Information Security Risk Manager
Crédit Agricole Corporate and Investment Bank (Crédit Agricole CIB)Mumbai, India
Job description
An experienced Information Security Risk Manager to strengthen our IS Risk management and control environment. The candidate shall also be responsible for managing audits and ensuring timely compliance, including tracking audit recommendations and findings. The ideal candidate must possess strong IS Risk management experience, preferably within the BFSI sector.
Key responsibilities
- Contribute to the development and maintenance of a robust Information Security Risk management framework, including Cyber Security, aligned with legal entity regulatory requirements for CACIB India.
- Handle regulatory, internal and external audits, primarily Reserve Bank of India audits, including closure of audit recommendations by coordinating with relevant stakeholders globally.
- Coordinate tracking and closure of risk recommendations arising from audits, assessments and risk reviews.
- Engage with multiple stakeholders, including global teams, to implement IS Risk management initiatives.
- Establish and implement IS Risk policies, procedures and standards.
- Perform risk-based deep dives to identify IS risks, validate root causes for IS-related events and recommend corrective actions.
- Monitor changes in Indian Information Security Risk Management regulations and escalate relevant updates to Head Office.
- Participate in implementing the global control plan.
- Assess and control the Information Security implications of local process or system changes.
- Assist the CISO in implementing and maintaining security controls.
Qualifications and experience
- Bachelor of Technology, Bachelor of Engineering or Bachelor of Science in Computer Science.
- Preferred certifications include CRISC, CISA, ISO 27001, ISO 31000, COBIT and ITIL.
- Minimum 8 years of professional experience in Information Security or related fields, preferably in BFSI.
- Experience handling regulatory, internal and external audits and closing audit recommendations.
- Strong understanding of the banking regulatory landscape in India.
- Knowledge of Network Security, Data Security, Security Operations Centers, IT networks, ISO controls, NIST and cybersecurity controls.
- Experience engaging with global stakeholders and IT teams on Information Security projects.
- Experience tracking recommendations from audits, assessments and risk reviews.
Skills
- Excellent English communication and interpersonal skills.
- Strong analytical, critical-thinking and reasoning skills.
- Self-driven, collaborative and able to multitask.
- Advanced proficiency with Microsoft Office tools.
About Crédit Agricole Corporate and Investment Bank
Crédit Agricole CIB is the corporate and investment bank of the Crédit Agricole group. It supports major companies and financial institutions in developing and financing their projects, with responsible finance and social and environmental commitments at the heart of its activities.