Senior Leader Information Security

Posted Yesterday
Be an Early Applicant
Mumbai, Maharashtra, IND
In-Office
Senior level
Fintech • Payments • Financial Services
The Role
Leads third-party information security risk, compliance, controls, and cybersecurity oversight for member banks and payment providers. Manages stakeholder relationships with executives, regulators, and government bodies; conducts third-party assessments and audits; identifies and closes security gaps; oversees privacy compliance under DPDP and GDPR; and advises on IAM, cloud, application, infrastructure security, DevSecOps, and international security frameworks.
Summary Generated by Built In
About the role

This role is responsible for ascertaining and overseeing the risk and security guidelines and controls applicable to third parties interacting with NPCI. It will ensure ecosystem-wide compliance with evolving security requirements arising from innovations across the organization.

The core focus of the role will be to ensure that member banks and TPAPs comply with the standards laid down by NPCI. It will also interface with CERT-In, NCIIPC, NCCC, RBI, MeitY and other government bodies on cybersecurity-related matters.
​
The role will also play a key part in addressing privacy-related aspects, including adherence to the DPDP Act, GDPR and other applicable data protection requirements.

What you’ll own

Stakeholder Management and Leadership
■Provide direction on regulatory compliance and cybersecurity protection.
■Demonstrate a thorough understanding of international governance and management principles.
■Engage with multiple stakeholders across organizational boundaries.

Risk and Control Objectives
■Develop and maintain robust international information security controls.
■Provide an external perspective to strengthen the design and implementation of security controls.
■Lead and review assessments for external agencies and members.

Decision-Making and Problem-Solving
■Make decisions regarding the maintenance of the security posture of the organization and its subsidiaries.
■Identify emerging global cyber-threat trends and align organizational strategy to address them.
■Provide solutions to address international challenges related to security architecture.

Specialization in Multiple Security Domains
■Act as a subject matter expert (SME) across multiple internal security domains, such as Identity and Access Management (IAM), infrastructure security, application security cloud security, Data Privacy and DPDP Act.
■Engage with development teams to enable DevSecOps.
■Demonstrate SME-level knowledge of key security and data protection standards and frameworks, such as GDPR, CIS, ISO 27001, NIST and PCI DSS.

What sets you apart

Major Challenges
■Coordinating with external entities and multiple stakeholders on information security-related matters.
■Identifying security gaps and following up to ensure their closure.
■Focusing information security operations on external parties and addressing data protection and privacy-related concerns.

Decisions Made by the Job Holder
■Reviewing and verifying controls relating to third-party applications and member banks.
■Certifying third parties associated with NPCI.
■Reviewing information security controls and guidelines followed by TPAPs and member banks.
■Effectively addressing various data-related concerns, as required by the Data Protection Officer (DPO), and ensuring adherence to DPDP and GDPR requirements.
■Conducting various third-party audits to ensure acceptable levels of cyber hygiene.

Recommendations to or Approval by Superior
■Exceptions and approvals relating to third-party risks.
■Measures to strengthen ecosystem-wide cyber hygiene.
■Matters relating to data protection and privacy.


Requirements
  • Understanding of Cybersecurity maturity frameworks and Information security standards like, but not limited to, ISO 27701, GDPR, PCI DSS, NIST 800-53, CIS 20, ISO 22301.

  • Experience at engaging, influencing, and managing multiple stakeholders across departmental and organizational boundaries up to C-suite.

  • Excellent understanding of legislations and regulations that impact Information security, e.g. GDPR.

  • Develop, implement and administer technical security standards as well as a suite of security practices.

  • Understanding of cloud service deployment and architecture with implementation experience on multiple cloud platforms like AWS, Azure, GCP etc.

  • Good understanding of security technologies and wider payment business solutions like Firewall, IDS/IPS, PIM/PAM, IAM setup, APIs, ISO 8583 etc.

  • Understanding of the emerging threat landscape and technologies, and what measures can be taken to protect the information security posture of the organization.


Skills Required

  • Understanding of cybersecurity maturity frameworks and information security standards, including ISO 27701, GDPR, PCI DSS, NIST 800-53, CIS Controls, and ISO 22301
  • Experience engaging, influencing, and managing stakeholders across departmental and organizational boundaries up to the C-suite
  • Excellent understanding of legislation and regulations affecting information security, including GDPR
  • Ability to develop, implement, and administer technical security standards and security practices
  • Understanding of cloud service deployment and architecture, with implementation experience across AWS, Azure, or GCP
  • Understanding of security technologies and payment business solutions, including firewalls, IDS/IPS, PIM/PAM, IAM, APIs, and ISO 8583
  • Understanding of emerging cyber threats, technologies, and measures to protect organizational information security posture
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Mumbai, Maharashtra
2,124 Employees
Year Founded: 2005

What We Do

NPCI is an umbrella organisation for all retail payment systems in India. It was set up with the support & guidance from Reserve Bank of India (RBI) & Indian Banks Association (IBA). A registered company under Section 8 of the Companies Act, 2013. Watch the NPCI Corporate AV - https://youtu.be/RGl9YQ6CB20 Products & Services Unified Payments Interface Unique payment solution which empowers a recipient to initiate the payment request from a smartphone. It facilitates 'virtual payment address'​ as a payment identifier for sending & collecting money & works on single click 2 factor authentication. Immediate Payment Service A 24X7, real time, cost effective, independent channel, retail payment service, introduced by NPCI, empowering customers to transfer money instantly with banks & RBI authorised PPIs across India. RuPay Robust card scheme designed to offer payment products with superior features & processes specifically designed to cater to diverse consumer needs. *99# USSD based mobile banking platform that makes banking services accessible to all the bank account holders on their mobile phones. National Automated Clearing House Centralised payment system developed with an aim to consolidate multiple ECS systems running across the country & provide a framework for the removal of local barriers/inhibitors. Aadhaar Enabled Payment System Bank led model which allows online financial inclusion transactions at micro-ATMs through the business correspondent of any bank using the Aadhaar authentication. e-KYC Electronic way of conducting authentic & real time KYC of a customer using Aadhaar authentication. Cheque Truncation System Electronic image of the cheque is transmitted to the drawee bank by the clearing house, along with relevant information. National Financial Switch Facilitates routing of ATM transactions through inter-connectivity between its member institutions thereby enabling the citizens of the country to utilise any ATM of a connected entity

Similar Jobs

CSC Logo CSC

Technical Product Trainer - CA Fresher

Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Hybrid
2 Locations
8500 Employees

Circle (circle.so) Logo Circle (circle.so)

Lead Engineer, AI Platform

Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
In-Office or Remote
18 Locations
250 Employees

Circle (circle.so) Logo Circle (circle.so)

Senior Quality Engineer

Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
In-Office or Remote
18 Locations
250 Employees
120K-130K Annually

Circle (circle.so) Logo Circle (circle.so)

Designer

Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
In-Office or Remote
18 Locations
250 Employees
100K-120K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account