Talent.com
IT Risk Officer
IT Risk OfficerIHX - A Perfios Company • Greater Bengaluru Area, India
IT Risk Officer

IT Risk Officer

IHX - A Perfios Company • Greater Bengaluru Area, India
6 hours ago
Job description

The IT Risk Officer owns day-to-day information-security, privacy, and IT-risk governance for IHX. Acting as the single point of contact between local teams and the Perfios central security office, the role ensures that technology risks are identified, assessed, mitigated, and reported in line with ISO 27001 : 2022 , the Digital Personal Data Protection (DPDP) Act , and Perfios Group policies.

Key Responsibilities

Risk Governance & GRC

Maintain and periodically review the IT / InfoSec risk register with the IT Head and Perfios security lead.

Align the subsidiary’s Statement of Applicability (SoA) with the Perfios ISO 27001 scope and manage related evidence collection.

Policy & Compliance

Localize Perfios security, privacy, and AI policies for complete compliance across teams.

Monitor adherence to the DPDP Act, client contractual obligations, and emerging regulatory requirements.

Security Operations Oversight

Oversee the health and performance of security solutions including CrowdStrike, Netskope, JumpCloud, and SOC integrations.

Triage high-severity alerts and coordinate incident response activities including root-cause analysis.

System Troubleshooting & Correlation

Troubleshoot and correlate system-level issues across Linux / Windows environments with cybersecurity alerts.

Analyze security events across multiple systems and platforms.

Threat & Vulnerability Management

Schedule vulnerability assessments, penetration tests, configuration audits, and GuardDuty reviews.

Track remediation SLAs and provide monthly status updates.

Third-Party Risk Management (TPISA)

Perform risk-based assessments of third-party service providers.

Follow up on identified remediations and verify compliance with contract clauses.

Incident Response & Forensics

Participate in incident response activities including log analysis, forensic triage, containment, and remediation.

Collaborate with forensic specialists to validate findings and assist in root-cause analysis.

Business Continuity & Disaster Recovery

Support disaster-recovery drills for client deployments and verify RTO / RPO compliance.

Update and maintain DR documentation and runbooks.

Awareness & Training

Conduct phishing simulations, awareness programs, and secure-coding refreshers.

Track awareness performance metrics and implement improvements.

Reporting & Metrics

Prepare monthly KPI / KRI dashboards covering risk posture, incidents, and roadmap progress for leadership review.

Required Qualifications & Experience

Mandatory

  • Education : Bachelor’s degree in IT, Computer Science, Information Security, or a related field.
  • Experience : 5–6 years in InfoSec, IT Risk, or Security Operations with hands-on exposure to SIEM / EDR and audits.
  • Certifications : CISSP, CISM, ISO 27001 Lead Auditor, or equivalent.
  • Technical Skills : Vulnerability management, endpoint security, cloud security (AWS / Azure / GCP), IAM (JumpCloud / AD), EDR / AV, IDS / IPS, encryption, DLP, SIEM / SOC operations, DDoS protection, patch management.
  • Frameworks : ISO 27001, NIST CSF, DPDP Act, OWASP.

Preferred

  • Education : Post-graduate in Cybersecurity or MBA (Tech Management).
  • Experience : Familiarity with BFSI or FinTech domains.
  • Certifications : CRISC, CCSP, CCSK.
  • Technical : DevSecOps tooling, IaC security frameworks.
  • Frameworks : RBI / SEBI guidelines, SOC 2.
  • Core Competencies

  • Risk-based decision-making.
  • Strong communication skills (technical and executive).
  • Analytical problem-solving and root-cause analysis.
  • Ownership and execution discipline.
  • Continuous learning mindset.
  • Create a job alert for this search

    Officer • Greater Bengaluru Area, India

    Related jobs
    Manager - IT Risk

    Manager - IT Risk

    Grant Thornton INDUS • Bengaluru, Karnataka, India
    The Controls Advisory delivers all project and engagement management phases for multiple clients in various industries.Responsibilities include executing business processes, IT control reviews, and...Show more
    Last updated: 19 days ago • Promoted
    IT Governance Risk and Compliance- AVP

    IT Governance Risk and Compliance- AVP

    MUFG Global Service (MGS) • Bengaluru, India
    Japans premier bank, with a global network spanning in more than 40 markets.Outside of Japan, the bank offers an extensive scope of commercial and investment banking products and services to busine...Show more
    Last updated: 30+ days ago • Promoted
    CSC Global - IT Audit & Risk Manager - Cyber Security Domain

    CSC Global - IT Audit & Risk Manager - Cyber Security Domain

    CSC Global • Bangalore
    Description : Role : IT Audit & Risk Manager Exp range : 12+ years Work L...Show more
    Last updated: 27 days ago • Promoted
    Risk and Compliance Officer

    Risk and Compliance Officer

    Confidential • Bengaluru / Bangalore, India
    We are a fast-growing digital marketplace, connecting users with top brands for gifting, rewards, and loyalty.As we scale, ensuring platform integrity, regulatory compliance, and fraud resilience i...Show more
    Last updated: 24 days ago • Promoted
    Manager of Technology

