Fintech Integration - Risk Assessment
ICICI Bank · Mumbai, Maharashtra, India
ICICI Bank · Mumbai, Maharashtra, India
**Essential Services: Role & Location Fungibility** While the role descriptions give you an overview of the responsibilities, it is only directional and guiding in nature. At ICICI Bank, we believe in serving our customers beyond our role definition, product boundaries, and domain limitations through our philosophy of customer 360-degree. In essence, this captures our belief in serving the entire banking needs of our customers as One Bank, One Team. To achieve this, employees at ICICI Bank are expected to be role and location-fungible with the understanding that Banking is an essential service. **About the Role** Vendor risk assessment with experience in Account aggregator/Fintech and heavy IT information Security risk assessment with 6 to 8 years of experience. This is Senior Lead role involves Fintech operations Cybersecurity compliance and strategic vendor security assessment This role also combines security assessment in terms of integration and components of underlying technology involved in development of software and technologies. **Key Responsibilities** - Perform vendor Assessment to comprehensively assess technical and operational audit of third-party vendors (Fintech, Payment gateway, Account Aggregators, software development firms, Heavy IT). - Assess account aggregators integration and data security of secure financial data transactions and exchange. - Review and assess security architecture and configurations not limited to software architecture, network segmentation, API, Web and hosting platforms both on-premise and cloud. - Assess third-party application security assessment ensuring compliance and regulations as set by RBI, SEBI, PCIDSS, ISO 27001:2022. - Assess third-party vendors for data protection, sovereignty and transparency risks. - Have a good understanding of risk assessment and mitigation methodologies. - Documenting and presenting risks analysis along with statistics of key metrics and KPIs. - Excellent documentation and communication skills, processing and assessing service agreements, multiple stakeholder management. - Experience in presenting assessment report to senior management committee. **Preferred skills and certifications** - CRISC, CISA, CISSP, ISO27001-2022 certified. - Strong communication and reporting skills for Auditors, regulators and leadership teams. - Good hands on with understanding and implementing controls from regulators, compliance, and statutory bodies across geography. **Must have** - Must have attended or lead information security audits preferably with RBI/SEBI, ISO27001, PCIDSS - Minimum 7 years of experience in information security. - At least 4 to 5 years of experience in Vendor risk assessment, architecture review & cyber security control reviews. - Minimum of 7 years experience in cyber risk management and mitigation. - Minimum of 3 years experience in application security. - Minimum of 3 years experience of Team management **About the Business Group** The Information Security Group (ISG) identifies, assesses, and appropriately manages risks to ICICI Bank's information and information systems. It oversees and ensures compliance with the directives, circulars, and regulatory requirements. It evaluates the options for dealing with these risks. It works with departments throughout the Bank to decide upon and implement controls that appropriately and proactively respond to these same risks. The ISG is also responsible for developing requirements that apply to the group companies and external information systems in which ICICI Bank participates (for example - extranets). These requirements include information security policies, standards, and procedures. ISG is the focal point for all matters related to information security. It is responsible for all endeavours within ICICI Bank that seek to avoid, prevent, detect, correct, or recover from threats to information or information systems.