Source description
About the role
Basic Details: Fill the required information about Job Poornata Position Number of the job 9 Poornata Position Title of the job (30 characters max) Chief Manager Business Aditya Birla Capital Business Unit Aditya Birla Health Insurance Effective Date (DD/MM/YYYY) 1) Job Purpose: Write the purpose for which the job exists (in 23 lines) (Max 1325 Characters) 1. Goverce, Risk and Compliance Audit (GRCA): Ensures audits cover goverce structures, regulatory compliance, security frameworks, business continuity, and incident response with regular documentation and remedial actions. 2. ThirdParty Risk Management (TPRM): Evaluates vendor security posture using questionnaires, AIdriven assessments, audits, and contract reviews, ensuring compliance with privacy laws and effective incident response. 3. Intermediaries Audit: Reviews intermediaries cyber policies, boardapproved controls, and oversight mechanisms to ensure safe data handling and regulatory compliance. 4. Legal Document Review: Ensures contracts include clear clauses for information security, data privacy, AI goverce, breach notification, and regulatory adherence aligned with organizational policies. 5. AI Security for ThirdParty Vendors: Requires transparency about AI use, robust security controls, bias mitigation, continuous monitoring, incident response, and regulatory compliance prior to onboarding AI vendors. 2) Job Context Major Challenges: Write the specific aspects of the job that provide a challenge internal and external) to the jobholder in the context of the Business / Unit / Function / Department / Section (Max 3975 Characters) The role operates within a complex and dynamic environment where ensuring robust information security goverce, risk management, and compliance (GRCA) is critical. Internally, the job holder faces the challenge of integrating evolving regulatory requirements, organizational policies, and technological advancements into practical and enforceable security frameworks, while aligning with business objectives across multiple departments. Major internal challenges include: 1. Managing coordination and communication between diverse stakeholders such as IT, legal, HR, compliance and business units to ensure unified risk mitigation strategies. 2. Keeping pace with rapidly changing cyber threat landscapes and ensuring that control measures including AI security protocols remain effective and relevant. 3. Balancing stringent security requirements with operational efficiency and business needs, especially when dealing with thirdparty risk management (TPRM) and onboarding AI vendors. 4. Maintaining thorough documentation, audit readiness, and remediation tracking amid frequent changes and updates. 5. Ensuring staff training and awareness programs effectively address evolving threats and compliance mandates. Externally, the sfbhjazjob holder contends with challenges related to vendor and thirdparty management, including: 1. Conducting rigorous assessments of vendors security postures, AI goverce, and data privacy practices amidst diverse technological capabilities and regulatory environments. 2. Navigating contractual negotiations to embed adequate security and compliance clauses, including those for AIrelated risks. 3. Addressing complexities of auditing intermediaries and ensuring they meet the organization s security and regulatory expectations. 4. Managing incident response and liability concerns that arise from thirdparty breaches or AI system failures. 5. Staying abreast of emerging regulations globally that impact vendor management and AI security, ensuring continuous compliance. Overall, the role demands a proactive, multidisciplinary approach to information security that anticipates risks, drives compliance, nurtures vendor relationships, and fosters a securityconscious culture within the organization and its extended ecosysteM 3) Dimensions: Mention quantitative or qualitative parameters that are relevant for the job and provide a better understanding of the scope and scale of the joB Dimensions: Overseeing security and compliance for "N" number of thirdparty vendors, including AI service providers, intermediaries, and contractors across diverse service lines; Reviewing and managing compliance for a large volume of legal agreements annually commonly hundreds that involve data privacy, security clauses, and AI goverce provisions; Supporting operations across ABHICL, ensuring adherence to regional cybersecurity regulations (e. g. IRDAI DPDPA in India); Coordinating multiple internal and external audits yearly, including GRCA, TPRM, intermediaries, and AI compliance assessments. 4) Key Result Areas: Write the key results expected from the job and the supporting actions for each of these key result areas (For majority of jobs typically there could be 4 7 key result areas) Maximum 10 KRAs can be updated Key Result Areas (Max 1325 Characters) Supporting Actions (Max 1325 Characters) Information Security Goverce Develop and enforce security policies; ensure compliance through audits and continuous monitoring Risk Management Compliance Conduct GRCA TPRM audits; manage risk remediation track clousre of findings Vendor ThirdParty Security Assess and onboard vendors including AI vendors, maintain ongoing security and compliance monitoring Legal and Contractual Complaince Review and validate contracts for security, privacy and AI goverce clauses; coordinate with legal teams Reporting communication Provide regular reports on security posture, risks and audits status to stakeholders Continuous Improvement Monitor emerging threats and regulatory changes; drive initiatives to enhance security posture. Ethical AI Goverce Ensure AI and automation systems operate transparently, ethically, and without bias; establish accountability mechanisms. Audit Inspection Management Plan, coordinate, and oversee internal and external audits; remediate any noncompliance findings effectively. Regulatory Standards Compliance Keep abreast of evolving regulations like IRDAI, DPDPA; ensure organizational policies align and are enforced. 5) Relationships: Describe the nature and purpose of most important contacts or relationship (except superior/team members) with individuals, departments, organizations inside and outside of the organization, that job is required to interact with in order to deliver the job objectives Relationships: Internal Legal team Regular Contract review and legal compliance IT Department Frequent (Daily/Weekly) Security technology deployment, incident response Compliance All Business As required Regulator adherence and audit coordination Auditors (Internal/External) Periodic (Quaterly) Security and Compliance audits Customers / Business Units Frequent Security requirements gathering, risk impact review Incident Response Teams As needed Security incident coordination and resolution External Vendors/ Third Party providers Ongoing Security Assessment, Compliance Monitoring AI Vendors Ongoing AI security evaluation, risk mitigation, goverce Regulatory Authorities As required (Audit Cycles) Compliance audits and reporting Auditors (Internal/External) Periodic (Annual) Security and Compliance audits Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
More at Aditya Birla Insulators