Assistant Manager Information Security
OSTTRA - IN - GURGAON AMBIENCE TOWER, India
S&P Global
We provide Essential Intelligence: a combination of the right data, connected technologies and experts to enable our customers to make decisions with conviction.OSTTRA India
The Role: Assistant Manager Information Security
The Team: The OSTTRA Technology team is composed of Capital Markets Technology professionals, who build, support and protect the applications that operate our network. The technology landscape includes high-performance, high-volume applications as well as compute intensive applications, leveraging contemporary microservices, cloud-based architectures.
The Impact: Together, we build, support, protect and manage high-performance, resilient platforms that process more than 100 million messages a day. Our services are vital to automated trade processing around the globe, managing peak volumes and working with our customers and regulators to ensure the efficient settlement of trades and effective operation of global capital markets.
What’s in it for you:
We are seeking a highly motivated and experienced Information Security person to join our growing security team. In this role, you will be responsible for managing and optimizing our Data Loss Prevention (DLP) solutions, ensuring compliance with relevant security standards i.e. ISO 27001, NIST and implementing and maintaining robust Identity and Access Management (IAM) and Privileged Access Management (PAM). You will play a crucial role in protecting our sensitive data and ensuring the security posture of our organization.
This is an excellent opportunity to be part of a team based out of Gurgaon and to work with colleagues across multiple regions globally.
Responsibilities:
Data Loss Prevention (DLP) Management:
Implement, Manage, and optimize DLP tools policies to prevent data leaks and ensure data protection.
Develop and maintain DLP policies and procedures.
Regularly update and fine-tune DLP rules to adapt to evolving data protection needs.
Monitor and analyse DLP alerts and incidents and perform incident response.
Provide training and guidance to users on DLP best practices.
Implement real-time monitoring and logging for data movement and access patterns.
Generate detailed reports on data loss attempts, policy breaches, and user behavior anomalies.
Evaluate and recommend improvements to existing DLP solutions.
Develop playbooks for quick response to DLP-related threats and incidents.
Perform regular data flow assessments to identify unprotected data paths
Identity and Access Management (IAM) and Privileged Access Management (PAM):
Manage requirements around IAM and PAM security, including user provisioning, access control, and privileged access management.
Develop and enforce IAM and PAM policies and procedures.
Conduct regular access reviews and audits.
Generate compliance reports for internal and external audits (e.g., SOX, GDPR, PCI-DSS).
Troubleshoot IAM and PAM issues together with the respective Infrastructure teams.
Integrate IAM/PAM systems with other security and business applications.
Regularly evaluate IAM/PAM solutions to keep pace with emerging threats and technologies.
Information Security Compliance:
Ensure compliance with relevant security standards and regulations, including ISO 27001, NIST Standard
Conduct internal security audits and assessments.
Develop and maintain security documentation and procedures.
Assist with external security audits and assessments.
Stay up to date on the latest security threats and vulnerabilities.
Other Duties:
Provide security consulting and support to other teams.
Knowledge on Application Pen testing would be an added advantage
Evaluate and recommend new security technologies and solutions.
Participate in security awareness training and initiatives.
Understanding on Technology & Security Risk Management and Vendor Risk Management Framework
What We’re Looking For:
Qualifications:
7 to 8 years’ experience working in IT Security & GRC in multiple capacities.
Bachelors in IT, Computer Science, Cyber Security, or equivalent experience required.
Proven experience with DLP tools and technologies (e.g., Symantec DLP, Forcepoint DLP, Microsoft Information Protection, Zscaler etc.) and certification on these tools would be added advantage
Strong understanding of IAM and PAM concepts, tools and technologies and certification on these tools would be added advantage
In-depth knowledge of ISO 27001 and other relevant security standards and regulations.
Certification like ISO 27001, CISA, CRISC, CISM etc. would be an added advantage.
Competencies:
The ability to multitask, act under pressure and quickly identify and deal with priority matters under tight deadlines. Attention to detail is essential.
The ability to handle multiple inquiries at any one time, often under considerable deadline pressure.
