While the role descriptions give you an overview of the responsibilities, it is only directional and guiding in nature. At ICICI Bank, we believe in serving our customers beyond our role definition, product boundaries, and domain limitations through our philosophy of customer 360-degree. In essence, this captures our belief in serving the entire banking needs of our customers as One Bank, One Team. To achieve this, employees at ICICI Bank are expected to be role and location-fungible with the understanding that Banking is an essential service.
About the role
The role requires mentoring a team of risk analysts for performing periodic assessment of IT related risks. This would entail performing the second layer of IT risk assessment by applying independent challenge to the Risk and Control Self Assessments conducted by the first line of defence; and assist tracking of remediation and management of open risks. Additionally, risk assessment as a component of risk management is employed on an ongoing basis and performed in form of Thematic review. An Annual Plan needs to be developed by considering new activities, closure of old activities, automations, audit observations etc.
Key Responsibilities:
Maintain and update IT risk database comprising IT related risk incidents, IT key risk indicators and IT risk register
Conceptualise themes for performing risk assessments of IT assets and IT operational areas
Develop skill sets in a team of risk analysts for developing quantitative models for performing comprehensive risk assessments encompassing business risks emanating out of use of technology, technology operational risks, regulatory and compliance risks, third party dependency risks etc.
Review of risks assessments throughout its life cycle for coverage, quality and timeliness
Summarising assessments in impactful Presentations to highlight managed risks vis--vis open risks
Collaboration with technology, business, risk, compliance, and audit functions for conduct effective risk assessments and reporting outcomes to Banks committees
Identify emerging risks that could impact the threat landscape of Banks technology ecosystem
Continuous engagement with subject matter experts to provide independent perspective on IT related risks to internal stakeholders
Key Qualifications & Skills:
B.E / B.Tech in IT /Computers/ Chartered Accountant
10 to 15 years of Hand on experience in IT Risk and/ or IT Audit function
Work experience in assessing various IT components i.e. applications, middleware, operating systems, databases, network and security tools, APIs, Cloud computing
Work experience in assessing key IT processes i.e. identity and access management, privilege access management, change management, capacity management, configuration management, IT incident management, IT project management, IT vendor management, application lifecycle management, data center processes
Well versed with information security controls for securing IT assets and data such as authentication, encryption/ masking/ redaction, secure hardening and patching, integration with PIM, PAM, SIEM, DAM, WAF etc.
Work experience in decoding regulatory expectations by assessing compliance with Master Directions and circulars issued by RBI for technology domain from time to time.
Candidate should be able to add value to existing IT operational areas by suggesting controls, methodologies and new technologies as per industry best practices and risk landscape
Resilient, Communication, Problem solving skills
Candidate must be certified in CISA and well versed with international frameworks like NIST, ISO, COBIT
About the Business Group:
ICICI Banks Technology Risk vertical of Information Security Group which believes in providing services to its customers in the safest and secure manner keeping in mind that data protection and secure Technology for its customers is as important as providing quality banking services across the spectrum.
Job Classification
Industry: Financial ServicesFunctional Area / Department: IT & Information SecurityRole Category: IT SecurityRole: Security Architect / ConsultantEmployement Type: Full time