Business Function
Technology and Operations (T&O) enables and empowers the bank with an efficient, nimble and resilient infrastructure through a strategic focus on productivity, quality & control, technology, people capability and innovation. In Group T&O, we manage the majority of the Bank's operational processes and inspire to delight our business partners through our multiple banking delivery channels.
Job Purpose
The Cybersecurity Regulatory and Compliance Officer is responsible for ensuring the organization’s cybersecurity practices comply with applicable laws, regulations, frameworks, and internal policies. This role bridges the gap between cybersecurity operations and legal / regulatory obligations, ensuring the organization maintains a robust, compliant security posture in a rapidly evolving threat and regulatory landscape.
Key Responsibilities
- Monitor cybersecurity regulations and frameworks (e.g., NIST, ISO 27001, DPDP, PCI-DSS, CIS controls) relevant to the organization’s operations and industry.
- Translate regulatory cybersecurity requirements into actionable internal controls and risk mitigation strategies.
- Collaborate with IT, security, audit, and business teams to develop and enforce cybersecurity policies and procedures.
- Conduct regular assessments, audits, and gap analyses to ensure compliance with cybersecurity standards and best practices.
- Support preparation and response for internal audits, external audits, assessments, and certification efforts (e.g., ISO 27001, PCI-DSS).
- Track regulatory changes and provide timely updates to stakeholders, ensuring policies and controls remain current.
- Manage cybersecurity risk registers and contribute to enterprise risk management initiatives.
- Oversee cybersecurity incident reporting and ensure compliance with breach notification laws.
- Prepare and submit cybersecurity-related regulatory filings, documentation, and reports.
- Deliver internal training and awareness on cybersecurity compliance requirements and secure practices.
Qualifications
Bachelor’s degree in Cybersecurity, Information Technology, or a related field (Master’s preferred).7-10 years of experience in cybersecurity, regulatory compliance, risk management, or related field.Strong understanding of regulations and compliance (e.g., RBI Cybersecurity Framework, SEBI CSCRF, NIST CSF, ISO / IEC 27001, PCI-DSS, etc.).Relevant certifications preferred :Compliance-focused : Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Information Privacy Professional (CIPP).Cybersecurity-focused : Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM).Experience supporting security and compliance audits and working with regulatory bodies or external assessors.Strong analytical, organizational, and communication skills.Preferred Experience
Hands-on experience working in regulated industries (e.g., NBFC and Bank ).Experience in incident response planning and regulatory breach reporting.