The ability to work both independently and as part of a team.
Desired Skills:
Excellent written and spoken English.
Detail oriented with excellent research, analytical and critical thinking skills.
Strong documentation, oral and written communications, and interpersonal skills.
The Location: Gurgaon, India
About Company Statement:
OSTTRA is a market leader in derivatives post-trade processing, bringing innovation, expertise, processes and networks together to solve the post-trade challenges of global financial markets. OSTTRA operates cross-asset post-trade processing networks, providing a proven suite of Credit Risk, Trade Workflow and Optimisation services. Together these solutions streamline post-trade workflows, enabling firms to connect to counterparties and utilities, manage credit risk, reduce operational risk and optimise processing to drive post-trade efficiencies.
OSTTRA was formed in 2021 through the combination of four businesses that have been at the heart of post trade evolution and innovation for the last 20+ years: MarkitServ, Traiana, TriOptima and Reset. These businesses have an exemplary track record of developing and supporting critical market infrastructure and bring together an established community of market participants comprising all trading relationships and paradigms, connected using powerful integration and transformation capabilities.
About OSTTRA
Candidates should note that OSTTRA is an independent firm, jointly owned by S&P Global and CME Group. As part of the joint venture, S&P Global provides recruitment services to OSTTRA - however, successful candidates will be interviewed and directly employed by OSTTRA, joining our global team of more than 1,200 post trade experts.
OSTTRA was formed in 2021 through the combination of four businesses that have been at the heart of post trade evolution and innovation for the last 20+ years: MarkitServ, Traiana, TriOptima and Reset. OSTTRA is a joint venture, owned 50/50 by S&P Global and CME Group.
With an outstanding track record of developing and supporting critical market infrastructure, our combined network connects thousands of market participants to streamline end to end workflows - from trade capture at the point of execution, through portfolio optimization, to clearing and settlement.
Joining the OSTTRA team is a unique opportunity to help build a bold new business with an outstanding heritage in financial technology, playing a central role in supporting global financial markets.
Learn more at www.osttra.com.
What’s In It For You?
Benefits:
We take care of you, so you can take care of business. We care about our people. That’s why we provide everything you—and your career—need to thrive at S&P Global.
Our benefits include:
Health & Wellness: Health care coverage designed for the mind and body.
Flexible Downtime: Generous time off helps keep you energized for your time on.
Continuous Learning: Access a wealth of resources to grow your career and learn valuable new skills.
Invest in Your Future: Secure your financial future through competitive pay, retirement planning, a continuing education program with a company-matched student loan contribution, and financial wellness programs.
Family Friendly Perks: It’s not just about you. S&P Global has perks for your partners and little ones, too, with some best-in class benefits for families.
Beyond the Basics: From retail discounts to referral incentive awards—small perks can make a big difference.
For more information on benefits by country visit: https://spgbenefits.com/benefit-summaries
-----------------------------------------------------------
Equal Opportunity Employer
S&P Global is an equal opportunity employer and all qualified candidates will receive consideration for employment without regard to race/ethnicity, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, marital status, military veteran status, unemployment status, or any other status protected by law. Only electronic job submissions will be considered for employment.
If you need an accommodation during the application process due to a disability, please send an email to: EEO.Compliance@spglobal.com and your request will be forwarded to the appropriate person.
US Candidates Only: The EEO is the Law Poster http://www.dol.gov/ofccp/regs/compliance/posters/pdf/eeopost.pdf describes discrimination protections under federal law. Pay Transparency Nondiscrimination Provision - https://www.dol.gov/sites/dolgov/files/ofccp/pdf/pay-transp_%20English_formattedESQA508c.pdf
-----------------------------------------------------------
20 - Professional (EEO-2 Job Categories-United States of America), BSMGMT203 - Entry Professional (EEO Job Group)* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits CISA CISM Cloud Compliance Computer Science CRISC GDPR IAM Incident response ISO 27001 Microservices Monitoring NIST Pentesting Risk management RMF SOX Vulnerabilities
Perks/benefits: Career development Competitive pay Flex hours Flex vacation Health care Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.