Source description
About the role
Job Description: Position Title Associate Vice President - Cyber Security Role Assist VP Cloud Security & Cyber Security Reporting To Vice President & Lead Cyber Security Key Responsibilities Handling the Cloud Security infrastructure planning, architecture & security operations of SBIL. Drawing up and implementing new Cloud security initiatives, preparing cyber security architecture of the SBIL to meet its projected needs and to remain abreast of times in terms of Cyber Security Standards & Procedures. Guiding and monitoring Vulnerability & Threat Management program, Red team exercises, Cyber Resilience exercises etc. Initiating pro-active compliance measures to comply with legal & regulatory as well as group guidelines. Key Performance Areas: ICT Security Infrastructure / Cyber Security Planning & Testing Draw and update periodically Cloud Security program for SBIL Analyse and establish security requirements for SBIL's systems/networks including Cloud setups. Defend systems against unauthorized access, modification and / or destruction. Design Offensive and Defensive cloud Security practices Design vulnerability & threat management program and plan to conduct various types of cloud security compliance assessments / Vulnerability testing, risk analysis etc. to ensure operational security Defining security standards for different areas like technology Cloud risk assessment, access privileges, control structures and resources Oversee and monitor routine Cloud security administration Manage various Cloud security compliance assessments / reviews like Container Security assessment, VA, PT, Application Security, Secure Code review, Secure Configuration review, Secure Network Architecture review, Firewall Rule base review, Security solution review etc. and ensure that periodic security compliance assessments are completed in defined time frame Comprehensive technical security compliance assessments including Cloud Infra VA, PT, secure config review, cloud architecture review, digital forensic readiness review etc. for all new applications & related infrastructure components and providing go ahead for production move Evaluation of all requests pertaining to changes undertaken in the existing applications & infrastructure components including cloud related applications and to identify the risks in context of regulatory InfoSec requirements, SBIL InfoSec policies, industry best practices and accordingly advise/recommend team to adhere the security practices and providing go ahead for production move Coordination with IT and ISSP (Information Security Service Provider) teams to undertake the cyber security testing / review / assessment and risk mitigation activity smoothly. Review / Presentation of Dashboards and Action Taken Reports of all types of security assessments / reviews (planned periodic or changes) related to pertaining to applications including APIs, infrastructure, solutions etc. to senior management Pursue with IT teams for closer / mitigation of reported vulnerabilities To review and provide inputs, recommend compensatory controls during the exceptions/deviations process. Review / Recommend /Approve Firewall Access Rules and other Rules / Policies of Cyber Security Solutions Manage Cyber Security Maturity Assessment initiatives Research and recommend security upgrades, new security solutions etc. Provide technical advice to colleagues Management reporting Co-ordinate with external/regulatory agencies Vendor Management Maintain relationships with SBIL's partners who support various IT security infrastructure components, reviews / assessments etc. Ensure that all the testing activity undertaken by ISSP as per the agreed scope and completed in the defined time frame. Enhance the level of monitoring mechanisms for these partners' performance and delivery standards / SLAs Negotiate contracts with vendors and manage costs and schedule of deliverables. Work with multi department and multi vendor situations. Compliance Ensure implementation of proper standards for cyber risk governance as well as regulatory compliance Be responsible for cyber security management and compliance with Information and Cyber Security policy framework as well as legal /regulatory (IRDAI, CERT-In, etc.) prescriptions and Group guidelines Provide Expertise < .
More at Evoke HR Solutions Pvt. Ltd.