HamburgerMenu
hirist

Job Description

Role & responsibilities:

1. SEBI CSCRF Compliance (Primary Responsibility):

- Serve as the subject matter expert for SEBI CSCRF across Angel One.

- Lead implementation, monitoring, and continuous improvement of controls required under SEBI CSCRF.

- Interpret regulatory requirements and convert them into technical and operational security controls.

- Ensure evidence collection for regulatory audits.

- Track compliance status across all CSCRF domains.

- Review control effectiveness.

- Maintain regulatory dashboards.

- Coordinate regulatory submissions.

- Support SEBI inspections and audits.

- Drive closure of regulatory observations.

- Develop internal CSCRF maturity assessments.

2. Security Assurance:

- Develop and execute the organization's Security Assurance strategy.

- Perform technical assurance across:

1. Infrastructure

2. Cloud

3. Applications

4. APIs

5. Databases

6. Containers

7. Kubernetes

8. CI/CD

9. Identity Platforms

10. End User Computing

- Validate implementation of security controls.

- Conduct security architecture reviews.

- Perform security design assessments.

- Review technical standards.

- Recommend security improvements.

3. Vulnerability Management:

- Own enterprise vulnerability management lifecycle.

- Coordinate:

1. Infrastructure VA

2. Application VA

3. Cloud Assessments

4. Container Security

5. API Security

6. Network Assessments

7. External Attack Surface Monitoring

- Review scan configurations.

- Validate scan coverage.

- Review vulnerability accuracy.

- Ensure remediation SLAs are met.

- Identify recurring security issues.

- Perform trend analysis.

- Drive reduction in organizational risk.

4. VAPT Governance:

- Manage bi-annual and ad-hoc VAPT exercises.

- Coordinate with CERT-In empanelled auditors.

- Validate:

1. Scope

2. Tool configurations

3. Coverage

4. Raw reports

5. False positives

6. Vulnerability counts

7. Severity classification

8. Risk acceptance

- Ensure submissions satisfy SEBI expectations.

- Maintain audit-ready evidence.

Preferred candidate profile:

Mandatory:

- Deep expertise in SEBI CSCRF.

- Experience supporting SEBI regulated entities.

- Security Assurance.

- Risk Assessments.

- Infrastructure Security.

- Cloud Security.

- Application Security.

- Vulnerability Management.

- Security Governance.

- Audit Management.

Experience:

- 10-12 years in Information Security.

- Minimum 6 years in Security Assurance or Security Governance.

- Experience working in: Banking, Capital Markets, Stock Exchanges, Brokerages, Financial Services, FinTech.

- Experience handling regulatory audits.

- Experience interacting with auditors.

- Experience driving remediation.

Qualifications:

Bachelor's degree in Engineering, Computer Science, Information Security, or related discipline.

Preferred Certifications:

- CISSP

- CISA

- CCSP

- CCSK

- ISO 27001 Lead Auditor

- AWS Security Specialty

- Azure Security Engineer

- GCP Professional Cloud Security Engineer

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...