Chief Information Security Officer, Sccl

Standard Chartered Mumbai , IN 46615

Posted 1 week ago

Key Responsibilities

Strategy

  • Accountable for the Information and Cyber Security Strategy for SCCL, India

  • Identify and independently drive strategic change initiatives to deliver on the ICS agenda with a forward-looking view.

  • Develop insightful strategies for engaging business on information security matters, ensure investments are prioritised and funding is approved.

  • Support delivery of the Entity's enterprise wide risk management plan and strategy.

  • Work with application development organisations to assist in the development of strategies and plans for improving both Architecture and application security.

  • Provide deep consulting expertise on complex projects, delivering workable and risk/threat-driven solutions

  • Provide thought leadership on emerging technologies and how they can be secured

Business

  • Ensure ICS risks in the Entity are proactively managed and effectively controlled, mitigated and remediated with senior stakeholder's support and buy-in, in line with Group, Region, Country, Business/Function risk appetite and regulatory driven requirements.

  • Be the focal point for ICS for SCCL India. Drive a strong engagement both with the CEO and CIO

  • Educate Senior executives regarding ICS Risks to drive accountability across the market

  • Assist in establishing priorities in partnership with the C-level Management and take responsibility for resolving security issues.

  • Ensure that the management of ICS risk is effective and operating efficiently in the Entity

  • Assist in driving security culture/awareness and help improve readiness for a cyber event.

  • Ensure information risks are identified, assessed, mitigated and controlled.

  • Ensure Critical Information Assets are identified and graded appropriately. Monitor changes in the risk profile of the highly critical systems.

  • Work with IT to validate the resilience of data and IT systems.

  • Support Group initiatives ensuring the respective business / function / region needs are represented effectively.

  • Face off to the ICS subject matter experts in Group Business lines.

  • Address GIA queries related to ICS and address GIA RFIs for ICS strategy, standards, controls and ICS tools

Processes

  • Drive the continuous improvement of practices.

  • Drive the implementation of the ICS agenda for the Entity by working with the respective Business/Function Heads, Management Team, C-level Management /CIO teams, ISOs and senior ICS leadership.

  • Manage ICS risk remediation initiatives and activities including incident responses, crisis exercises, risk assessments, stress testing, regulator engagement.

  • Drive the implementation of the ICS RTF in in the Entity. The plan will incorporate digital footprint discovery, threat/risk assessment, definition and implementation of controls as guided by the ICS RTF.

People and Talent

  • Excellent organisation and leadership skills with ability to manage multiple deadlines and effectively prioritise, including strong collaboration with peers

  • Maintain strong stakeholder engagement and serve as the business-facing lead with Group, Regional and Country IT, Business/Function, C-level Management, ISOs, Risk & Control stakeholders to bring alignment across stakeholder groups in conjunction with ICS risk management.

  • Collaborate with Corporate Communications, threat intelligence and other functions to lead and coordinate the information security change management effort around branding, communications, staff awareness and training.

  • Maintain relationships with key service and product owners within Security Technology Services / Cyber Security Services to keep abreast of changes that may affect ICS's risk landscape.

  • Help to interpret and translate the ICS requirements of the ICS programmes into technical requirements when needed.

  • Engage external agencies / third parties to understand the threat environment and reported events; assess impact for the respective business / function / region.

Risk Management

  • Responsible for monitoring and managing ICS Incidents for SCCL, India

  • Responsible to represent SCCL, India in the Regional and Market Governance Forums and Risk Committees

  • Responsible to remediate Audit/Regulator ICS Issues for SCCL, India

  • Responsible for the SCCL, India ICS Risk Profile in executing the TSRA framework

  • Drive the adoption of "lessons learnt" driving consistency and efficiency.

  • Drive compliance with Group policies standards, and local regulatory requirements.

  • Work closely with CISRO, Regional ISO, Country ISO, Head of ICS Governance, TISO, Business and C-level Management to provide oversight, governance and monitoring, and work with various delivery owners to embed the ICS RTF.

  • Understand and assess the impact of changes in the policy or procedures on the respective business / function / region and engage with the respective business / function / region Heads to ensure the impact is understood.

  • Recommend additions/enhancements/changes to the ICS policy, procedures, and RTF.

Risk Management

Governance

  • Monitor ICS risk profile and posture and report any non-compliance to senior management or governance committees.

  • Participate and represent the Entity in Risk Committees, ICS working groups, Programme Steer Cos etc. to provide updates and influence positive outcomes for the Business/Function/Region/Country.

  • Validate the accuracy and consistency of KRIs, KCIs and other risk ratings/assessments, as well as process designs using available MI.

  • Support the Third-Party Security Assessment team during 3rd party reviews.

