Lead Security Assurance
Angel One · Mumbai, Maharashtra, India
Angel One · Mumbai, Maharashtra, India
**Role & responsibilities** **SEBI CSCRF Compliance (Primary Responsibility)** - Serve as the subject matter expert for SEBI CSCRF across Angel One. - Lead implementation, monitoring, and continuous improvement of controls required under SEBI CSCRF. - Interpret regulatory requirements and convert them into technical and operational security controls. - Ensure evidence collection for regulatory audits. - Track compliance status across all CSCRF domains. - Review control effectiveness. - Maintain regulatory dashboards. - Coordinate regulatory submissions. - Support SEBI inspections and audits. - Drive closure of regulatory observations. - Develop internal CSCRF maturity assessments. **2. Security Assurance** - Develop and execute the organization's Security Assurance strategy. - Perform technical assurance across: - Infrastructure - Cloud - Applications - APIs - Databases - Containers - Kubernetes - CI/CD - Identity Platforms - End User Computing - Validate implementation of security controls. - Conduct security architecture reviews. - Perform security design assessments. - Review technical standards. - Recommend security improvements. **3. Vulnerability Management** - Own enterprise vulnerability management lifecycle. - Coordinate: - Infrastructure VA - Application VA - Cloud Assessments - Container Security - API Security - Network Assessments - External Attack Surface Monitoring - Review scan configurations. - Validate scan coverage. - Review vulnerability accuracy. - Ensure remediation SLAs are met. - Identify recurring security issues. - Perform trend analysis. - Drive reduction in organizational risk **4. VAPT Governance** - Manage bi-annual and ad-hoc VAPT exercises. - Coordinate with CERT-In empanelled auditors. - Validate: - Scope - Tool configurations - Coverage - Raw reports - False positives - Vulnerability counts - Severity classification - Risk acceptance - Ensure submissions satisfy SEBI expectations. - Maintain audit-ready evidence. **Preferred candidate profile** **Mandatory** - Deep expertise in **SEBI CSCRF** - Experience supporting SEBI regulated entities - Security Assurance - Risk Assessments - Infrastructure Security - Cloud Security - Application Security - Vulnerability Management - Security Governance - Audit Management **Experience** - 10 12 years in Information Security. - Minimum 6 years in Security Assurance or Security Governance. - Experience working in: Banking, Capital Markets, Stock Exchanges, Brokerages, Financial Services, FinTech - Experience handling regulatory audits. - Experience interacting with auditors. - Experience driving remediation. **Qualifications** Bachelor's degree in Engineering, Computer Science, Information Security, or related discipline. Preferred Certifications: - CISSP - CISA - CCSP - CCSK - ISO 27001 Lead Auditor - AWS Security Specialty - Azure Security Engineer - GCP Professional Cloud Security Engineer