I

Information Security Manager - Cloud

ICICI Bank · Mumbai, Maharashtra, India

8–15 yrs experiencefull_timePosted 1w ago
Apply now →

Job description

**Essential Services: Role & Location Fungibility:** While the role descriptions give you an overview of the responsibilities, it is only directional and guiding in nature. At ICICI Bank, we believe in serving our customers beyond our role definition, product boundaries, and domain limitations through our philosophy of customer 360-degree. In essence, this captures our belief in serving the entire banking needs of our customers as One Bank, One Team. To achieve this, employees at ICICI Bank are expected to be role and location-fungible with the understanding that Banking is an essential service. **About the Role:** We are currently seeking professionals to join our team in the role of Information Security Manager in ICICI Bank. The Information Security Manager is responsible for leading and managing the organization’s information security program to ensure the confidentiality, integrity, and availability of data, systems, and networks. This role involves developing, implementing, and maintaining security policies, standards, and procedures, overseeing compliance efforts, and responding to evolving cyber threats. The Information Security Manager works closely with technical teams, business leaders, and external stakeholders to foster a culture of security and effectively mitigate risks. Hands-on experience in Cloud (OCI/GCP) security architecture, security engineering, or equivalent experience with vendor specific cloud certification. **Key Responsibilities:** - Lead Cloud Security Risk Management team for managing, prioritizing, and acting on risks in large scale multi-cloud environment. - Conduct cloud risks assessments for new proposals and review changes in existing environment. - Manage Cloud Security Operations including, inventory, Cloud security change management, security compliance review, tracking and closure of open risks. - Work closely with Technology team and other stakeholders for addressing / mitigating cloud risks. - Design and develop security architectures for cloud and cloud/hybrid-based systems. Possess a firm understanding of the offerings within OCI and GCP platforms. Based on business requirements, design and implement cloud architectures and designs with a minimal degree of risk and with appropriate security controls present. - Represents Security Platform in development and implementation of the overall global enterprise cloud architecture. Acts as senior technical representative for Enterprise Security while engaging with other senior technical leaders throughout organization in design and implementation of cloud and cloud/hybrid-based implementations and solutions. Works with Engineering, Infrastructure Services, and Application Development organizations to choose appropriate technology solutions and facilitates complete integration into the company environments. Develops standards in partnership with Engineering, Infrastructure Services, and Application Development. - Leads initiatives designed to share knowledge across Security Platforms and/or Technology teams. Identifies, recommends, coordinates, deliver timely knowledge to support teams regarding technologies, processes, or tools. Develops and executes strategies to increase Cloud Security knowledge throughout the enterprise. - Develops standards, policies, and procedures best practices documentation. - Participate in working groups that tailor the company’s security policies and standards for use in cloud environment **Key Qualifications & Skills:** - **Education Qualification:** Engineering Graduate in CS, IT, EC or InfoSec, CyberSec or MCA equivalent. - **Certifications:** Certification(s) such as CISSP, CISM, or equivalent are preferred. - **Compliance:** Great Awareness of cyber security trends & hacking techniques. - **Communication Skills:** Good oral and written communication skills. Strong organizational, teamwork, multitasking & time management skills - **Synergize with the Team:** Outstanding communication abilities. Ability to effectively communicate the required recommendations. Strong attention to detail with an analytical mindset & outstanding problem-solving skills - Experience with assessment, development, implementation, optimization, and documentation of a comprehensive and broad set of security technologies and processes (secure software development (Application Security), data protection, cryptography, key management, identity and access management (IAM), network security) , Infrastructure as Code (IaC) within SaaS, IaaS, PaaS, and other cloud environments. - Working knowledge of common and industry standard cloud-native/cloud-friendly authentication mechanisms (OAuth, OpenID, etc.). - Experience with deployment orchestration, automation, and security configuration management preferred - Experience with service-oriented architecture for cloud-based services. - Experience working with cloud security and governance tools, cloud access security brokers (CASBs), and server virtualization technologies. - Experience with enterprise applications (architecture, development, support, and troubleshooting). - Proficient in preparation of reports, dashboards, and documentation - Experience in maintaining various metrics **Few Success Factors:** - Strategic Focus - Openness to collaborate - Vigil on norms & regulations - Orientation to understand business - Learning aptitude **About the Business Group:** The Information Security Group at ICICI Bank believes in providing services to its customers in the safest and secure manner keeping in mind that data protection for its customers is as important as providing quality banking services across the spectrum. The CIA triad of Confidentiality, Integrity, and Availability is at the heart of building a comprehensive information security framework. The Bank also lays emphasis on customer elements like protection from phishing, adaptive authentication, awareness initiatives, and provide easy to use protection and risk configuration abil