Padmi

Angel One - Security Assurance Lead - SEBI CSCRF Compliance

MumbaiPosted 1 month ago
CybersecuritySeniorFull Time; Regular
Apply at Angel One

Opens the source posting on shine.com

Source description

About the role

View original

Role & responsibilities: 1. SEBI CSCRF Compliance (Primary Responsibility): - Serve as the subject matter expert for SEBI CSCRF across Angel One. - Lead implementation, monitoring, and continuous improvement of controls required under SEBI CSCRF. - Interpret regulatory requirements and convert them into technical and operational security controls. - Ensure evidence collection for regulatory audits. - Track compliance status across all CSCRF domains. - Review control effectiveness. - Maintain regulatory dashboards. - Coordinate regulatory submissions. - Support SEBI inspections and audits. - Drive closure of regulatory observations. - Develop internal CSCRF maturity assessments. 2. Security Assurance: - Develop and execute the organization's Security Assurance strategy. - Perform technical assurance across: 1. Infrastructure 2. Cloud 3. Applications 4. APIs 5. Databases 6. Containers 7. Kubernetes 8. CI/CD 9. Identity Platforms 10. End User Computing - Validate implementation of security controls. - Conduct security architecture reviews. - Perform security design assessments. - Review technical standards. - Recommend security improvements. 3. Vulnerability Management: - Own enterprise vulnerability management lifecycle. - Coordinate: 1. Infrastructure VA 2. Application VA 3. Cloud Assessments 4. Container Security 5. API Security 6. Network Assessments 7. External Attack Surface Monitoring - Review scan configurations. - Validate scan coverage. - Review vulnerability accuracy. - Ensure remediation SLAs are met. - Identify recurring security issues. - Perform trend analysis. - Drive reduction in organizational risk. 4. VAPT Governance: - Manage bi-annual and ad-hoc VAPT exercises. - Coordinate with CERT-In empanelled auditors. - Validate: 1. Scope 2. Tool configurations 3. Coverage 4. Raw reports 5. False positives 6. Vulnerability counts 7. Severity classification 8. Risk acceptance - Ensure submissions satisfy SEBI expectations. - Maintain audit-ready evidence. Preferred candidate profile: Mandatory: - Deep expertise in SEBI CSCRF. - Experience supporting SEBI regulated entities. - Security Assurance. - Risk Assessments. - Infrastructure Security. - Cloud Security. - Application Security. - Vulnerability Management. - Security Governance. - Audit Management. Experience: - 10-12 years in Information Security. - Minimum 6 years in Security Assurance or Security Governance. - Experience working in: Banking, Capital Markets, Stock Exchanges, Brokerages, Financial Services, FinTech. - Experience handling regulatory audits. - Experience interacting with auditors. - Experience driving remediation. Qualifications: Bachelor's degree in Engineering, Computer Science, Information Security, or related discipline. Preferred Certifications: - CISSP - CISA - CCSP - CCSK - ISO 27001 Lead Auditor - AWS Security Specialty - Azure Security Engineer - GCP Professional Cloud Security Engineer .

One address, no account. We’ll tell you when matching roles go live.

More at Angel One

Related open roles

View all roles