Job Description
About Us
SBI Card is a leading pure-play credit card issuer in India, offering a wide range of credit cards to cater to diverse customer needs. We are constantly innovating to meet the evolving financial needs of our customers, empowering them with digital currency for seamless payment experience and indulge in rewarding benefits. At SBI Card, the motto 'Make Life Simple' inspires every initiative, ensuring that customer convenience is at the forefront of all that we do. We are committed to building an environment where people can thrive and create a better future for everyone.
SBI Card is proud to be an equal opportunity & inclusive employer and welcome employees without any discrimination on the grounds of race, colour, gender, religion, creed, disability, sexual orientation, gender identity, marital status, caste etc. SBI Card is committed to fostering an inclusive and diverse workplace where all employees are treated equally with dignity and respect which makes it a promising place to work.
Join us to shape the future of digital payment in India and unlock your full potential.
What’s in it for YOU
- SBI Card truly lives by the work-life balance philosophy. We offer a robust wellness and wellbeing program to support mental and physical health of our employees
- Admirable work deserves to be rewarded. We have a well curated bouquet of rewards and recognition program for the employees
- Dynamic, Inclusive and Diverse team culture
- Gender Neutral Policy
- Inclusive Health Benefits for all - Medical Insurance, Personal Accidental, Group Term Life Insurance and Annual Health Checkup, Dental and OPD benefits
- Commitment to the overall development of an employee through comprehensive learning & development framework
Role Purpose
Responsible for managing all identified/known insider threat vector of information leakage either deliberately or inadvertently with focus on preventing Insider threat in getting exposed. The role is also responsible for leading the complete program to protect SBIC’s critical information from unauthorized exposure.
Role Accountability
- Define and Manage processes around insider threat management
- Manage Insider Threat Monitoring program by ensuring processing security alerts generated by the various monitoring tools and technologies operated by the team in order to identify potential instances of data loss / exfiltration and other activity which may pose a potential Insider Threat risk
- Prepare and operationalize the relevant Alert/ Incident metrics, as part of the overall infosec function
- Manage escalations of security alerts for review by business line management, seek response and validate vis-a-vis SBI card information security policies and allowed security practices
- Manage escalations of security incidents alerts to SBIC Compliance Team and Co-ordinate with them for presentation in the steering committees for formal review and decisioning on the Disciplinary actions
- Provide feedback to the DLP(Data Leak prevention) Team basis review of the Alerts, Incidents identified as per the existing DLP rules
- Review the classification of alerts raised on a periodic basis to decrease false positives
- Lead maintain internal users (FTEs and NFTEs) related security incidents which could indicate a potential Insider Threat risk, and maintain detailed trackers for incidents witnessed and actions taken
- Ensure end to end tracking of Insider threat alerts and incidents, including disciplinary actions taken by responsible business/ Human resource/ legal function
- Provide inputs to the Enterprise risk management committee(ERMC)/Information Security Committee(ISC) as per the prescribed frequency regarding incidents and actions taken on incidents
- Participate in Disaster Recovery Planning, testing, troubleshooting and root cause analysis and documentation of the root causes
- Manage Service Partner operation from technology prospective
- Ensure process documentation and compliance adherence
Measures of Success
- Successful development and monitoring of insider threat program
- Increase in maturity of insider threat Programs (Adoption & Capabilities)
- Timely delivery of project plans, milestone updates, presentations, assessment reports etc. to relevant stakeholders
- Security metrics within acceptable threshold
- Availability of DLP as a service in line with the enterprise expectations
- Resolution of all technical issues reported by users within agreed TAT
- Timely updation of DLP related SOPs and other documents
- No adverse observations in Internal / External Audits
- Process Adherence as per MOU
Technical Skills / Experience / Certifications
- Knowledge and in-depth understanding of Log management and processing
- Experience in Technologies like DLP, CASB, UAM, Data Classification, IRM
- Knowledge of cybersecurity risks and information security standards
- Understanding of security controls from a people, process and technology perspective.
- Knowledge of standard security processes and guidelines.
- Certifications including, Security+, CEH, GCIA, GCIH or similar
- Knowledge of insider and privacy frameworks such as - NIST, DSCI, ISO, PCI, GDPR, etc.
- Prior experience working in a Security Operations Center (SOC)
- Experience in managing data incidents and breaches
Competencies critical to the role
- Detail Orientation
- Teamwork and Collaboration
- Stakeholder Management
- Analytical ability
- Problem Solving
Qualification
Bachelor’s Degree or B.Tech in Computer Science / Information Technology or in a related discipline
Preferred Industry
BFSI / NBFC /E-commerce/IT & ITES / Telecom