About Us
JOB DESCRIPTION
SBI Card is a leading pure-play credit card issuer in India, offering a wide range of credit cards to cater to diverse customer needs. We are constantly innovating to meet the evolving financial needs of our customers, empowering them with digital currency for seamless payment experience and indulge in rewarding benefits. At SBI Card, the motto 'Make Life Simple' inspires every initiative, ensuring that customer convenience is at the forefront of all that we do. We are committed to building an environment where people can thrive and create a better future for everyone.
SBI Card is proud to be an equal opportunity & inclusive employer and welcome employees without any discrimination on the grounds of race, colour, gender, religion, creed, disability, sexual orientation, gender identity, marital status, caste etc. SBI Card is committed to fostering an inclusive and diverse workplace where all employees are treated equally with dignity and respect which makes it a promising place to work.
Join us to shape the future of digital payment in India and unlock your full potential.
What's In It For YOU
- SBI Card truly lives by the work-life balance philosophy. We offer a robust wellness and wellbeing program to support mental and physical health of our employees
- Admirable work deserves to be rewarded! We have a well curated bouquet of rewards and recognition program for the employees
- Dynamic, Inclusive and Diverse team culture
- Gender Neutral Policy
- Inclusive Health Benefits for all - Medical Insurance, Personal Accidental, Group Term Life Insurance and Annual Health Checkup, Dental and OPD benefits
- Commitment to overall development of an employee through comprehensive learning & development framework
Role Purpose
Responsible for planning and coordinating with IT and business functions on security architecture & design principle to supports the maintenance of information security, ensuring the integrity, availability & confidentiality of SBI Card internal and customer's information hosted in cloud.
The role is also responsible for assuring that all technology solutions and services being delivered are compliant with our ISMS and that all exceptions and risks are documented and managed.
Role Accountability
Cloud Security Architecture
Lead the design and development of Azure and AWS security architectures for protecting PII / PCI data deployed into different types of cloud and cloud / hybrid systemsLead the security vision and strategy around cloud-based applications, across all types (including Infrastructure, Platform, and Software as a Service (IaaS / PaaS / SaaS)Serve as the central point of contact for Enterprise Security for other Technology teams within the organization for all matters related to cloud securityDesign and develop security architectures for cloud and cloud / hybrid based systems. Possess a firm understanding of the offerings within Amazon Web Services (AWS) and the Microsoft Azure platformsDesign and implement cloud-native architectures and designs that will allow those requirements to be met with a minimal degree of risk to Organization and with appropriate security controls presentRepresent Security Platform in development and implementation of the overall enterprise cloud architectureAct as the ambassador and senior technical representative for Enterprise Security while engaging with other senior technical leaders throughout organization in design and implementation of cloud and cloud / hybrid based implementations and solutionsWorks with IT Infrastructure Services, and Application Development organizations to choose appropriate technology solutions and facilitates complete integration into the company environmentsDevelop standards in partnership with Engineering, Infrastructure Services, and Application Development.Lead initiatives designed to share knowledge across Security Platforms and / or Technology teams, identify, recommend, coordinate and deliver timely knowledge to support teams regarding technologies, processes or toolsOversees the development and maintenance of the information security strategy and develop and execute strategies to increase Cloud Security knowledge throughout the enterpriseEnsures the effective translation of the security architecture is implemented into the solutionsAssist to evaluate all the new initiatives / solutions (including Cloud) with the design recommendations and work with project managers and architects during implementationNew Technology & Risks
Evaluate and recommend tools and solutions to enhance the security posture of the EnterpriseMaintain contact with vendors regarding security system updates and technical support of security productsPerform cost-benefit and risk analysis- Analyzes business impact and exposure, based on emerging security threats, vulnerabilities and risksProject Management
Lead project implementation for Information risk management projectsEnsure integration of security requirements in project design, timely and high quality delivery of projectsPartner with SecOps to develops operational run book to ensure smooth transition post implementationLiaison with IT teams and other biz functions to ensure security is engaged in all projectsEnsure process documentation and compliance adherenceMeasures of Success
Successful implementation / adoption of any new solution, technology or frameworkTimely and in- budget delivery of security projects specifications within time and budgetTimely delivery of Cloud Security Architecture covering all types (including Infrastructure, Platform, and Software as a Service (IaaS / PaaS / SaaS)Process Adherence as per MOUTechnical Skills / Experience / Certifications
Knowledge of enterprise IT Systems, infrastructure and security technologiesKnowledge of Information Security Standards like ISO 27001, PCI-DSS, NIST CSF, CSA framework etc.Working knowledge of common and industry standard cloud-native / cloud-friendly authentication mechanisms (OAuth, OpenID, etc.)Experience with deployment orchestration, automation, and security configuration management (Jenkins, Puppet, Chef, etc.) preferredExperience architecting solutions within Amazon Web Services (AWS), Azure, Google Cloud Platform (GCP), VMware NSX, Oracle etc.Experience with assessment, development, implementation, optimization, and documentation of a comprehensive and broad set of security technologies and processes such as secure software development, Application Security, data protection, cryptography, key management, identity and access management (IAM), network security) within SaaS, IaaS, PaaS, and other cloud environmentsExperience working with cloud security and governance tools, cloud access security brokers (CASBs), and server virtualization technologiesExperience with enterprise applications (architecture, development, support, and troubleshooting)Experience performing threat modeling and design reviews to assess security implications and requirements for introduction of new technologiesWorking knowledge of compliance frameworks and security management standards (e.g., ISO 27001, NIST CSF, CIS etc.)Experience with enterprise architecture and working as part of a cross-functional team to implement solutionsIndustry standard certifications such as CISSP, CISM, CCSP, CEH, CHFI, Cloud security, ISO27001, SABSA, TOGAF, AWS, Azure etc.Competencies critical to the role
Stakeholder ManagementTeamwork & CollaborationResult OrientationProblem SolvingQualification
Graduate in IT / Computer Science or equivalent
Preferred Industry
BFSI / NBFC / E-commerce / IT & ITES / Telecom
Skills Required
Security Architecture, Network Security, Enterprise Architecture, threat modeling , Azure, Aws