AVP - DATA PRIVACY AND BUSINESS INFORMATION SECURITY - LEADING MNC - CISSP, CISA, CRISC, CISM
- Full-time
Company Description
- A leading financial company
Job Description
AVP - DATA PRIVACY AND BUSINESS INFORMATION SECURITY - LEADING MNC - 8-12 YRS - MUMBAI
B.E./ B.Tech./ MCA in IT or CS.
ROLE:
- Understand the key assets and processes, identify and evaluate risks and controls, and suggest incremental controls or risk mitigation strategies
- Responsible for complex privacy and/or security matters and privacy programs in compliance ISO 27001, #GDPR and other global privacy laws and regulations (with additional consideration for sector-specific experience in financial services, insurance, education, telecom, biometrics, or digital advertising
- Drive data breach preparation, risk mitigation, coordination and responses
- Drive Technology transactions related to privacy and security-related due diligence and advising.
- Ensure business compliance with Information Security Policies and Standards while continuously monitoring and reporting on risks and documented exceptions
- Develop and maintain in depth understanding of region/business unit processes, systems, technologies, data, customers, consumers, partners
- Review and audit the Information Security Policies and Standards and technical implementations of security solutions required to meet business objectives
- Identify noncompliance and areas of potential improvement, and issue corrective actions
- Provide escalation path for security issues, incidents and inquiries
- Review work of the Security Incident Response and Crisis Management teams to ensure effectively driving incidents to acceptable resolution; assist with investigations as needed
- Work with the Compliance and Information Risk Management team to drive policy and regulatory compliance.
EXPERIENCE:
- Certification pertaining to information security and data privacy protection (#CISSP, #CISA, #CRISC, #CISM, etc.)
- Experience in the design and implementation of information security programs
- Experience in compliance, government or financial industry.
- Expert level understanding of key network and technical security controls
- Security best practices including experience with #ISO27001 and PCI DSS
Qualifications
Certifications: CISA/ CISSP/ COBIT/ ITILv3/ CISM/ CRISC/ ISO27001