Team Member - Information Security Assurance - Mumbai

Mumbai, Maharashtra4-6 yrsPermanentOn-siteINR 12 - 15 LPA

Hiring for: One of India’s leading non-banking financial companies (NBFCs), focused on driving financial inclusion across rural and semi-urban markets.

Role: Team Member - Information Security Assurance - Bangalore

Experience: 4 to 6 years

Location(s): Kurla, Mumbai

Salary: Up to INR 15 LPA (Including 5% variable pay)


Job Description


Role Purpose

The IS Assurance Manager will support the IS Assurance Lead in managing day-to-day IS Assurance activities, ensuring effective execution, tracking, monitoring and reporting of security assurance, compliance, risk and governance activities. The role will coordinate with IT, IS, business and third-party stakeholders, maintain assurance evidence and trackers, identify gaps, follow up on remediation and support the IS Assurance Lead in sustaining security controls, compliance and risk posture.


Security KRI & Risk Monitoring

• Track and monitor Security IT & IS KRIs, including performance against defined thresholds and timelines.

• Prepare periodic KRI dashboards, management reports and highlight deviations to the IS Assurance Lead.

• Support tracking of the Top 10 Cyber Risks, including remediation status, closure evidence and sustenance monitoring.

• Coordinate with stakeholders for timely closure of identified risks and observations.


Integrated Security Assurance & Compliance

• Support integrated compliance correlation across Penetration Testing, Red Teaming, Risk Acceptance, VABA (Vulnerability Assessment & Baseline Assessment) and TPISA (Third Party Information Security Assessment).

• Maintain consolidated trackers and ensure observations are mapped to appropriate risks, controls and remediation activities.

• Follow up on outstanding observations and ensure appropriate evidence is available for closure and assurance reporting.


Vendor Governance & TPISA

• Support vendor governance, SLA and contract monitoring from an information security assurance perspective.

• Coordinate TPISA assessments for material and critical vendors.

• Track assessment findings, remediation commitments, exceptions and closure evidence.

Maintain appropriate records and management reporting for third-party security assurance activities.


IS Policies, Standards & Procedures

• Support IS restructuring and maintenance of Policies, Standards and Procedures.

• Coordinate periodic review and updates based on business, technology, regulatory and security requirements.

• Conduct/support control testing to validate continued adherence to approved policies, standards and procedures.

• Identify deviations and coordinate remediation with relevant stakeholders.


IS & IT Assurance Assessments

• Conduct periodic assessments of IS and IT functions to validate adherence to approved policies and procedures.

• Identify risks, control gaps and process deviations in BAU activities.

• Document observations, obtain management responses and track corrective actions.

• Support periodic assurance reporting to the IS Assurance Lead.


Sampling & Sustenance Testing

• Conduct regular sampling tests to validate continued adherence to previously identified observations and remediation commitments.

• Verify sustainability of implemented controls and identify instances of control regression.

• Maintain evidence and testing records for management and audit requirements.


Security Culture & Role-Based Awareness

• Support execution of the security culture and role-based security awareness program.

• Coordinate awareness activities, participation tracking and effectiveness monitoring.

• Support identification of awareness gaps based on security incidents, assessments and assurance observations.


Cyber Crisis Management Readiness

• Support CCMP (Cyber Crisis Management Plan) tabletop exercises covering multiple cyber-crisis scenarios.

• Coordinate exercise logistics, participant engagement, documentation and action tracking.

• Track identified improvement areas and support closure of post-exercise actions.

• Support ongoing assessment of cyber crisis readiness.


SOAR-Based Governance Automation

• Support implementation and adoption of SOAR-based governance automation for applicable assurance and compliance processes.

• Identify opportunities for automation of repetitive tracking, evidence collection, workflow and reporting activities.

• Monitor automated workflows and coordinate resolution of process exceptions.


NIST Implementation & Maturity Sustainment

• Support ongoing NIST framework implementation and maturity sustainment activities.

• Track control maturity, identified gaps and improvement initiatives.

• Maintain evidence and reporting required to demonstrate continued maturity and adherence.


Security Tool User Access Reviews (UAM & RBAC)

• Coordinate periodic User Access Reviews for security tools.

• Validate user access against defined roles and business requirements.

• Track inappropriate, excessive or obsolete access for remediation.

• Maintain review evidence and closure records.


Required Skills & Competencies

• Strong understanding of Information Security Governance and Assurance.

• Experience in security control assessment, compliance monitoring and risk tracking.

• Understanding of VAPT, Red Teaming, vulnerability management and risk acceptance processes.

• Understanding of third-party information security assessments and vendor governance.

• Experience in policy, standard and procedure management.

• Knowledge of security control testing and evidence-based assurance.

• Understanding of NIST Cybersecurity Framework and security maturity concepts.

• Experience in security awareness and cyber crisis/tabletop exercise coordination.

• Strong analytical, documentation, stakeholder-management and reporting skills.

• Ability to manage multiple assurance activities and drive closure through cross-functional coordination.

• Good understanding of security governance automation/SOAR concepts would be advantageous.


Experience & Qualification

• Qualification: Graduate/Postgraduate in Information Technology, Computer Science, Cyber Security or related discipline.

• Relevant professional certifications such as CISA, CISM, CRISC, ISO 27001, CISSP or equivalent would be preferred.

• Experience: Typically 8–12 years of relevant experience in Information Security, Security Assurance, IT Risk, GRC, Cyber Security Governance or related areas.

Skills

Information Security AssuranceInformation Security GovernanceIT Vulnerability ManagementRed TeamingRisk AcceptanceSecurity Control AssessmentThird-Party Security AssessmentsVAPTVendor GovernanceVulnerability Management

Posted September 29, 2026