Kotak Mahindra Bank Logo

Kotak Mahindra Bank

Information Security II-SUPPORT SERVICES-IT Security

Posted 6 Hours Ago
Be an Early Applicant
In-Office
2 Locations
Senior level
In-Office
2 Locations
Senior level
Owns audit, compliance, and cybersecurity governance for Network and Security Operations. Responsibilities include coordinating internal, external, and regulatory audits; closing audit and security assessment findings; ensuring PCI DSS and regulatory compliance; maintaining SOPs and technology inventories; tracking patch, vulnerability, change, and exception management; and reporting compliance dashboards to senior management.
The summary above was generated by AI

Job Title: Senior Manager / Associate Vice President - Network & Security Operations Compliance

Job Purpose:

Oversee the Audit and Compliance activities for the Network & Security Operations within the Information Technology division of the Bank. This role requires effective collaboration with Internal Auditors, External Auditors, Regulatory Auditors, the Information Security Team, the IT Compliance Team, IT - PMO team and the Project and Support teams of the Network & Security Operations function

Location: Mumbai

Years of experience: 6 to 10 Years

Job Description:

Single Point of Contact (SPOC) for Audit & Compliance activities of the Network & Security Operations Function.

Collaborate with the Project & Support team of the Network & Security Operations function to:

Ensure timely submission of data requirements for various internal, external, and regulatory audits.

Lead discussions with auditors during process and technology walkthroughs.

Review auditee responses for non-conformities raised in various audits.

Maintain up-to-date records of non-conformities raised in audits.

Document the progress of closing non-conformities identified in audits.

Review auditee responses and artefacts for compliance with non-conformities raised in audits.

Ensure timely submission of auditee responses and artefacts to relevant stakeholders.

Maintain up-to-date records of non-conformities, compliance submissions, and supporting artefacts for easy reference.

Provide information to senior management as needed.

Collaborate with the Information Security Team, IT Compliance, and Project/Support Team of the Network & Security Operations function to:

Ensure timely closure of non-conformities raised in Security Assessment activities such as VAPT, Application Security Testing, and Red Team Assessment.

Ensure compliance with PCI DSS requirements.

Ensure timely submission of compliance to regulatory requirements such as Master Directions, Circulars, Advisories, Alerts, and Ad hoc Questionnaires.

Ensure timely submission of regulatory requirements such as Cybersecurity KRIs, OKRs, and RBS Tranche.

Maintain Standard Operating Procedures (SOPs) and ensure their timely update.

Maintain an up-to-date inventory of Applications, Servers, Security, and Network Devices for the function.

Track compliance across various domains, including Inventory Management, Patch Management, Vulnerability Management, Change Management, and Exception Management.

Publish compliance dashboards to senior management on a periodic basis.

Eligibility :

Minimum 7 years of experience as a Cyber Security practitioner with relevant knowledge in Governance, Risk, and Compliance (GRC).

Experience in Information Security domains such as Network Security Management, Perimeter Security Management, Identity & Access Management, Cyber Risk Management, Data Loss Prevention, and Infrastructure Security.

Hands-on experience in managing Cybersecurity solutions, particularly in one or more of the following: Firewalls, Web Application Firewalls (WAFs), Remote Access VPNs, Micro-segmentation, Privileged Access Management, 2FA solutions, Data Loss Prevention, and File Integrity Monitoring.

Experience in assessing and/or implementing security and risk standards, including ISO 27001, NIST CSF, PCI DSS v3.2.1/4.0, and RBI Cybersecurity Framework.

Well-versed in cybersecurity auditing methodologies.

MBA/Graduate with B.E/B.Tech degree or Post Graduate with M.S/M.Tech/M.E.

Preferred cybersecurity certifications: CISA, CISM, CCNA, CCNP, Microsoft Technologies, etc.

Strong team player with excellent presentation, communication, and management skills.

Uphold high standards of ethical behaviour and professionalism.


Similar Jobs

6 Hours Ago
In-Office
2 Locations
Senior level
Senior level
Insurance • Payments • Financial Services
Owns audit, regulatory, and cybersecurity compliance for network and security operations. Responsibilities include coordinating audits, closing non-conformities, maintaining compliance records and SOPs, tracking vulnerability, patch, inventory, change, and exception management, ensuring PCI DSS and regulatory compliance, and reporting dashboards to senior management.
Top Skills: Application Security TestingData Loss Prevention (Dlp)File Integrity Monitoring (Fim)FirewallsIso 27001Micro-SegmentationNist CsfPci DssPrivileged Access Management (Pam)Rbi Cybersecurity FrameworkRed Team AssessmentRemote Access VpnsTwo-Factor Authentication (2Fa)VaptWeb Application Firewalls (Waf)
14 Minutes Ago
Remote or Hybrid
India
Senior level
Senior level
Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Build and scale enterprise applications across C#/.NET backends and React/TypeScript frontends. Design APIs, data access layers, application architecture, and cloud deployments in Azure. Use AI coding tools and help implement AI-enabled product features. Mentor developers, conduct code reviews, improve testing and CI/CD, troubleshoot production issues, and optimize performance and reliability while collaborating with product stakeholders in Agile/Scrum teams.
Top Skills: .NetApplication InsightsAsp.Net CoreAzureAzure AiAzure App ServiceAzure SqlC#Ci/CdDapperEntity FrameworkGitGithub CopilotOpenai ApisReactRedisSQL ServerTypescript
14 Minutes Ago
Remote or Hybrid
India
Senior level
Senior level
Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Oversee private equity fund accounting, NAV calculations, capital accounts, waterfalls, carried interest, fees, expenses, transactions, valuations, and financial reporting. Review statements and investor packages, manage audits, ensure LPA and accounting-standard compliance, coordinate with auditors and tax advisors, and lead a fund accounting team. Drive controls, process standardization, automation, and system enhancements while supporting clients, GPs, and internal stakeholders.
Top Skills: GenevaIfrsInvestranLux GaapExcelUs Gaap

What you need to know about the Mumbai Tech Scene

From haggling for the best price at Chor Bazaar to the bustle of Crawford Market, the energy of Mumbai's traditional markets is a key part of the city's charm. And while these markets will always have their place, the city also boasts a thriving e-commerce scene, ranking among the largest in the region. Driven by online sales in everything from snacks to licensed sports merchandise to children's apparel, the local industry is worth billions, with companies actively recruiting to meet the demands of continued growth.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account