Team Leader - IRM-SUPPORT SERVICES-Information Risk Management Team
Mumbai, Maharashtra, India
Kotak Mahindra Bank
Kotak Mahindra Bank, India’s trusted bank offers personal & business banking services - accounts, deposits, loans, cards, insurance, investments & more.Job Description – Thematic Assessments & Enterprise Risk Management
Responsibilities
- Conduct thematic risk assessments in key identified areas of improvement, per internal or external audit observations, and determine effectiveness of Bank defences through interaction, interviews and on-ground assessment of operational effectiveness of IT and cybersecurity solutions.
- Work with industry partners to identify emerging areas of cybersecurity risk and devise framework to assess risk to the Bank in these identified areas.
- Liaise with IT and business stakeholders for conduct of assessments and closure of observations.
- Conduct comprehensive risk assessments to identify and mitigate information security risks at the enterprise level.
- Propose and steer implementation of controls, key performance indicators (KPIs), key risk indicators (KRIs) and trending metrics, in collaboration with business and IT teams to plan effective risk mitigation strategies.
- Collate, validate and present single-view dashboard and risk heat map of the risk indicators and metrics for consumption of Board and management committees.
- Review root cause analyses (RCA) for KRI threshold failures and present findings in management meetings.
- Basis above indicators and metrics, distil inputs on material risks in security domains to the Risk register of the Bank.
- Follow-up on the mitigation of identified risks, maintaining and updating the risk register.
- Maintain and update procedures and process documentation concerned with risk assessment and management.
- Identify opportunities to automate risk management processes and drive their implementation.
Required Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related field.
- 11-12 years of experience in risk assessments, maintaining and presenting risk registers, KRIs and KPIs. 2-4 years of BFSI experience would be preferable
- Strong knowledge of security frameworks and methodologies (e.g., RBI guidelines, NIST Cybersecurity Framework, ISO 27001)
- Excellent understanding of cloud security principles and practices.
- Strong analytical and problem-solving skills.
- Ability to work independently and manage multiple projects simultaneously.
- Certification such as CRISC or CISSP would be preferred.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
0
0
0
Categories:
Compliance Jobs
Leadership Jobs
Tags: CISSP Cloud Computer Science CRISC ISO 27001 KPIs NIST Risk assessment Risk management
Region:
Asia/Pacific
Country:
India
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information System Security Officer jobsInformation Security Specialist jobsSenior Security Analyst jobsSenior Cloud Security Engineer jobsSystems Engineer jobsSenior Cybersecurity Engineer jobsSystems Administrator jobsSenior Information Security Analyst jobsInformation Security Manager jobsCyber Security Specialist jobsSenior Network Security Engineer jobsIT Security Analyst jobsChief Information Security Officer jobsIT Security Engineer jobsSecurity Consultant jobsSecurity Specialist jobsInformation System Security Officer (ISSO) jobsInformation Systems Security Engineer jobsSenior Information Security Engineer jobsSenior Cyber Security Engineer jobsSenior Product Security Engineer jobsCyber Threat Intelligence Analyst jobsCyber Security Architect jobsSecurity Operations Analyst jobsCybersecurity Specialist jobs
TS/SCI jobsEDR jobsSaaS jobsBash jobsJava jobsTop Secret jobsThreat detection jobsTerraform jobsSplunk jobsRMF jobsIDS jobsSDLC jobsIPS jobsSOC 2 jobsSQL jobsMalware jobsFinance jobsForensics jobsCompTIA jobsDocker jobsActive Directory jobsGIAC jobsIntrusion detection jobsITIL jobsDoDD 8570 jobs
VPN jobsOWASP jobsHIPAA jobsCRISC jobsIT infrastructure jobsAnsible jobsTCP/IP jobsCCSP jobsData Analytics jobsClearance Required jobsNIST 800-53 jobsOSCP jobsMITRE ATT&CK jobsBanking jobsZero Trust jobsCISO jobsUNIX jobsSOAR jobsDNS jobsIndustrial jobsJira jobsSOX jobsEndpoint security jobsPolygraph jobsJavaScript jobs