Manager - Security Architecture Governance

Mumbai, Maharashtra8-12 yrsPermanentOn-siteINR 28 - 30 LPA

Hiring for: One of India’s leading non-banking financial companies (NBFCs), focused on driving financial inclusion across rural and semi-urban markets.

Role: Manager - Security Architecture Governance

Experience: 8 to 12 years

Location(s): Kurla, Mumbai

Salary: Up to INR 30 LPA (Including 10% variable)



Role Purpose

The Security Architecture Governance Lead will provide governance, coordination, assurance, and execution support across Information & Cyber Security initiatives to ensure that identified security gaps, remediation actions, compliance requirements, and security controls are effectively implemented, sustained, and closed within agreed timelines. The role will work closely with Application, IT Infrastructure, Information Security, Technology Operations, Risk, Compliance, and other stakeholders to drive timely remediation, resolve operational challenges, monitor control effectiveness, and provide management visibility on the overall security posture.

This is an additional bandwidth role intended to strengthen the existing security governance function through structured tracking, cross-functional coordination, control assurance, configuration governance, and sustained compliance monitoring.


Key Responsibilities

1. Security Remediation Governance & Closure

• Maintain and govern the central tracker for security vulnerabilities, audit observations, compliance gaps, security findings, and other remediation actions.

• Track remediation progress against agreed timelines, owners, priorities, risk ratings, and dependencies.

• Coordinate with Application, IT, Infrastructure, and Information Security teams to drive timely remediation and closure.

• Follow up on overdue and high-risk remediation items and escalate delays, dependencies, and risks through the appropriate governance forums.

• Review closure evidence and ensure remediation actions are formally closed only when adequate evidence is available.

• Provide periodic dashboards covering open risks, ageing, overdue actions, closure trends, and key dependencies.


2. Cross-Functional Security Coordination

• Act as a coordination point between Information Security and technology/business teams for security remediation and control-related activities.

• Engage with application, infrastructure, network, endpoint, cloud, IAM, SOC, and other technology teams to facilitate resolution of security issues.

• Guide stakeholders on expected security requirements and practical closure approaches based on approved policies, standards, and controls.

• Identify operational, technical, or resource dependencies affecting remediation and facilitate resolution with relevant stakeholders.


3. Continuous Compliance & Security Assurance

• Perform continuous monitoring of security and compliance activities against approved policies, standards, regulatory

requirements, and internal control requirements.

• Track compliance observations and ensure timely remediation and closure.

• Support periodic control assessments and evidence collection in coordination with control owners.

• Monitor whether implemented security controls continue to operate effectively after implementation.

• Identify control degradation, recurring gaps, exceptions, and non-compliance and coordinate corrective actions.


4. Security Configuration & Control Governance

• Prepare, maintain, update, and periodically review security configuration documents, hardening standards, baseline

configurations, and operational security procedures.

• Coordinate with technology and security teams to keep configuration standards aligned with approved security

policies, regulatory requirements, industry practices, and organizational risk appetite.

• Review the effectiveness of security configurations and controls implemented across enterprise security technologies.

• Conduct periodic governance reviews of security control configurations and policies for Firewall, NAC, Cloud Security,

Secure Web Gateway/Proxy, Microsoft 365, Email Security, MDM/Endpoint Management, IAM, EDR, DLP, and

SIEM/SOC-related controls.

• Identify configuration gaps, deviations, control weaknesses, and improvement opportunities and coordinate

remediation with respective control owners.

• Review periodic security tool configuration reports and ensure identified gaps are tracked through to closure.

• Ensure security configuration documents and control requirements are updated following material technology,

process, or security requirement changes.


5. Sustained Control Effectiveness & Operational Support

• Establish governance mechanisms to ensure security controls remain effective beyond initial implementation.

• Track recurring security issues and identify trends indicating weaknesses in existing controls or processes.

• Coordinate corrective and preventive actions with control owners where weaknesses are identified.

• Support periodic reviews of control performance, exceptions, and remediation status.

• Support Information Security and technology teams in resolving day-to-day security governance and operational

challenges.

• Facilitate discussions where security requirements create implementation or operational challenges and help identify

practical, risk-based solutions.

• Support exception management, risk acceptance tracking, and follow-up actions where applicable.



Required Experience & Competencies

• 8–12 years of experience in Information Security, Cyber Security, Security Governance, Security Assurance, Technology

Risk, or a related domain.

MMFSL | Security Architecture Governance Lead | L5M

• Strong experience in security governance, remediation tracking, compliance monitoring, control assurance, and

stakeholder management.

• Good understanding of enterprise security controls across network/infrastructure, application, IAM, cloud, endpoint,

email, proxy, data security, and security operations.

• Experience managing remediation programs involving multiple technology and business stakeholders.

• Strong understanding of risk-based remediation and security control effectiveness.

• Ability to understand technical security issues and translate them into actionable remediation requirements.

• Strong communication, coordination, follow-up, escalation, documentation, and stakeholder-management skills.

• Ability to manage multiple parallel initiatives independently and provide clear management-level reporting.

Preferred Certifications

• CISSP /CISM/ CRISC/ CEH / CCSP or relevant cloud/security certifications


Skills

CEHCertified Cloud Security Professional (CCSP)CISMCISSPCompliance MonitoringControl AssuranceCRISCCyber SecurityEnterprise Security ControlsInformation SecurityRemediation TrackingSecurity AssuranceSecurity GovernanceTechnology Risk

Posted September 29, 2026