Navi is looking for an Associate Manager II - Information Security to lead key aspects of its group-wide cybersecurity and regulatory compliance program. This role involves interpreting and implementing cybersecurity mandates from regulators such as RBI, IRDAI, SEBI, and NPCI, ensuring continuous compliance across all business units.
You will collaborate closely with engineering, infrastructure, legal, and IT teams to establish and maintain robust security policies, frameworks, and controls. Additionally, the role includes conducting risk assessments, enabling audit readiness, managing third-party / vendor security, and driving awareness initiatives across the organization, while also representing Navi in internal and external forums when needed.
Responsibilities :
- Compliance and Risk Management : Interpret and implement regulations related to cybersecurity issued by RBI, IRDAI, SEBI, NPCI, and others. Ensure ongoing monitoring and compliance with regulatory expectations. Conduct and review Technology Risk Assessments, and recommend mitigation strategies.
- Maintain audit readiness with appropriate documentation and evidence. Represent Navi in Board meetings and regulatory discussions, if needed.
- Security Governance : Define and implement information security policies, frameworks, standards, and controls. Architect and assess solutions for regulatory cybersecurity compliance. Review controls at data centers, for cloud security, and during IT BCP / DR drills.
- Review and conduct : Third Party Risk & Vendor Assessments pre-onboarding. Monitor and analyze cyber / information security incidents and drive timely resolution.
- Operations and Enablement : Conduct security awareness programs and train teams on data security and privacy. Identify and define. Security KPIs, publish weekly / monthly dashboards. Project manage Information Security initiatives with measurable outcomes.
Requirements :
5+ years of experience in Information Security or Compliance roles.Prior experience in Fintech / Startup environments.Familiarity with regulatory compliance frameworks like PCI DSS, RBI Master Directions, IRDA, SEBI, andNPCI guidelines.
Experience with frameworks such as ISO27001 PCI DSS, etc.Working knowledge of cloud environments like AWS, GCP.Exposure to Agile methodologies, DevOps, and Cloud-native tech.Hands-on problem-solver for complex security issues.Strong ability to multitask, prioritize, and meet deadlines in a fast-paced environment.Ability to balance risk, impact, business priorities, and timelines.Excellent communication skills (verbal and written).Bachelor's degree or diploma in Computer Science, Information Technology, or Information Security.Relevant certifications like ISO 27001 Lead Auditor / Implementer, CISA, CISM, CISSP, etc.(ref : hirist.tech)