- Develop & maintain the Enterprise Information Security Policy & Standards for the organisation - Design, plan and drive information security awareness programs, training, induction sessions, and build risk awareness within the organisation - Ensure organisational compliance with corporate information security policy, procedures, and regulations by conducting audits and monitoring. - Responsible for compliance &reporting on various security aspects like patches, antivirus, encryption, etc., to management. - Ensure senior management remain informed of regulatory, information security changes and the obligations under the IT act. - Proactively identify emerging risks, perform vulnerability and penetration testing with partners' help, and report to relevant stakeholders. - Manage all internal & external audits, including client audits from information security compliance - Develop & Maintain Risk Register for the organisation and train departmental risk champions on implementation - Monitor implementation of action plans to ensure risk mitigation efforts are proceeding as required - Liaise with department and division heads on the adequacy of proposed actions in the management of risk areas highlighted in internal & external audit reports - Conduct Information security meetings to keep management updated on currently identified risks and mitigation plans - Responsible for doing vendor & their solution assessment from an information security perspective before onboarding new vendors. - Responsible for designing security framework for new solutions like Manufacturing Execution System
Interested candidates are required to send their resume to: hidden_email

Keyskills: internal audit risk assessment compliance management risk management financial services business process improvement internal controls regulatory compliance auditing legal compliance