s diverse range of products caters to individuals as well as group customers through Protection, Pension, Savings & Health solutions. Driven by ‘Customer-First’ approach, --- --- places great emphasis on maintaining world class operating efficiency & providing hassle-free claim settlement experience to its customers by following high ethical standards of service. Additionally, --- --- is committed to enhance digital experiences for its customers, distributors & employees alike.
Apply Now
- Interested candidates are requested to apply for this job.
- Recruiters will evaluate your candidature and will get in touch with you.