  • Help design and embed ICS RTF controls in ORF across the Entity

  • Ensure key ICS risk and issues are monitored and appropriately addressed by key stakeholders

  • Ensure adoption of the ICS controls within SCCL, India

  • Ensure ICS Controls are being adopted in new technologies and projects

Regulatory & Business Conduct

  • Display exemplary conduct and live by the Group's Values, Valued Behaviours, and Code of Conduct

  • Take personal responsibility for embedding the highest standards of ethics, including regulatory and business conduct, across the Bank.

  • Effectively and collaboratively identify, escalate, mitigate, and resolve risk, conduct and compliance matters.

Key stakeholders

  • CISO, WRB and Markets

  • Region CISO

  • Market C-level Management and CIO

  • ICS Control owners

Skills and Experience

  • Understanding of the Cyber landscape and ICS Controls

  • Excellent organisation and leadership skills with ability to manage multiple deadlines and effectively prioritise

  • Proven ability to lead highly complex, global, pan-bank, multi-year programmes by driving collaboration and participation by functions, Regions and countries.

  • Extensive change and programme management experience, ideally gained in the financial industry

  • Ability to foster positive relationships with internal and external stakeholders at appropriate level ensuring open co-operative environment. Be a Team player.

Qualifications

Education

  • Degree in Engineering, Computer Science/Information Technology or its equivalent.

Training

  • Strong knowledge of ICS products and operations will be preferred.

  • Ability to articulate gross and residual risk with specific ability to communicate complex technology and process risk clearly, concisely and accurately to non-technical stakeholders in a lucid way.

  • Strong interpersonal and stakeholder management skills, across various levels in the organization including senior leadership teams, in influencing key decisions taken in the business and in support teams.

  • Strong communication skills - oral, written and presentation. Sound knowledge of MS-Excel, PPT, and Word.

  • Must be a self-starter who is able to initiate and successfully drive programs and projects to completion with little or no management supervision.

  • Strong analytical skills and ability to prioritise, make decisions, and work to tight timeframes.

  • Strong business acumen and deep knowledge and experience in the ICS field.

  • Proven ability to lead highly complex, global activities through influence and credibility rather than command and control.

  • Ability to both assess strategic priorities and to focus on detailed aspects of a function in order to drive effective delivery.

  • Strong integrity, independence, and resilience.

Certifications

  • One or more of the following certifications will be preferred:

  • Certified Information Security Manager (CISM)

  • Certified Information Systems Security Professional (CISSP)

  • SANS Global Information Assurance Certifications (GIAC)

  • Certified in Risk & Information Systems Control (CRISC)

  • Certified Information Systems Auditor (CISA)

  • Languages - English

About Standard Chartered

We're an international bank, nimble enough to act, big enough for impact. For more than 170 years, we've worked to make a positive difference for our clients, communities, and each other. We question the status quo, love a challenge and enjoy finding new opportunities to grow and do better than before. If you're looking for a career with purpose and you want to work for a bank making a difference, we want to hear from you. You can count on us to celebrate your unique talents and we can't wait to see the talents you can bring us.

Our purpose, to drive commerce and prosperity through our unique diversity, together with our brand promise, to be here for good are achieved by how we each live our valued behaviours. When you work with us, you'll see how we value difference and advocate inclusion.

Together we:

  • Do the right thing and are assertive, challenge one another, and live with integrity, while putting the client at the heart of what we do

  • Never settle, continuously striving to improve and innovate, keeping things simple and learning from doing well, and not so well

  • Are better together, we can be ourselves, be inclusive, see more good in others, and work collectively to build for the long term

What we offer

In line with our Fair Pay Charter, we offer a competitive salary and benefits to support your mental, physical, financial and social wellbeing.

  • Core bank funding for retirement savings, medical and life insurance, with flexible and voluntary benefits available in some locations.

  • Time-off including annual leave, parental/maternity (20 weeks), sabbatical (12 months maximum) and volunteering leave (3 days), along with minimum global standards for annual and public holiday, which is combined to 30 days minimum.

  • Flexible working options based around home and office locations, with flexible working patterns.

  • Proactive wellbeing support through Unmind, a market-leading digital wellbeing platform, development courses for resilience and other human skills, global Employee Assistance Programme, sick leave, mental health first-aiders and all sorts of self-help toolkits

  • A continuous learning culture to support your growth, with opportunities to reskill and upskill and access to physical, virtual and digital learning.

  • Being part of an inclusive and values driven organisation, one that embraces and celebrates our unique diversity, across our teams, business functions and geographies - everyone feels respected and can realise their full potential.

icon no score

See how you match
to the job

Find your dream job anywhere
with the LiveCareer app.
Mobile App Icon
Download the
LiveCareer app and find
your dream job anywhere
App Store Icon Google Play Icon
lc_ad

Boost your job search productivity with our
free Chrome Extension!

lc_apply_tool GET EXTENSION

Similar Jobs

Want to see jobs matched to your resume? Upload One Now! Remove

Chief Information Security Officer, Sccl

Standard Chartered