Padmi

Lead Auditor-Cybersecurity

MumbaiPosted 30 days ago
CybersecuritySenior
Apply at Reserve Bank Information Technology Pvt Ltd

Opens the source posting on rebithr.darwinbox.in

Source description

About the role

View original

Reports to Sr. Manager Systems Audit

Graduate in Computer Science/IT or B. Tech or BCA/ MCA

CISA / CISM / CISSP / CEH / CRISC

ISO 27001 Lead Auditor/Lead Implementer

Additionally, below domain-specific certifications may be preferred.

Application & API Security:

Certification in Mobile application security testing

Certifications in API security

Database Security:

Oracle database

Certification in big data / analytics

Network Security:

CCNA.

Certified Firewall administrator

Payments Security:

Relevant certifications into ATM security, PCI DSS, QSA

Cloud Security:

AWS/Azure/GCP

Artificial Intelligence

Any Online courses on AI security

8 to 12 years of experience in Regulatory compliance, information security operations, Information System Audits encompassing experience into few Domains–Application Security, Database management and administration, / Network security and SOC / Payment systems/ Cloud security in addition to IT General controls (ITGC).

Exposure to the Banking / Finance / Payment industry domains would be preferrable.

Hands-on experience in the following areas:

Implementation of Information security policies, procedures, and processes

Conducting risk assessment covering Cyber Security domains as noted below:

Application/ API Security:

Mobile application assessment, OWASP security practices for applications, VA/PT/AppSec, black/grey/white box testing, ASDLC, Strong knowledge of programming languages for applications.

Database Security:

Database administration and management - Oracle, MS SQL etc., Database Activity Monitoring tools, data security and localization.

Payments Systems Security:

Understand payment systems and architecture such as SWIFT, UPI, IMPS, ATM, Internet Banking, Mobile Banking, payment gateway, ATM switch and terminal.

Experience in PCI DSS implementation/assessment and ATM end-point security and Cards data security and operations.

Networks Security:

Managing Infrastructure & Network security solutions such as firewalls, routers, proxy, WAF, email filtering, DLP, DDoS protection, data encryption, IPS/IDS, Incident response and investigating security breaches, VA-PT for networks.

Security Operations Centre- Implementation and review.

IT General Controls:

Familiarity with Technical Security controls of Identity & Access Management, Network, Server, Application, Change management, Backup and Restoration etc. and process controls reviews.

Understand BCP and DR processes and architecture.

Experience in conducting reviews based on ISO standards and regulatory guidelines in the banking/ Non bank PSO for a medium to large sized organization would be preferred.

Experience in conducting Information System Audits

Must have experience in preparing quality deliverables such as audit reports, presentations etc.

Excellent written, oral communication and presentation skills

Excellent organizational and interpersonal skills

Ability to work independently or as part of a team

Ability to manage team

Please note: While multi domain expertise and certifications are preferred, the candidate is required to have specialization in at least one of the technical areas mentioned above.

Information technology / Banking and Financial services / FinTech/ Auditing / Cyber Security consulting

Candidates will have to travel extensively within Mumbai and across the c ountry for performing audits, as per RBI requirements.

Conducting audit of Information security policies, procedures, and processes to identify process/design gaps.

Conduct audits of information security systems and infrastructure to verify systems are secure and support the related applications/business processes.

Conducts audits in different Non-bank Payment system operators (PSO) such as Active Directory, WAF, Network access security, End-point security, Application VA/PT/AppSec, SDLC, Database management and security, PCI-DSS, ATM controls, Cards (Debit/Credit) security, Payment-gateway, Cloud security, API Security and IT General Controls etc.

Additional weightage will be given to candidates with experience in domains such as Cloud Security, API security and Payment’s security.

Developing project plans, work programs, evaluating system controls, identifying risks and audit gaps, documenting gaps in audit report format, and communicating information to stakeholders.

Support in maintaining audit checklist and documents, trend analysis, preparing presentations etc.

Should be a self-learner and must keep updated with the latest security guidelines issued by regulators, international standards for information security, threats and vulnerabilities researched/discovered.

Research public domain to keep up to date knowledge on emerging technologies – Cloud, Virtualization, AI-ML, and ensure continuous learning

Experience into people management / team management

Navi Mumbai

All positions are on fixed term contract on a full-time basis exclusively for ReBIT, initially for a period of five years, extendable by mutual consent.

One address, no account. We’ll tell you when matching roles go live.

More at Reserve Bank Information Technology Pvt Ltd

Related open roles

View all roles