Skip to main content
N

NPCI International Payments Limited

Senior Leader Information Security

Mumbai, MaharashtraPosted today

Skills

AWSAzureGoogle CloudStakeholder ManagementLeadershipDecision MakingProblem SolvingCybersecurity

Job description

About the role This role is responsible for ascertaining and overseeing the risk and security guidelines and controls applicable to third parties interacting with NPCI. It will ensure ecosystem-wide compliance with evolving security requirements arising from innovations across the organization. The core focus of the role will be to ensure that member banks and TPAPs comply with the standards laid down by NPCI. It will also interface with CERT-In, NCIIPC, NCCC, RBI, MeitY and other government bodies on cybersecurity-related matters. The role will also play a key part in addressing privacy-related aspects, including adherence to the DPDP Act, GDPR and other applicable data protection requirements. What you’ll own Stakeholder Management and Leadership ■Provide direction on regulatory compliance and cybersecurity protection. ■Demonstrate a thorough understanding of international governance and management principles. ■Engage with multiple stakeholders across organizational boundaries. Risk and Control Objectives ■Develop and maintain robust international information security controls. ■Provide an external perspective to strengthen the design and implementation of security controls. ■Lead and review assessments for external agencies and members. Decision-Making and Problem-Solving ■Make decisions regarding the maintenance of the security posture of the organization and its subsidiaries. ■Identify emerging global cyber-threat trends and align organizational strategy to address them. ■Provide solutions to address international challenges related to security architecture. Specialization in Multiple Security Domains ■Act as a subject matter expert (SME) across multiple internal security domains, such as Identity and Access Management (IAM), infrastructure security, application security cloud security, Data Privacy and DPDP Act. ■Engage with development teams to enable DevSecOps. ■Demonstrate SME-level knowledge of key security and data protection standards and frameworks, such as GDPR, CIS, ISO 27001, NIST and PCI DSS. What sets you apart Major Challenges ■Coordinating with external entities and multiple stakeholders on information security-related matters. ■Identifying security gaps and following up to ensure their closure. ■Focusing information security operations on external parties and addressing data protection and privacy-related concerns. Decisions Made by the Job Holder ■Reviewing and verifying controls relating to third-party applications and member banks. ■Certifying third parties associated with NPCI. ■Reviewing information security controls and guidelines followed by TPAPs and member banks. ■Effectively addressing various data-related concerns, as required by the Data Protection Officer (DPO), and ensuring adherence to DPDP and GDPR requirements. ■Conducting various third-party audits to ensure acceptable levels of cyber hygiene. Recommendations to or Approval by Superior ■Exceptions and approvals relating to third-party risks. ■Measures to strengthen ecosystem-wide cyber hygiene. ■Matters relating to data protection and privacy. Requirements Understanding of Cybersecurity maturity frameworks and Information security standards like, but not limited to, ISO 27701, GDPR, PCI DSS, NIST 800-53, CIS 20, ISO 22301. Experience at engaging, influencing, and managing multiple stakeholders across departmental and organizational boundaries up to C-suite. Excellent understanding of legislations and regulations that impact Information security, e.g. GDPR. Develop, implement and administer technical security standards as well as a suite of security practices. Understanding of cloud service deployment and architecture with implementation experience on multiple cloud platforms like AWS, Azure, GCP etc. Good understanding of security technologies and wider payment business solutions like Firewall, IDS/IPS, PIM/PAM, IAM setup, APIs, ISO 8583 etc. Understanding of the emerging threat landscape and technologies, and what measures can be taken to protect the information security posture of the organization.