    Manager of Technology

    Confidential • Bengaluru / Bangalore, India
    The Cyber Security IT Audit and Risk Manager is an essential role to assist our business with making risk informed decisions. The position is responsible for supporting the security direction of the...Show more
    Last updated: 30+ days ago • Promoted
    Tech Risk

    Tech Risk

    Confidential • Bengaluru / Bangalore, India
    PAYU PAYMENTS PRIVATE LIMITED Job Title : • Tech Risk Analyst - Group CISO Organization.This role demands proficiency in risk management, cybersecurity technologies, and innovative problem-solving a...Show more
    Last updated: 24 days ago • Promoted
    IT Advisory Risk Consultant

    IT Advisory Risk Consultant

    Randstad India • Bengaluru, Karnataka, India
    Information Security Governance Privacy and Compliance and Security Assessment.IT and IS Risk Assessments and program reviews / establishment. ISO 27001 / NIST 800-53 / PCI-DSS.Interacting with onshor...Show more
    Last updated: 2 days ago • Promoted
    IT Risk and Security Consultant

    IT Risk and Security Consultant

    Confidential • Bengaluru / Bangalore, India
    IT Security, Risk and Governance practices.Evidence of influencing senior stakeholders and dealing with external auditors and regulators. Excellent interpersonal skills and good oral and written com...Show more
    Last updated: 14 days ago • Promoted
    IT Audit and Risk Management Lead

    IT Audit and Risk Management Lead

    CSC • Bengaluru, Republic Of India, IN
    The IT Audit and Risk Manager is an essential role to assist our business with making risk informed decisions.The position is responsible for supporting the security direction of the business and e...Show more
    Last updated: 1 hour ago • Promoted • New!
    Technology Risk and Audit Director

    Technology Risk and Audit Director

    CSC • Bengaluru, Republic Of India, IN
    The IT Audit and Risk Manager is an essential role to assist our business with making risk informed decisions.The position is responsible for supporting the security direction of the business and e...Show more
    Last updated: 1 hour ago • Promoted • New!
    Cybersecurity Governance & Compliance Lead

    Cybersecurity Governance & Compliance Lead

    IHX - A Perfios Company • Bengaluru, Republic Of India, IN
    Acting as the single point of contact between local teams and the Perfios central security office, the role ensures that technology risks are identified, assessed, mitigated, and reported in line w...Show more
    Last updated: 1 hour ago • Promoted • New!
    Manager - IT Risk

    Manager - IT Risk

    Confidential • Bengaluru / Bangalore, India
    The Controls Advisory delivers all project and engagement management phases for multiple clients in various industries.Responsibilities include executing business processes, IT control reviews, and...Show more
    Last updated: 13 days ago • Promoted
    IT Controls, Risk & Compliance

    IT Controls, Risk & Compliance

    VDart Software Services Pvt. Ltd. • Bengaluru, KA, India
    Quick Apply
    Provide end-to-end support for control operations, including monitoring activities, identifying risks, and driving corrective actions. Work with platforms like ServiceNow, Archer GRC< / b&...Show more
    Last updated: 5 days ago
    Manager - It Risk

    Manager - It Risk

    Grant Thornton INDUS • Bengaluru, Republic Of India, IN
    The Controls Advisory delivers all project and engagement management phases for multiple clients in various industries.Responsibilities include executing business processes, IT control reviews, and...Show more
    Last updated: 20 days ago • Promoted
    Lead IT Risk Analyst

    Lead IT Risk Analyst

    7-Eleven Global Solution Center – India • Bangalore Urban, Karnataka, India
    Why Join 7-Eleven Global Solution Center?.When you join us, you'll embrace ownership as teams within specific product areas take responsibility for end-to-end solution delivery, supporting local te...Show more
    Last updated: 2 days ago • Promoted
    Information Security & IT Risk Manager

    Information Security & IT Risk Manager

    IHX - A Perfios Company • Bengaluru, Republic Of India, IN
    Acting as the single point of contact between local teams and the Perfios central security office, the role ensures that technology risks are identified, assessed, mitigated, and reported in line w...Show more
    Last updated: 1 hour ago • Promoted • New!
    Manager IT Risk

    Manager IT Risk

    Confidential • Bengaluru / Bangalore
    Manage a portfolio of engagements, leading a team of Assistant Managers, Senior Associates, and Associates / Analysts.Execute business processes, IT control reviews, and activities related to Sarbane...Show more
    Last updated: 19 days ago • Promoted
    IT Advisory, Rick Consulting- TPRM(Third Party Risk Management )

    IT Advisory, Rick Consulting- TPRM(Third Party Risk Management )

    Randstad India • Bengaluru, Karnataka, India
    Information Security Governance Privacy and Compliance and Security Assessment.IT and IS Risk Assessments and program reviews / establishment. ISO 27001 / NIST 800-53 / PCI-DSS.Interacting with onshor...Show more
    Last updated: 30+ days ago • Promoted