<p style=" line-height:normal;background:white;"><strong>Roles and
Responsibilities:
</strong></p><ul type="disc"><li style="color:#222222;line-height:normal; background:white;">Ensure Compliance with the Regulatory requirements w.r.t the Information and Cyber Security requirements - RBI, UIDAI, CIC, etc.</li><li style="color:#222222;line-height:normal; background:white;">Identify and develop the InfoSec Policy, Processes, and Procedures to incorporate the industry benchmarks / best practices and the latest trends.</li><li style="color:#222222;line-height:normal; background:white;">To identify, track, monitor &amp; ensure compliance with InfoSec Policy, Regulatory, Legal &amp; Audit requirements.</li><li style="color:#222222;line-height:normal; background:white;">To develop &amp; manage InfoSec Training &amp; awareness.</li><li style="color:#222222;line-height:normal; background:white;">Work with respective stakeholders to ensure that the Policy/Procedures, regulatory, legal &amp; audit requirements for Information and cyber security are understood and implemented on a continual basis.</li><li style="color:#222222;line-height:normal; background:white;">Monitor &amp; track the compliance to all relevant processes/practices to ensure that they are followed as desired.</li><li style="color:#222222;line-height:normal; background:white;">Liaison with internal and external Security Audits and assessments – VAPT, GDPR/ISO 27001 compliance.</li><li style="color:#222222;line-height:normal; background:white;">Establish continual improvement processes to mitigate identified gaps &amp; improve overall maturity<strong>&nbsp;</strong>to provide adequate assurance.</li><li style="color:#222222;line-height:normal; background:white;">Establish security metrics based on agreed KGIs/KPIs to monitor &amp; track compliance.</li><li style="color:#222222;line-height:normal; background:white;">Escalate deviations and violations on time.</li><li style="color:#222222;line-height:normal; background:white;">Remain updated with the latest security trends and related regulatory &amp; legal requirements.</li><li style="color:#222222;line-height:normal; background:white;">To maintain the required security posture for cloud security, primarily AWS &amp; GCP</li><li style="color:#222222;line-height:normal; background:white;">To maintain &amp; improve code security &amp; DevopsSec practices</li><li style="color:#222222;line-height:normal; background:white;">To maintain &amp; improve the endpoint security, by bringing in DLP and data classification practices.</li><li style="color:#222222;line-height:normal; background:white;">To review and improve email, apps &amp; network security.</li><li style="color:#222222;line-height:normal; background:white;">To run periodic phishing campaigns.</li><li style="color:#222222;line-height:normal; background:white;">To respond third-party risk assessment questionnaire</li><li style="color:#222222;line-height:normal; background:white;">Perform Independent Internal Audit and assessment in line with Regulatory requirements - RBI, UIDAI, CIC, V-CIP, DLG, etc.</li></ul><p style=" line-height:normal;background:white;"><br></p><p style=" line-height:normal;background:white;"><strong>Key Skills and Qualifications</strong></p><ul type="disc"><li style="color:#222222;line-height:normal; background:white;">Bachelor of Engineering/Computer Science or equivalent from a recognized University</li><li style="color:#222222;line-height:normal; background:white;">The ability to interact efficiently with peers and customers is required.</li><li style="color:#222222;line-height:normal; background:white;">4-6 years with relevant experience in establishing &amp; managing InfoSec Governance and compliance.</li><li style="color:#222222;line-height:normal; background:white;">Should have sound knowledge &amp; experience in developing Enterprise Frameworks, Policies, and Processes by adopting Industry Best Practices and standards like ISO27001, and Regulatory Guidelines.</li><li style="color:#222222;line-height:normal; background:white;">Should have strong analytical and communication skills.</li><li style="color:#222222;line-height:normal; background:white;">Should have sound knowledge, experience &amp; understanding of Compliance Management.</li><li style="color:#222222;line-height:normal; background:white;">Should have the ability to develop and effectively measure, and present Dashboard/reports with or without GRC tools.</li><li style="color:#222222;line-height:normal; background:white;">Should have experience in developing InfoSec awareness programs and rendering InfoSec awareness sessions.</li><li style="color:#222222;line-height:normal; background:white;">An individual with 2-3 years of IT experience in Cloud Security would be preferred.</li><li style="color:#222222;line-height:normal; background:white;">Candidates with professional security certificates like CISA, CISM, and ISO27001 Lead Auditor would be preferred.</li><li style="color:#222222;line-height:normal; background:white;">A good understanding of cloud security, AWS, and GCP is a must to have.</li></ul><ul><li>A good understanding of the Data Privacy Framework - GDPR, India Data Privacy Act, etc.</li></ul><div><br></div><div><strong style="box-sizing: border-box; outline: 0px; font-weight: 700; color: rgb(0, 0, 0); font-family: -apple-system, BlinkMacSystemFont, ;">Note: Looking for Immediate Joiner/30 days</strong></div><div><strong style="box-sizing: border-box; outline: 0px; font-weight: 700; color: rgb(0, 0, 0); font-family: -apple-system, BlinkMacSystemFont, ;">Work Mode: Work at office only(No Hybrid/WFH)</strong></div><div><strong style="box-sizing: border-box; outline: 0px; font-weight: 700; color: rgb(0, 0, 0); font-family: -apple-system, BlinkMacSystemFont, ;">Experience: 1- 6 years</strong></div>
Job details are sourced from the employer's original posting.
Open job postingAbout the company
KreditBee is a digital lending platform that offers instant personal loans to salaried and self-employed individuals.