Talent.com
Prudential plc
PHI - Lead- Tech RiskPrudential plc • Mumbai
PHI - Lead- Tech Risk

PHI - Lead- Tech Risk

Prudential plc • Mumbai
30+ days ago
Job description

Prudential’s purpose is to be partners for every life and protectors for every future. Our purpose encourages everything we do by creating a culture in which diversity is celebrated and inclusion assured, for our people, customers, and partners. We provide a platform for our people to do their best work and make an impact to the business, and we support our people’s career ambitions. We pledge to make Prudential a place where you can Connect, Grow, and Succeed.

About the Job

Prudential’s purpose is to be partners for every life and protectors for every future. Our purpose encourages everything we do by creating a culture in which diversity is celebrated and inclusion assured—for our people, customers, and partners. We provide a platform for our people to do their best work and make an impact to the business, and we support our people’s career ambitions. We pledge to make Prudential a place where you can Connect, Grow, and Succeed.

At Prudential Health India (PHI), we are on a mission to make Indians healthier, while bridging the health protection gap. This is a Zero-to-One team undertaking a greenfield health insurance deployment in India committed to building journeys that truly empathise with the customer and offer a differentiated, bespoke experience.

To partner us in this mission, we are looking for a talented candidate for the role of…

Tech Risk Lead

Note: The title will depend on (1) Experience (2) Expertise and (3) Performance. So the title could be:

  • Tech Risk Lead
  • Senior Tech Risk Lead
  • (Associate Director) Technology Risk

People Manager Role

Experience: 10–18 years
Location: Mumbai
Work Mode: Work from office only

Job Profile Summary

The Tech Risk Lead will be responsible for establishing and leading the technology Risk function at PHI, ensuring compliance with internal policies, regulatory frameworks (IRDAI, GDPR, HIPAA), and global Prudential standards. This role will oversee Risk trails, vulnerability management, and risk mitigation across PHI’s cloud-native infrastructure and applications.

Job Description

  • Develop and implement a comprehensive technology Risk strategy and annual Risk plan aligned with PHI’s business and regulatory requirements.
  • Conduct risk-based Risks across infrastructure, applications, data platforms, and security controls.
  • Ensure complete and tamper-proof Risk trails of user activities, data changes, and system events.
  • Collaborate with InfoSec, DevSecOps, and AppSec teams to validate remediation of vulnerabilities and ensure patch compliance.
  • Lead privacy impact assessments, penetration testing reviews, and security onboarding for new applications.
  • Monitor and report on the implementation of Risk recommendations and track remediation progress.
  • Maintain documentation and Risk logs in accordance with professional standards and Prudential Group policies.
  • Support investigations into technology-related incidents, control breaches, or compliance failures.
  • Present Risk findings and risk assessments to senior leadership and the Risk Committee.
  • Stay updated on emerging risks, regulatory changes, and best practices in technology Risk and governance.
  • Develop and maintain risk registers and mitigation plans.
  • Monitor emerging risks (cloud, AI, third-party integrations).
  • Collaborate with architecture and security teams to embed controls.
  • Support risk reporting and governance forums.
  • Conduct impact analysis and scenario modelling.
  • Align risk controls with Prudential Group standards and regulatory expectations.
  • Work with product and engineering teams to ensure risk-aware design and delivery.
  • Maintain risk dashboards, metrics, and control effectiveness reports.

Security & Compliance Technologies

  • Implement and Risk SAST, DAST, and SCA scanning tools and processes.
  • Ensure secure integration of CI/CD pipelines using Checkmarx, GitHub, GitHub Actions, HashiCorp Vault, and Azure AD.
  • Oversee onboarding and compliance of WAF (Web Application Firewall) solutions including Imperva API Security and DDoS/WAAP protection.
  • Validate controls for privileged access management using tools like CyberArk.
  • Ensure compliance with data classification, encryption standards, and endpoint protection policies.

Who We Are Looking For

Technical Skills & Work Experience

  • Bachelor's in Engineering, Computer Science, or equivalent; certifications in CISA, CISSP, or ISO 27001 are a plus.
  • 10–18 years of experience in technology Risk, risk management, or compliance, preferably in insurance or financial services.
  • Strong understanding of GCP, CI/CD pipelines, DevSecOps, and infrastructure as code.
  • Experience with tools such as Checkmarx, GitHub, Azure AD, HashiCorp Vault, CyberArk, and Imperva.
  • Familiarity with SQL and NoSQL databases, encryption standards, and data classification frameworks.
  • Proven ability to lead cross-functional Risk engagements and manage stakeholder expectations.
  • Familiarity with enterprise risk frameworks (COSO, NIST).
  • Experience in risk modelling and impact analysis.
  • Exposure to cloud risk, data privacy, and third-party risk domains.
  • Understanding of DevSecOps and secure SDLC practices.
  • Experience with risk tooling and control libraries.

Personal Traits

  • Strategic thinker with strong analytical and investigative skills.
  • High integrity and ethical standards.
  • Excellent communication and presentation skills.
  • Ability to work independently and manage multiple concurrent Risks.
  • Strong attention to detail and documentation discipline.

What Can Make You Extra Special

  • Experience in setting up Risk functions in greenfield environments.
  • Exposure to IRDAI Risks and regulatory inspections.
  • Familiarity with centralised vulnerability dashboards and build breaker enforcement.
  • Experience with public-facing application security, DDoS/WAAP onboarding, and penetration testing workflows.

Language

Fluent written and spoken English

Equal Opportunity Statement

Create a job alert for this search

PHI - Lead- Tech Risk • Mumbai

Similar jobs

Credit Risk Analytics & Product Management

EliteRecruitmentsMumbai, Maharashtra, India

Job Summary: We are seeking an experienced and analytically driven professional to head the credit product and policy design, launch and management of our embedded finance portfolio as the Director... Show more

 • Promoted

Specialist - Catastrophe Risk Management

Guy CarpenterMumbai, Maharashtra, India

Are you excited by challenges and someone who seeks to find solution? We are looking for a talented and dynamic individual to join our Catastrophe Modelling team at Guy Carpenter.This is a hybrid r... Show more

 • Promoted

Lead Auditor - ISMS

Vitasta Consulting Pvt LtdMumbai, MH, Maharashtra, IN

Job Title - Lead Auditor (ISMS ISO 27001)<br /> BU / Department - Business Assurance - Management Systems<br /> Directly Reports to Branch Manager</strong></p> <p><... Show more

Manager- ERM

Vitasta Consulting Pvt LtdMumbai, MH, Maharashtra, IN

Key Responsibilities:<br /> <br /> - Implementation of ERM Framework, Risk Registers, KRIs, Risk Appetite Statements, and Incident Tracking<br /> - ESG Framework implementation an... Show more

Project Management - CCR/Market Risk

KPMG IndiaMumbai, Maharashtra, India

About the Company KPMG entities in India are professional services firm(s).Member firms are affiliated with KPMG International Limited.KPMG was established in India in August 1993.Our professionals... Show more

 • Promoted

Structured Trade Review- Senior Risk Analyst

Riverforest Connections Private LimitedMumbai, MH, Maharashtra, India

Times New Roman,Times,serif;"><strong>Job Description : </strong></span></span></p> <p><span style="font-size:12px;"><span style=... Show more