Upload Button Icon Add office photos
Engaged Employer

i

This company page is being actively managed by Crisil Team. If you also belong to the team, you can get access from here

Crisil Verified Tick

Compare button icon Compare button icon Compare
3.7

based on 1.5k Reviews

filter salaries All Filters

500 Crisil Jobs

Crisil - Associate Director - Information Security/Governance/Risk & Compliance (12-18 yrs)

12-18 years

Crisil - Associate Director - Information Security/Governance/Risk & Compliance (12-18 yrs)

Crisil

posted 9mon ago

Job Description

Associate Director Information Security Governance,Risk & Compliance


- Establishing and maintaining Information security program conforming to ISO/IEC 27001:2015 for uplifting the cyber resilience and incident response for CRISIL in compliance to Information Security and Cybersecurity Policy, Common Security Standards, Technical Security Standards, Industry best practices and CISO Directives.


- Responsible for assisting CISO in reporting to CRISIL Management and IT Risk Committee the critical cyber security threats and vulnerabilities that CRISIL is exposed to, ensuring emerging cyber threats and the bank's preparedness in response to these threats are reported and discussed in the CRISIL IT Risk Committee.


- Be the focal person for CRISIL during various audits, be able to communicate accurately and effectively CRISIL's security posture and regulatory compliance status. Be the point of contact and interact regularly with regulatory agencies and Computer Emergency Response Team (CERT-In).


- Support and manage ISO 27001 and SOC2Type2 external and internal audits.


- Responsible for driving the regulatory compliance for Cyber Security Framework and all current and future advisory notes received from the regulator.


- Being the information security and cyber policy owner, responsible for development of (but not limited to) CRISIL Information Security and Cyber Security Policy, Data Governance and Classification Policy, Access Control Policy, Acceptable use of assets and asset management policy.


- Keep abreast with country specific cyber threats through maintaining close work relationship with regulatory agencies CERT-In, attend RBI's cyber events & trainings


- Establish a Cyber Management Group with representations from CRISIL management and functional heads. Establish and maintain the Cyber Incident Response Plan (CIRT) which defines the roles and responsibilities amongst key functional stakeholders during a cyber incident.


- Planning and executing periodic cyber breach simulation exercises, make sure CRISIL Branch is well prepared for any cyber breach incidents with widespread impacts.


- Responsible for developing CRISIL cybersecurity KRIs and KPIs and presenting the KRIs and KPIs to CRISIL risk committee for independent challenge and management oversight.


- Work with the CISO & CIO to develop a holistic risk management framework for CRISIL.


- Partner with 2nd Line IT and Cyber Risk Management, Country Compliance and Global regulatory compliance activities. Provide subject matter expert advisory on cybersecurity, security technology, best practice and regulatory compliance requirements.


- Manage risk remediation activities for CRISIL, ensuring the remediation works are executed in accordance to the approved timeline and deliverables.


- Manage risks associated with third party suppliers, conduct third party due diligence and ongoing risk management activities in accordance to the bank's Third-Party Risk Management Framework.


- Conduct Information Security awareness training periodically to general staffs and functional leads across the CRISIL.


Education / Experience / Other Information:


- Bachelor degree in Engineering or Graduation in Computer Science degree or equivalent degree


- 12-15 years' experience in information security, cybersecurity, technology risk management in large multinational financial / technology institutions environment


- ISMS ISO 27001 LI/LA and other Security related certifications viz., CISA / CISM (or equivalent) is an advantage.


- Hand-on experience on Process definitions, process drafting, documentation, conducting and managing audits, knowledge of Data privacy laws of various countries


- Excellent verbal and written communication skills.


Roles and Responsibilities:


Accountabilities:


- Establishing and maintaining Information security program conforming to ISO/IEC 27001:2015 for uplifting the cyber resilience and incident response for CRISIL in compliance to Information Security and Cybersecurity Policy, Common Security Standards, Technical Security Standards, Industry best practices and CISO Directives.


- Responsible for assisting CISO in reporting to CRISIL Management and IT Risk Committee the critical cyber security threats and vulnerabilities that CRISIL is exposed to, ensuring emerging cyber threats and the bank's preparedness in response to these threats are reported and discussed in the CRISIL IT Risk Committee.


- Be the focal person for CRISIL during various audits, be able to communicate accurately and effectively CRISIL's security posture and regulatory compliance status. Be the point of contact and interact regularly with regulatory agencies and Computer Emergency Response Team (CERT-In).


- Support and manage ISO 27001 and SOC2Type2 external and internal audits.


- Responsible for driving the regulatory compliance for Cyber Security Framework and all current and future advisory notes received from the regulator.


- Being the information security and cyber policy owner, responsible for development of (but not limited to) CRISIL Information Security and Cyber Security Policy, Data Governance and Classification Policy, Access Control Policy, Acceptable use of assets and asset management policy.


- Keep abreast with country specific cyber threats through maintaining close work relationship with regulatory agencies CERT-In, attend RBI's cyber events & trainings


- Establish a Cyber Management Group with representations from CRISIL management and functional heads. Establish and maintain the Cyber Incident Response Plan (CIRT) which defines the roles and responsibilities amongst key functional stakeholders during a cyber incident.

