The Information Security Officer will work closely with inefficient formulation, implementation, and
management of the Bank's information security policy(s) and compliance programs. The incumbent
will ensure efficient management of Information Security Governance, in line with the Reserve Bank
of India and other statutory/regulatory bodies governing our India operations. He/she will also
coordinate and execute the information security management system program (ISMS), Security
operations, VAPT program, and Cyber Security Framework implementation. The job holder will also
ensure that risk management needs in relation to information security, including but not limited to
incident response, access control, business continuity and disaster recovery are duly and promptly
addressed. This role requires extensive coordination and teamwork with inter and intra-department
officials.
STRATEGIC
- Responsible for all cyber security governance framework along with other activities related to information and cyber security aspects as per the directions from Group Chief Information Security Officer.
- Contribute to the formulation of, annual strategies, policies, and procedures of the Information Security Section, to support divisional and organizational business strategy.
- Ensure that the Information Security plans are within agreed budgets and timescales. Assist the Country Manager & Group Chief Information Security Officer in preparing/providing timely, accurate, and complete progress reports to the Management reviews, RBI, IBA, IDRBT, CERT-In, CSITE, etc.
- Update self on the IT/security industry trends, new solutions, and techniques, as well as emerging threats and regulatory requirements/changes set by QCB and other relevant government bodies, and suggest adequate changes in the section, including but not limited to the staffing of employees, department deliverables, etc.
- Develop and maintain robust working relationships with internal/external stakeholders to facilitate functional/operational/ strategic needs.
- Develop and maintain various performance monitoring checklists as required by ISO27001 /RBI Cyber Security Framework for IT and other operations.
- Is well versed in cyber security governance framework and responsible for managing RBI - CSITE advisories, circulars, policy development, security operation center (SOC), vulnerability assessment and penetration testing, etc.
- Member of Bank’s India Management Committee where information security-related risks, gaps, and remedial measures are discussed and tabled.