I

Information Security Manager - Cloud SaaS

ICICI Bank · Mumbai, Maharashtra, India

full_timePosted 1w ago
Apply now →

Job description

**Essential Services: Role & Location Fungibility:** While the role descriptions give you an overview of the responsibilities, it is only directional and guiding in nature. At ICICI Bank, we believe in serving our customers beyond our role definition, product boundaries, and domain limitations through our philosophy of customer 360-degree. In essence, this captures our belief in serving the entire banking needs of our customers as One Bank, One Team. To achieve this, employees at ICICI Bank are expected to be role and location-fungible with the understanding that Banking is an essential service. **About the Role:** We are currently seeking professionals to join our team in the role of Information Security Manager in ICICI Bank. The Information Security Manager is responsible for leading and managing the organization’s information security program to ensure the confidentiality, integrity, and availability of data, systems, and networks. This role involves developing, implementing, and maintaining security policies, standards, and procedures, overseeing compliance efforts, and responding to evolving cyber threats. The Information Security Manager works closely with technical teams, business leaders, and external stakeholders to foster a culture of security and effectively mitigate risks. To utilize the expertise in SaaS cloud security and risk management to proactively assess, identify, and mitigate risks across cloud-based applications and services. To support organizational resilience by ensuring compliance with regulatory standards, enhancing security posture, and contributing to the development of robust cloud governance frameworks. **Key Responsibilities** 1. Risk Identification & Assessment Regularly assess SaaS applications for security risks, misconfigurations, and data exposure. Evaluate vendor risk, including third-party integrations and supply chain dependencies. Identify gaps in access controls, data handling, and encryption practices. 2. Security Posture Evaluation Review SaaS platforms for adherence to security best practices (e.g., SSO, MFA, RBAC). Monitor changes in SaaS configurations and assess their impact on risk posture. Use tools like CASB (Cloud Access Security Broker) or SSPM (SaaS Security Posture Management) to automate assessments. 3. Compliance & Regulatory Alignment Ensure SaaS usage complies with internal policies and external regulations (e.g., RBI, GDPR, HIPAA, SOC 2). Support audit readiness by maintaining documentation and evidence of controls. 4. Technical & Analytical Skills Analyze SaaS environments using security tools and dashboards. Understand API integrations, data flows, and how they impact risk. Use scripting or automation to streamline risk assessment processes. 5. Reporting & Communication Create clear, actionable risk reports for stakeholders. Communicate findings to IT, security, and business teams to drive remediation. Maintain a risk register and track mitigation progress. 6. Continuous Monitoring & Improvement Stay updated on emerging SaaS threats, vulnerabilities, and vendor updates. Recommend improvements to SaaS governance and onboarding processes. Contribute to the development of SaaS security policies and standards. **Key Qualifications & Skills:** - **Education Qualification:** Engineering Graduate in CS, IT, EC or InfoSec, CyberSec or MCA equivalent. - **Certifications:** Certification(s) such as CISSP, CISM, or equivalent are preferred and any global cloud certifications. - **Compliance:** Great Awareness of cyber security trends & hacking techniques. - **Communication Skills:** Good oral and written communication skills. Strong organizational, teamwork, multitasking & time management skills - **Synergize with the Team:** Outstanding communication abilities. Ability to effectively communicate the required recommendations. Strong attention to detail with an analytical mindset & outstanding problem-solving skills **Few Success Factors:** - Strategic Focus - Openness to collaborate - Vigil on norms & regulations - Orientation to understand business - Learning aptitude **About the Business Group:** The Information Security Group at ICICI Bank believes in providing services to its customers in the safest and secure manner keeping in mind that data protection for its customers is as important as providing quality banking services across the spectrum. The CIA triad of Confidentiality, Integrity, and Availability is at the heart of building a comprehensive information security framework. The Bank also lays emphasis on customer elements like protection from phishing, adaptive authentication, awareness initiatives, and provide easy to use protection and risk configuration ability in the hands of customers. The Bank also undertakes campaigns to create awareness among customers on security aspects while banking through digital channels.