Assistant Vice President - Insider Threat Lead

Posted 3 Days Ago
Be an Early Applicant
Gurugram, Haryana, IND
In-Office
Senior level
Fintech • Software • Financial Services
The Role
Lead and manage the insider threat program to detect, investigate, and prevent data leakage. Operate monitoring tools, review alerts, coordinate escalations with compliance and HR, maintain incident trackers, refine DLP rules, produce metrics and reports, manage service partners, and ensure process documentation, DR participation, and adherence to security frameworks and audits.
Summary Generated by Built In

About Us

SBI Card is a leading pure-play credit card issuer in India, offering a wide range of credit cards to cater to diverse customer needs. We are constantly innovating to meet the evolving financial needs of our customers, empowering them with digital currency for seamless payment experience and indulge in rewarding benefits. At SBI Card, the motto 'Make Life Simple' inspires every initiative, ensuring that customer convenience is at the forefront of all that we do. We are committed to building an environment where people can thrive and create a better future for everyone.

SBI Card is proud to be an equal opportunity & inclusive employer and welcome employees without any discrimination on the grounds of race, colour, gender, religion, creed, disability, sexual orientation, gender identity, marital status, caste etc. SBI Card is committed to fostering an inclusive and diverse workplace where all employees are treated equally with dignity and respect which makes it a promising place to work.

Join us to shape the future of digital payment in India and unlock your full potential.

What’s in it for YOU

  1. SBI Card truly lives by the work-life balance philosophy. We offer a robust wellness and wellbeing program to support mental and physical health of our employees
  2. Admirable work deserves to be rewarded. We have a well curated bouquet of rewards and recognition program for the employees
  3. Dynamic, Inclusive and Diverse team culture 
  4. Gender Neutral Policy
  5. Inclusive Health Benefits for all - Medical Insurance, Personal Accidental, Group Term Life Insurance and Annual Health Checkup, Dental and OPD benefits
  6. Commitment to the overall development of an employee through comprehensive learning & development framework

Role Purpose 

Responsible for managing all identified/known insider threat vector of information leakage either deliberately or inadvertently with focus on preventing Insider threat in getting exposed. The role is also responsible for leading the complete program to protect SBIC’s critical information from unauthorized exposure.

Role Accountability 

  1. Define and Manage processes around insider threat management
  2. Manage Insider Threat Monitoring program by ensuring  processing security alerts generated by the various monitoring tools and technologies operated by the team in order to identify potential instances of data loss / exfiltration and other activity which may pose a potential Insider Threat risk
  3. Prepare and operationalize the relevant Alert/ Incident metrics, as part of the overall infosec function
  4. Manage escalations of security alerts for review by business line management, seek response and validate vis-a-vis SBI card information security policies and allowed security practices
  5. Manage escalations of security incidents alerts to SBIC Compliance Team and Co-ordinate with them for presentation in the steering committees for formal review and decisioning on the Disciplinary actions
  6. Provide feedback to the DLP(Data Leak prevention) Team basis review of the Alerts, Incidents identified as per the existing DLP rules 
  7. Review the classification of alerts raised on a periodic basis to decrease false positives
  8. Lead maintain internal users (FTEs and NFTEs) related security incidents which could indicate a potential Insider Threat risk, and maintain detailed trackers for incidents witnessed and actions taken
  9. Ensure end to end tracking of Insider threat alerts and incidents, including disciplinary actions taken by responsible business/ Human resource/ legal function
  10. Provide inputs to the Enterprise risk management committee(ERMC)/Information Security Committee(ISC) as per the prescribed frequency regarding incidents and actions taken on incidents
  11. Participate in Disaster Recovery Planning, testing, troubleshooting and root cause analysis and documentation of the root causes
  12. Manage Service Partner operation from technology prospective
  13. Ensure process documentation and compliance adherence

Measures of Success 

  1. Successful development and monitoring of insider threat program
  2. Increase in maturity of insider threat Programs (Adoption & Capabilities)
  3. Timely delivery of project plans, milestone updates, presentations, assessment reports etc. to relevant stakeholders
  4. Security metrics within acceptable threshold
  5. Availability of DLP as a service in line with the enterprise expectations
  6. Resolution of all technical issues reported by users within agreed TAT
  7. Timely updation of DLP related SOPs and other documents 
  8. No adverse observations in Internal / External Audits 
  9. Process Adherence as per MOU

Technical Skills / Experience / Certifications

  1. Knowledge and in-depth understanding of Log management and processing
  2. Experience in Technologies like DLP, CASB, UAM, Data Classification, IRM 
  3. Knowledge of cybersecurity risks and information security standards 
  4. Understanding of security controls from a people, process and technology perspective. 
  5. Knowledge of standard security processes and guidelines.
  6. Certifications including, Security+, CEH, GCIA, GCIH or similar
  7. Knowledge of insider and privacy frameworks such as - NIST, DSCI, ISO, PCI, GDPR, etc.
  8. Prior experience working in a Security Operations Center (SOC)
  9. Experience in managing data incidents and breaches

Competencies critical to the role

  1. Detail Orientation
  2. Teamwork and Collaboration
  3. Stakeholder Management
  4. Analytical ability
  5. Problem Solving

Qualification 

Bachelor’s Degree or B.Tech in Computer Science / Information Technology or in a related discipline

Preferred Industry

BFSI / NBFC /E-commerce/IT & ITES / Telecom

Skills Required

  • Bachelor's Degree or B.Tech in Computer Science / Information Technology or related discipline
  • Knowledge and in-depth understanding of log management and processing
  • Experience with DLP (Data Loss Prevention)
  • Experience with CASB (Cloud Access Security Broker)
  • Experience with UAM (User Activity Monitoring) and Data Classification
  • Experience with IRM (Information Rights Management)
  • Knowledge of cybersecurity risks and information security standards
  • Understanding of security controls across people, process, and technology
  • Certifications such as Security+, CEH, GCIA, GCIH or similar
  • Knowledge of insider/privacy frameworks such as NIST, DSCI, ISO, PCI, GDPR
  • Prior experience working in a Security Operations Center (SOC)
  • Experience managing data incidents and breaches
  • Preferred industry experience: BFSI, NBFC, E-commerce, IT & ITES, Telecom
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Calcutta
24,089 Employees

What We Do

SBI Card was launched in 1998 with the State Bank of India, India's largest bank, as the majority stakeholder. In March 2020, SBI Card was listed on BSE and NSE. Today, SBI Card is India’s largest pure-play credit card issuer with over 20 million cards in force, as of December 2024. Its wide array of products and services caters to a diverse range of customer segments across India, right from new-to-credit to super premium. The SBI Card brand is based on the value proposition of 'Make Life Simple'. The proposition manifests in SBI Card’s continuous efforts to simplify the lives of its customers, employees and other key stakeholders. Customer-centricity, supported by the values of trust and transparency, is core to SBI Card’s ethos.

Similar Jobs

Ericsson Logo Ericsson

Performance and Business Operation

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Gurgaon, Gurugram, Haryana, IND
88000 Employees

Capco Logo Capco

Visualisation Analyst (Liquidity & Treasury)

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
India
6000 Employees

McCain Foods Logo McCain Foods

Associate Director - App Engineering

Food • Retail • Agriculture • Manufacturing
In-Office
Gurugram, Haryana, IND
20000 Employees

BlackRock Logo BlackRock

Artificial Intelligence Engineer

Fintech • Information Technology • Financial Services
In-Office
2 Locations
25000 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account