Key Responsibilities:
The Lead – Infosec Governance, Risk & Compliance (GRC) will be responsible for establishing, managing, and continuously enhancing the Information Security Governance, Risk Management, Compliance, programs across the NBFC. The role will ensure alignment with RBI regulations, applicable laws, industry security standards, and business objectives while driving a strong security and risk-aware culture across the organization.
The incumbent will act as the primary custodian of Information Security policies, cyber risk management, regulatory compliance, third-party risk governance, security awareness, audit management, and GRC transformation initiatives.
1. Information Security Governance
- Develop, implement, and maintain the Information Security Governance framework.
- Define and manage information security policies, standards, procedures, and guidelines.
- Establish security committees, governance forums, and reporting mechanisms.
- Present cyber risk posture, compliance status, and key metrics to executive leadership and Board committees.
- Drive enterprise-wide security awareness and security culture initiatives.
2. Cyber Risk Management
- Own and manage the Information Security Risk Management Framework.
- Conduct enterprise cyber risk assessments and periodic reviews.
- Facilitate risk identification, treatment, mitigation, acceptance, and monitoring processes.
- Maintain the cyber risk register and track remediation activities.
- Quantify and communicate cyber risks to senior management and stakeholders.
3. Regulatory Compliance & Assurance
- Ensure compliance with RBI Master Directions, Digital Lending Guidelines, IT Governance requirements, Cyber Security Frameworks, and applicable regulatory directives.
- Manage compliance with:
- RBI regulations
- Information Technology Act
- CERT-In Directions
- NPCI security requirements
- UIDAI Requirements
- IRDAI Requirements
- Establish compliance monitoring and reporting mechanisms.
- Coordinate regulatory inspections and responses.
4. Audit & Assessment Management
- Lead Information Security audits, internal audits, statutory audits, and regulatory audits.
- Manage external assessments including:
- ISO 27001
- PCI DSS (where applicable)
- SOC Assessments
- Track observations and ensure timely closure of audit findings.
- Prepare management and Board-level audit updates.
5. Security Metrics & Reporting
- Define and monitor Information Security KPIs and KRIs.
- Develop executive dashboards for leadership and Board reporting.
- Analyze security compliance trends and risk posture.
- Prepare periodic reports for management committees.
6. Third-Party & Vendor Risk Management
- Establish and operate Third-Party Risk Management (TPRM) programs.
- Perform security due diligence of vendors, partners, fintechs, cloud providers, and service providers.
- Review vendor security controls, contracts, SLAs, and compliance evidence.
- Monitor supply chain cyber risk and remediation activities.
7. Security Frameworks & Certifications
- Lead implementation and maintenance of:
- ISO 27001:2022
- NIST Cybersecurity Framework
- RBI Cyber Security Framework
- Drive certification and recertification initiatives.
9. Business Continuity & Operational Resilience
- Govern Business Continuity Management (BCM) and Disaster Recovery (DR) programs for Infosec
- Conduct BCP and DR testing exercises in collaboration with IT
- Ensure cyber resilience and operational resilience requirements are met.
- Support crisis management and cyber incident governance activities.
10. Team Leadership & Stakeholder Management
- Build and lead a high-performing GRC team.
- Mentor and develop team members.
- Collaborate with Business, Technology, Risk, Audit, Legal, Compliance, and Operations teams.
- Manage relationships with regulators, auditors, consultants, and external partners.
Education:
- Bachelor's degree or higher
- ISO 27001 LA/LI, CISA, CRISC, ITIL certifications are preferred
Experience:
- 12 to 16 years
- Minimum 5 years in Information Security Governance, Risk & Compliance.
- Experience within NBFC, Banking, FinTech, Payments, Insurance, or Financial Services preferred