Padmi
ION Group logo
ION Group

financial software · workflow automation

Markets Governance, Risk and Controls Manager

IndiaPosted 3 months ago
CybersecuritySeniorFull Time; Regular
Apply at ION Group

Opens the source posting on shine.com

Source description

About the role

View original

As an Information Security Risk Advisor, your primary role will be to support and advise on Information Security Management System (ISMS) and associated controls. You will also be responsible for providing a transparent view of the risk posture to stakeholders and ensuring compliance with relevant control standards, regulations, and audit requirements. Your key responsibilities will include: - Documenting and monitoring the risk and control environment to identify existing and emerging risks and issues. - Evaluating and documenting issues related to changes in the risk environment and risk priorities. - Identifying and aggregating thematic risks related to findings and trends, such as regulatory preparedness and thematic concerns. - Engaging with Internal Audit to discuss risk posture and audit inputs. - Communicating heightened risks that are relevant to stakeholders and customers to ensure transparency and appropriate prioritization for remediation. - Understanding legal and regulatory obligations relevant to the product and how the processes and associated controls provide evidence of compliance. - Partnering with business stakeholders to respond to customers, external audit, and regulatory requests for information. - Educating and advising on security policy, standards, and procedures. - Managing and maintaining external certification activities. To excel in this role, you should possess the following skills, qualifications, and experience: - Experience working within the technical financial services industry or other highly regulated industries. - Knowledge of information security management, governance, and compliance principles, practices, laws, rules, and regulations, such as NIST, ISO, NIS, DORA, and GDPR. - Familiarity with information technology systems and processes, network infrastructure, data architecture, data processes, and protocols. - Understanding of cyber and cloud security standard frameworks, architecture, design, operations, controls, technology, solutions, and service orchestration, such as CIS and CSF. - Proficiency in information systems auditing, monitoring, controlling, and assessment processes. - Knowledge of incident response management, e.g., ITIL, and risk assessment and management methodology, e.g., NIST and ISO 27005. - Expertise in security training techniques, reporting activities, and developing and implementing enterprise governance, risk, and compliance strategy and solutions. - Ability to research and understand security information related to internal and external organizations using online and other sources. - Experience in managing technology vulnerability and threat information, security project management, planning, and risk management, information security, and audit management lifecycles. This job opportunity will allow you to utilize your expertise in information security risk assessment and management to contribute effectively to the organization's overall risk management framework. As an Information Security Risk Advisor, your primary role will be to support and advise on Information Security Management System (ISMS) and associated controls. You will also be responsible for providing a transparent view of the risk posture to stakeholders and ensuring compliance with relevant control standards, regulations, and audit requirements. Your key responsibilities will include: - Documenting and monitoring the risk and control environment to identify existing and emerging risks and issues. - Evaluating and documenting issues related to changes in the risk environment and risk priorities. - Identifying and aggregating thematic risks related to findings and trends, such as regulatory preparedness and thematic concerns. - Engaging with Internal Audit to discuss risk posture and audit inputs. - Communicating heightened risks that are relevant to stakeholders and customers to ensure transparency and appropriate prioritization for remediation. - Understanding legal and regulatory obligations relevant to the product and how the processes and associated controls provide evidence of compliance. - Partnering with business stakeholders to respond to customers, external audit, and regulatory requests for information. - Educating and advising on security policy, standards, and procedures. - Managing and maintaining external certification activities. To excel in this role, you should possess the following skills, qualifications, and experience: - Experience working within the technical financial services industry or other highly regulated industries. - Knowledge of information security management, governance, and compliance principles, practices, laws, rules, and regulations, such as NIST, ISO, NIS, DORA, and GDPR. - Familiarity with information technology systems and processes, network infrastructure, data architecture, data processes, and protocols. - Understanding of cyber and cloud security standard frameworks, architecture, design, operations, controls, technology, so

One address, no account. We’ll tell you when matching roles go live.

More at ION Group

Related open roles

View all roles