I

Information Security - Compliance Manager

ICICI Bank · Mumbai, Maharashtra, India

full_timePosted 2w ago
Apply now →

Job description

**Essential Services: Role & Location Fungibility:** While the role descriptions give you an overview of the responsibilities, it is only directional and guiding in nature. At ICICI Bank, we believe in serving our customers beyond our role definition, product boundaries, and domain limitations through our philosophy of customer 360-degree. In essence, this captures our belief in serving the entire banking needs of our customers as One Bank, One Team. To achieve this, employees at ICICI Bank are expected to be role and location-fungible with the understanding that Banking is an essential service. **About the Role:** As an Information and Cyber Security Professional in ICICI Bank, you will have an opportunity to work across the following functions: • Cybersecurity Governance Framework • Regulatory Compliance Management • IS & CS Risk and control • Metrics, reporting, and regulatory communication • Audit and regulatory governance support **Key Responsibilities** • **Regulatory Compliance Management** : Assisting to analyze and implement RBI circulars, guidelines (e.g., Master Direction on Cybersecurity Framework), and notifications related to IT and cybersecurity • **Policy and Governance:** Develop and maintain the Information Security and Cybersecurity Compliance Framework in accordance with RBI norms. Coordinate regular review and updates to security policies, procedures, and controls. • **Risk Assessment and Audit** : Assist in cyber risk assessments and gap analysis based on RBI guidelines. Coordinate internal and external audits related to cyber and information security. Assist in timely closure of compliance gaps, audit findings, and regulatory observations. • **Reporting and Documentation** : Prepare periodic regulatory reports (e.g., Cyber Security Incident Reports, RBS, CRILC related inputs). Maintain records for compliance evidence, including risk assessments, monitoring logs, and audit trails. • **Audit and Regulatory Governance Support:** Coordinate cyber governance aspects of internal/external audits and regulatory inspections. Track governance-related audit findings and manage timely closure and documentation. **Key Qualification and Skills:** • **Education Qualification:** Engineering Graduate in CS, IT, EC or InfoSec, CyberSec or MCA equivalent • **Certifications** : ISO27001, CISSP, CISM, CISA, CRISC, PCI-DSS ISA, CPISI • **Compliance** : Knowledge of handling and reviewing the RBI cyber security requirements of business team such as Data localization SAR, PA/PG guidelines SAR, RBI Master Direction in Digital payment security controls requirements, V-KYC, Tokenization guidelines, etc. • **Communication Skills:** Good oral and written communication skills. • **Synergize with the Team** : Regular interaction with various business unit functions such as Cards, NEFT, RTGS, IMPS, Mobile Banking, Internet Banking, swift AEPS, I-core, Treasury, ATM, POS, E-commerce, payment gateway, payment aggregator, offline merchants, etc. **About the Business Group** The Information Security Group (ISG) identifies, assesses, and appropriately manages risks to ICICI Bank's information and information systems. It oversees and ensures compliance with the directives, circulars, and regulatory requirements. It evaluates the options for dealing with these risks. It works with departments throughout the Bank to decide upon and implement controls that appropriately and proactively respond to these same risks. The ISG is also responsible for developing requirements that apply to the group companies and external information systems in which ICICI Bank participates (for example - extranets). These requirements include information security policies, standards, and procedures. ISG is the focal point for all matters related to information security. It is responsible for all endeavours within ICICI Bank that seek to avoid, prevent, detect, correct, or recover from threats to information or information systems.