Planning and executing periodic cyber breach simulation exercises, make sure CRISIL Branch is well prepared for any cyber breach incidents with widespread impacts.


- Responsible for developing CRISIL cybersecurity KRIs and KPIs and presenting the KRIs and KPIs to CRISIL risk committee for independent challenge and management oversight.


- Work with the CISO & CIO to develop a holistic risk management framework for CRISIL.


- Partner with 2nd Line IT and Cyber Risk Management, Country Compliance and Global regulatory compliance activities. Provide subject matter expert advisory on cybersecurity, security technology, best practice and regulatory compliance requirements.


- Manage risk remediation activities for CRISIL, ensuring the remediation works are executed in accordance to the approved timeline and deliverables.


- Manage risks associated with third party suppliers, conduct third party due diligence and ongoing risk management activities in accordance to the bank's Third-Party Risk Management Framework.


- Conduct Information Security awareness training periodically to general staffs and functional leads across the CRISIL.



Educational Qualification - Bachelor degree in Engineering or Graduation in Computer Science degree or any other graduation / post graduation


Educational Qualification - Bachelor degree in Engineering or Graduation in Computer Science degree or any other graduation / post graduation


Functional Areas: Other

Read full job description

Crisil Interview Questions & Tips

Prepare for Crisil roles with real interview advice

People are getting interviews at Crisil through

(based on 128 Crisil interviews)
Job Portal
Campus Placement
Referral
Company Website
Recruitment Consultant
Walkin
35%
22%
13%
12%
3%
2%
13% candidates got the interview through other sources.
High Confidence
?
High Confidence means the data is based on a large number of responses received from the candidates.

What people at Crisil are saying

What Crisil employees are saying about work life

based on 1.5k employees
79%
82%
65%
95%
Flexible timing
Monday to Friday
No travel
Day Shift
View more insights

Crisil Benefits

Work From Home
Cafeteria
Health Insurance
Free Transport
Job Training
Gymnasium +6 more
View more benefits

Compare Crisil with

ICRA

3.2
Compare

India Ratings & Research

3.7
Compare

Brickwork Ratings

3.8
Compare

SMERA Ratings

2.8
Compare

CareEdge Ratings

3.0
Compare

Acuité Ratings & Research

3.7
Compare

Equifax

3.3
Compare

Experian Credit Information Company Of India

3.5
Compare

Credit Information Bureau

3.7
Compare

Bureau of Energy Efficiency

3.9
Compare

Indegene

3.4
Compare

Kantar

3.5
Compare

Acuity Knowledge Partners

3.4
Compare

Mu Sigma

2.7
Compare

Nielsen

3.7
Compare

Serco

4.4
Compare

Netscribes

2.8
Compare

Sutherland Healthcare Solutions

3.9
Compare

Karvy Data Management Services

3.8
Compare

GlobalData

3.5
Compare

Similar Jobs for you

Security at CareerNet Technologies Pvt. Ltd.

10-18 Yrs

₹ 60-75 LPA

Technology at HDFC Credila Financial Services Limited

5-11 Yrs

₹ 30-35 LPA

Senior Lead at Employee Forums

8-12 Yrs

₹ 22-25 LPA

Senior Information Security Manager at Serving Skill

Mumbai

7-12 Yrs

₹ 10-15 LPA

Technology at Serving Skill

10-14 Yrs

₹ 18-20 LPA

Risk Management at Value Vision Management Consultants

Delhi ncr, Mumbai + 3

14-17 Yrs

₹ 35-50 LPA

Internal Audit Lead at Employee Forums

9-15 Yrs

₹ 41-50 LPA

Technology Auditor at Employee Forums

8-10 Yrs

₹ 22-25 LPA

Technology at FRONIX SOLUTIONS PRIVATE LIMITED

10-20 Yrs

₹ 30-50 LPA

IT Manager at Lipton Teas & Infusions.

6-10 Yrs

₹ 25-35 LPA

Crisil Chennai Office Locations

View all
Chennai Office
Thapar House, 43/44, Montieth Road, Egmore, Chennai Chennai
600008
Chennai Office
CRISIL GR&A, TVH -Beliciaa Towers, 3rd Floor, Tower-II, Block No.94, MRC Nagar Chennai
600028

Backend Developer - GenAI Systems

5-7 Yrs

Mumbai, Pune

6hr ago·via naukri.com

Frontend Developer - GenAI Systems

5-7 Yrs

Mumbai, Pune

6hr ago·via naukri.com

UX/UI Designer - GenAI Systems

7-10 Yrs

Mumbai, Pune

6hr ago·via naukri.com

Assistant Manager - Risk

4-7 Yrs

Mumbai, Pune

7hr ago·via naukri.com

Structured Finance Research #2

1-3 Yrs

Chennai

18hr ago·via naukri.com

Equity Research Associate I US Oil & Gas

1-3 Yrs

Mumbai

18hr ago·via naukri.com

Senior Business Development Officer (Third Party Payroll)

1-2 Yrs

Mumbai

18hr ago·via naukri.com

Lead Analyst (Manager)

5-7 Yrs

Mumbai

18hr ago·via naukri.com
write
Share an Interview