About this role
Job Summary:
- Experienced Security Architect role focused on strengthening the Banks and vendors security architecture, regulatory compliance, and ATM logical security.
- Responsible for assessing and improving security posture across systems, data, applications, and networks in line with industry standards, regulations, and best practices.
Key Responsibilities:
Security Architecture Design:
- Design and implement robust security architecture for cloud, on-premises, and hybrid environments.
- Conduct internal architecture reviews to validate design adequacy, security controls, and alignment with Bank standards before implementation, followed by annual or half-yearly reviews based on criticality.
- Develop and enforce security policies, standards, and procedures across systems and applications.
- Define security requirements, understand data flows, and partner with teams to enable secure design and integration.
Risk Management & Compliance:
- Conduct risk assessments and recommend mitigation strategies.
- Ensure compliance with relevant regulatory frameworks, including ISO 27001, NIST, and PCI-DSS.
- Support audits and regulatory responses across DPSC, RBI Cybersecurity Framework, SEBI CSCRF, IT outsourcing, and digital lending requirements.
ATM Logical Security:
- Ensure ATM logical controls are aligned with Bank standards.
- Conduct periodic ATM security assessments covering vulnerabilities, host security, and control effectiveness.
- Perform governance reviews of ATM logical security controls.
Collaboration & Guidance:
- Act as a security advisor to business, IT, vendors, partners, and application teams.
- Lead threat modeling and security reviews for new systems, projects, and services.
Regulatory Reporting:
- Ensure timely and accurate submission of regulatory returns and reports, including Quarterly Cyber KRI and Tranche I, II, and III submissions.
- Maintain records of regulatory submissions, approvals, and RBI correspondence.
Training & Awareness:
- Conduct training and awareness on RBI regulations and compliance practices.
- Promote regulatory compliance and ethical conduct across the organization.
Monitoring & Response:
- Partner with Security Operations to enhance monitoring and incident response capabilities.
- Support security breach investigations and root cause analysis.
Security Tools & Technologies:
- Manage security solutions such as SIEM, EDR, WAF, and IAM.
- Track emerging cybersecurity trends, technologies, and threat landscapes.
Requirements:
- Bachelors degree in computer science, Cybersecurity, Information Technology, or a related field; Masters preferred.
- 10+ years of cybersecurity experience, including 5+ years in security architecture or engineering.
- Preferred certifications: CISSP, CISM, CISA, AWS/Azure/GCP Security Specialty, or equivalent.
Skills & Competencies:
- Strong understanding of security principles, architecture, and technologies.
- Strong knowledge of cloud platforms, including AWS, Azure, and GCP, and cloud security frameworks.
- Familiarity with microservices and container security, including Docker and Kubernetes.
- Proven ability to conduct security assessments and interpret security reports.
Strong analytical, problem-solving, and communication skills, with the ability to engage internal and external stakeholders effectively.
Location:
I-Think Techno, Kanjurmarg
Job:
Technology
Schedule:
Regular
Employee Status:
Full time