ISS:Head - Information Security Governance & Technology Risk
About this role
Job Title: Head of Technology Risk & Info Sec Governance
Job Summary: The Head of Technology Risk & Info Sec governance will be responsible for overseeing and managing the technology risk framework within the organization and governance matters around Information Security. This role involves
- identifying, assessing, and mitigating risks associated with the use of technology in business operations
- providing an integrated risk framework around all aspects of cyber & tech risk including resilience, continuity, vendors, security etc. through governance on these matters
- ensuring compliance to internal policy and regulatory aspects of cyber security and technology risk
- This includes ensuring Compliance tracking support to infosec teams by tracking regulatory guidelines, ensuring data collation, review and timely submission of daily / monthly / quarterly returns.
- This includes ensuring handling regulatory, compliance and audit interactions and addressing key actionables from such processes and closure of observations that may come from such interactions.
- ensuring risks are reviewed and escalated
The ideal candidate will have a strong background in operations & technology risk management, cybersecurity, and compliance, with the ability to lead a team and collaborate with various stakeholders to ensure the organization's technology infrastructure is secure and resilient.
Key Responsibilities: overseeing the following three aspects of technology risk & information security governance
- Technology Risk
- Develop and implement a comprehensive technology risk management framework.
- Identify, assess, and prioritize technology risks across the organization.
- Collaborate with IT, cybersecurity, and business units to develop risk mitigation strategies.
- Monitor and report on the effectiveness of risk management initiatives.
- Ensure compliance with relevant regulations and industry standards.
- Lead and mentor a team of technology risk professionals.
- Conduct regular risk assessments and audits.
- Stay updated on emerging technology risks and trends.
- Communicate risk management strategies and policies to senior management and stakeholders.
- IS Compliance
- Coordinating with various infosec teams and stakeholders to collect and verify the necessary data for regulatory advisories, s, circulars, questionnaires, and correspondences
- Maintaining the Advisory Digest document and updating it regularly with the latest information on cyber security incidents, best practices, and recommendations from regulators and authorities
- Ensuring timely and accurate submission of daily, monthly, and quarterly returns to the relevant regulators and authorities, such as CERT-In, NCIIPC, SEBI, PFRDA, etc.
- Tracking and managing the NCIIPC correspondences and compliance requirements, and communicating with them on any issues or queries - Gathering the metrics related to Key Risk Indicators (KRI) and ensuring they are aligned with the infosec framework and objectives
- Responding to the CERT-In technical advisory correspondences and compliance requirements, and implementing the suggested actions and measures
- Coordinating for the CII-ISSC meeting activities and handling adhoc data requirements from various regulators and authorities
- Acting as the infosec spoc for Business Continuity Planning (BCP) and Functional Recovery Planning (FRP), and conducting periodic infosec BIA and coordinating for planned/unplanned BCP
- Tracking all ATRs from all the committees (ITDSC, ISSC, AOP, ITSC, etc.), where ISS is the action owner, and ensuring the action plans are adequately documented, executed, and reported
- Tracking the infosec deliverable calendar across the unit and proactively identifying and resolving any delays or issues, and ensuring the delivery of all activities within timeline
- Compliance, Audit and Risk office
- Respond to RBI queries during annual RBS audit.
- Co-ordinate for all the activities related to Risk Based Supervision / other regulatory inspections including the submission of data / documents and represent the department for all the queries raised during the RBI inspections.
- Formulate responses to RAR observations from RBI
- Keep abreast with the regulatory changes and ensure dissemination and Implementation of regulations / amendments / actionable/ compliance communication in line with the milestones committed and within the timelines prescribed by regulators / internal timelines.
- Design new processes/ controls to address gaps highlighted by Operational Risk after risk assessment exercise and IAD after audit review
- Review of Policies pertaining to Information Security and Technology Risk in alignment with the regulatory guidelines
- Monitoring the Compliance Risk / Operational risk dashboards / risk movements of assessment units and flagging of the concerns to Head of the Department.
- Provide regular updates to Segment Heads and Senior Management on status of implementation of Risk Mitigation Plan advised by RBI through weekly dashboards and bi-monthly RMP meeting with all Department Heads and MANCOM members.
Qualifications:
- MBA from a reputed institution
- Bachelor's degree in Information Technology, Computer Science, or a related field., and certifications around information security would be an additional benefit.
- Proven experience of 15 – 20 years in operational risk management, technology risk management, cybersecurity, and compliance.
- Strong understanding of regulatory requirements and industry standards.
- Excellent leadership and team management skills.
- Strong analytical and problem-solving abilities.
- Effective communication and interpersonal skills.
- Ability to work collaboratively with cross-functional teams.
Preferred Skills:
- 15-20 years Experience in financial services or a related industry.
- Knowledge of operational, technology and cyber security risk management frameworks
- Familiarity with cloud computing, data privacy, and emerging technologies
Frequently Asked Questions
Is the salary disclosed for the ISS:Head - Information Security Governance & Technology Risk position at Axis Bank?
Where is the ISS:Head - Information Security Governance & Technology Risk position at Axis Bank located?
Is the ISS:Head - Information Security Governance & Technology Risk role at Axis Bank full-time or part-time?
How do I apply for the ISS:Head - Information Security Governance & Technology Risk position at Axis Bank?
When was the ISS:Head - Information Security Governance & Technology Risk job at Axis Bank posted?
You'll be redirected to Axis Bank's official application page on ripplehire.