Job Description
Group Technology and Operations (T&O) enables and empowers the bank with an efficient, nimble and resilient infrastructure through a strategic focus on productivity, quality & control, technology, people capability and innovation. In Group T&O, we manage the majority of the Banks operational processes and inspire to delight our business partners through our multiple banking delivery channels.
Job Purpose
The purpose of the role is to govern an assure internal and external security risk posture is aligned to Bank s and Regulator s policies, standards and guidelines.
This role also plays pivotal role to identify and prioritize information security related risks through proactive risk assessment and being mindful of security compliance.
Key Accountabilities
Primary SPOC for internal and external IS audits
Manage regulatory submissions related to IS
Audit readiness and preparedness within IS team
IS Calendar and compliance delivery assurance tracker
Manage Security Awareness programme
Build partnership with Tech GRC, Risk and Compliance depts along with group
Job Duties & responsibilities
Work closely with Information Security / CISO functions for risk mitigation plan of identified risk tracked in GRC system.
Collaborate with ITGRC and Compliance for external and internal IT audits and review/ manage audit response from internal IS team before audit submissions. Participate in the audit meetings to discuss audit issues impact and risk severity.
Decipher regulatory circulars, advisories, master directions and convert into key actionable KPI, governance tracker, system changes, policy and standard changes.
Define KRI and ensure compliance and security assurance
Maintain list of circulars and actionable
Maintain IS calendar for key deliverables on defined frequency
Liaise with local and group GRC team on key updates/initiatives.
Review internal requirement received from Compliance dept and
Track and follow up with risk / action owners to check status of the risk mitigation plan and update IT management on the status.
Drive IS awareness programme including periodic mailers aligned as per Cyber Jagrookta Diwas
Exercise Risk Control Self Assessment (RCSA) exercise for ISS dept.
Proactively highlight anticipated delay in risk mitigation plan and get the target completion date extended with formal approvals and update GRC system.
Report key risks in IT Steering / Strategy committee and other risk management committees.
Apply principle of Risk management to transfer, mitigate OR accept the risk for identified risk.
Ensure readiness of security audits with historical audit re-requisites
Proactively ensure compliance on recurring audit requirements
Get the risk acceptance approved as per risk approval matrix and lodged them in the GRC tool.
Perform IT risk assessment and process review to confirm compliance to
💡 Quick Summary
Seeking a career-building opportunity? The Immediate recruitment Officer| Generalist| Business position is now open for candidates interested in the Human Resource (HR) Jobs sector. This role in Mumbai offers a professional environment and growth potential.
Requirement Snapshot: Candidates should possess basic communication skills, a proactive attitude, and the ability to work in a team. Experience in Human Resource (HR) Jobs is a plus.
