Website:
bimasugam.co.in
Job details:
Title Cyber Security Specialist - GRC Position
Objectives:
This role shall support the organization’s Cyber Security, privacy and data governance objectives by ensuring availability of policies, procedures and standards, effective implementation of security controls, compliance to regulatory requirements and protection of sensitive business, customer, employee, partner, and regulatory data across its lifecycle. The role will function as a cross-functional bridge between Information Security, Technology, Business Operations, Legal & Compliance, HR, and Risk functions to strengthen the organization’s overall Information Security posture. The role is expected to combine operational execution, governance support, risk measuring capabilities and an audit ready mindset to proactively identify, assess, mitigate, monitor and report risks related to data exposure, unauthorized access, leakage, misuse, over-retention, insecure integrations, and non compliance with security governance, audit and regulatory requirements.
Indicative Responsibilities
Data Security Governance
• Support implementation and operationalization of enterprise data protection and privacy controls.
• Assist in maintaining data protection governance frameworks, procedures, standards, and operating guidelines.
• Coordinate with business and technology teams to ensure sensitive data is identified, classified, labelled, retained, archived, and disposed appropriately.
• Participate in reviews of data flows across applications, cloud environments, APIs, third party integrations, and internal systems.
• Support implementation and operational management of data lifecycle protection controls.
• Support in developing and updating cyber security policies and standards.
• Review implementation of AI / ML frameworks to ensure compliance across business and support functions.
• Measure data security KRIs and KPIs Data Security Monitoring & Risk Identification
• Monitor data protection risks across systems, endpoints, cloud platforms, email environments, collaboration tools, and third party integrations.
• Review alerts and incidents related to:
o Data Leakage / DLP events
o DSPM events o Unauthorized data access
o Excessive data sharing
o Misconfigured storage repositories
o Insecure APIs or integrations
o Sensitive data exposure
o Unusual download or extraction activities
• Perform trend analysis and identify recurring control weaknesses.
• Support investigations involving data breach of customer, employee data or confidential organizational information.
• Assist in root cause analysis and corrective action tracking for data-related incidents.
Privacy & Regulatory Support
• Support compliance activities aligned with applicable privacy and cybersecurity regulations, contractual obligations, and internal governance requirements.
• Assist in privacy impact assessments, vendor assessments, and data handling reviews.
• Coordinate with Legal, Compliance, HR, and Security teams for privacy-related operational activities.
• Support review of consent handling, data sharing practices, retention controls, and secure disposal requirements.
• Assist in maintaining records related to data processing, third party data access, and regulatory evidence.
Technology & Security Collaboration
• Work closely with Security Operations, Infrastructure, Cloud, Application, and Engineering teams to strengthen data protection controls.
• Assist in implementation, tuning, validation, and effectiveness review of:
o DLP controls
o Data discovery solutions
o RBAC and ABAC controls
o Email security controls
o Endpoint protection controls
o CASB / SaaS security controls
o Encryption mechanisms
o Access controls
o Logging and monitoring use cases
• Participate in secure design and architecture discussions from a data protection perspective.
• Review new system implementations and integrations for potential data protection risks.
Reports To Lead - InfoSec
GRC Coverage / Sub functions
• Data Protection and Privacy
• Cyber Security
• Data Risk and Governance
• Incident Management
• Audits and Regulatory Compliance
Key Skills & Competencies:
Technical & Functional Skills
• Understanding of AWS cloud environment and data security controls.
• Understanding data protection, information security, and privacy principles.
• Knowledge of data lifecycle management concepts and data handling controls.
• Familiarity with:
o DLP technologies
o SIEM/SOC operations
o Cloud security concepts
o Access management
o Endpoint security
o Email security
o Encryption concepts
o SaaS security
• Understanding of data classification and sensitive data identification mechanisms. •
Ability to review logs, alerts, incidents, and identify suspicious data-related activities.
• Basic understanding of privacy regulations and regulatory expectations related to personal data protection. •
Familiarity with security and governance frameworks such as:
o ISO/IEC 27001
o NIST CSF
o CIS Controls
o Privacy and data protection practices
• Experience coordinating with technology, business, compliance, and external stakeholders.
• Strong documentation and reporting skills.
Analytical & Investigative Capabilities
• Ability to correlate security observations and identify underlying data risks.
• Investigative mindset with strong attention to detail.
• Ability to identify anomalies, misuse patterns, and control gaps.
• Ability to conduct structured analysis and support root cause investigations.
• Strong risk-based thinking and prioritization capability.
Qualifications
• 5+ years of experience in one or more of the following: Information and Cyber Security, Data Protection, Privacy Implementation, Security Monitoring and Incident Management, Governance, Risk & Compliance, Cloud Security, Data Governance, etc.
• Bachelor’s degree in Information Security, Computer Science, Information Technology, Cyber Security, Data Governance, or related discipline.
• Master’s degree or specialization in cybersecurity, privacy, or data governance is desirable.
• Experience in regulated industries such as Financial Services, Insurance, BFSI, Healthcare, or Technology platforms shall be preferred.
Location Mumbai (work from office)
About Bima Sugam:
Pursuant to the “Insurance Regulatory and Development Authority of India (Bima Sugam - Insurance Electronic Marketplace) Regulations, 2024” dated 20 March 2024, Bima Sugam India Federation (BSIF) has been established as a “not for profit company” formed under section 8 of the Companies Act, 2013. The main objective of the Company is to establish, facilitate, develop, operate and maintain the “Insurance Electronic Marketplace” as a robust Digital Public Infrastructure with open standards and interoperable platforms, enabling seamless integration with various services to facilitate inter purchase, sale, servicing of insurance policies, settlement of insurance claims, grievance redressal and other related matters as permitted under the objects of the company. The platform is aimed at digitizing insurance in India and potentially becoming the first of its kind globally. This is an insurance industry led initiative and the shareholding of the Company shall be widely held amongst Life Insurers, General Insurers and Health Insurers with no single entity having controlling stake. BSIF is committed to building a “people-first” workplace, focussed on organization’s performance & on people outcomes. We are in the process of building our founding team, a team bound by a sense of mission and inspired by BSIF’s social objective. We seek to attract the best talent from various industry domains (including but not limited to Insurance & Financial Services, Tech Led New Age Economy Companies, FMCG companies etc.) to live their potential as well as to contribute to a noble cause.
Click on Apply to know more.