Posted on: 29/07/2026
Role & responsibilities:
1. SEBI CSCRF Compliance (Primary Responsibility):
- Serve as the subject matter expert for SEBI CSCRF across Angel One.
- Lead implementation, monitoring, and continuous improvement of controls required under SEBI CSCRF.
- Interpret regulatory requirements and convert them into technical and operational security controls.
- Ensure evidence collection for regulatory audits.
- Track compliance status across all CSCRF domains.
- Review control effectiveness.
- Maintain regulatory dashboards.
- Coordinate regulatory submissions.
- Support SEBI inspections and audits.
- Drive closure of regulatory observations.
- Develop internal CSCRF maturity assessments.
2. Security Assurance:
- Develop and execute the organization's Security Assurance strategy.
- Perform technical assurance across:
1. Infrastructure
2. Cloud
3. Applications
4. APIs
5. Databases
6. Containers
7. Kubernetes
8. CI/CD
9. Identity Platforms
10. End User Computing
- Validate implementation of security controls.
- Conduct security architecture reviews.
- Perform security design assessments.
- Review technical standards.
- Recommend security improvements.
3. Vulnerability Management:
- Own enterprise vulnerability management lifecycle.
- Coordinate:
1. Infrastructure VA
2. Application VA
3. Cloud Assessments
4. Container Security
5. API Security
6. Network Assessments
7. External Attack Surface Monitoring
- Review scan configurations.
- Validate scan coverage.
- Review vulnerability accuracy.
- Ensure remediation SLAs are met.
- Identify recurring security issues.
- Perform trend analysis.
- Drive reduction in organizational risk.
4. VAPT Governance:
- Manage bi-annual and ad-hoc VAPT exercises.
- Coordinate with CERT-In empanelled auditors.
- Validate:
1. Scope
2. Tool configurations
3. Coverage
4. Raw reports
5. False positives
6. Vulnerability counts
7. Severity classification
8. Risk acceptance
- Ensure submissions satisfy SEBI expectations.
- Maintain audit-ready evidence.
Preferred candidate profile:
Mandatory:
- Deep expertise in SEBI CSCRF.
- Experience supporting SEBI regulated entities.
- Security Assurance.
- Risk Assessments.
- Infrastructure Security.
- Cloud Security.
- Application Security.
- Vulnerability Management.
- Security Governance.
- Audit Management.
Experience:
- 10-12 years in Information Security.
- Minimum 6 years in Security Assurance or Security Governance.
- Experience working in: Banking, Capital Markets, Stock Exchanges, Brokerages, Financial Services, FinTech.
- Experience handling regulatory audits.
- Experience interacting with auditors.
- Experience driving remediation.
Qualifications:
Bachelor's degree in Engineering, Computer Science, Information Security, or related discipline.
Preferred Certifications:
- CISSP
- CISA
- CCSP
- CCSK
- ISO 27001 Lead Auditor
- AWS Security Specialty
- Azure Security Engineer
- GCP Professional Cloud Security Engineer
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1658543