
AVP - Cyber Risk Oversight
- Mumbai, Maharashtra
- Permanent
- Full-time
- Develop and maintain high level Cyber Risk policy, embedding relevant Group, regulatory and industry good practice requirements
- Manage the risk appetite statements for technology and digital risks in relation to cyber and provide reporting to the Risk committee of performance against these statements sampling
- Oversee and guide Cyber Risk mitigation projects and controls improvement initiatives. Lead and manage enterprise wide Red/Blue/Purple teaming activities and provide oversight for regulatory testing like CBEST/FCA Audits.
- Assess the effectiveness of processes and internal controls implemented by the first line and infrastructure functions through a programme of a sampling to evaluate their quality and associated documentation, and feedback for action
- Cloud Security Assessment: Oversight of cloud security and services, including AWS, Azure, GCP, or other cloud providers.
- Participate in cyber incident response planning, testing, and execution when invoked to support a real incident
- Participate in the annual programme of deep dive and thematic reviews, leading reviews where these relate to cyber across all business areas and outsourced service providers as may be required
- Assess first line processes and technical analysis of cyber security events and root cause as well as remedial solutions, and provide a second line view on their effectiveness
- Provide advice and guidance on compliance with regulatory requirements that relate to cyber risk and contribute to regulatory enquiries on the same.
- Oversee the identification, assessment, processing, analysis, and reporting of tactical and strategic threat intelligence to assist in decision making and actively thwart emergent and current threats targeting our organisation.