Information Systems Security Manager
IDFC FIRST Bank · Navi Mumbai
- Experience5–6 yrs
- SalaryNot disclosed
- Work modeonsite
- Levelsenior
- Posted17 Sept 2026
About IDFC FIRST Bank
IDFC FIRST Bank is hiring in Navi Mumbai in financial services. This role looks for around 5+ years of experience.
Skills
- cybersecurity infrastructure
- device control
- encryption tools
- access management systems
- security audits
- risk assessments
- incident investigations
- business continuity
- disaster recovery
- threat detection
- cybersecurity governance
The role
A security engineer at a financial services company manages cybersecurity infrastructure and access management, conducts risk assessments, and leads incident investigations and business continuity planning. The role applies encryption tools and threat detection to strengthen organizational security.
Full job description
Job Requirements
About the Role
The Information Systems Security Manager will be responsible for managing a comprehensive portfolio of cybersecurity services and implementing strategic initiatives to strengthen the organization’s cyber defence. Based in Mumbai, the role involves overseeing security infrastructure, conducting risk assessments, and ensuring compliance with cybersecurity policies. The role holder will play a key part in minimizing cyber risks through effective governance, process optimization, and team leadership.
Key Responsibilities
Primary Responsibilities
Supervise the device control server infrastructure, ensuring high availability, policy enforcement, patching, reporting, and logging.Install, configure, and upgrade security software such as antivirus programs.Conduct regular security audits and risk assessments to identify vulnerabilities and recommend mitigation strategies.Manage and govern in-house tools for access and inventory management.Oversee the governance of device control and encryption tools, including related products and processes.Administer security controls to manage access to the bank’s application systems.Translate cybersecurity insights into actionable risk mitigation plans to protect business operations.Ensure all service requests and changes comply with SLAs, approved procedures, and the security matrix.Implement business continuity plans to maintain uninterrupted service during security breaches or disaster recovery events.Lead investigations following security incidents, including impact analysis and recommendations to prevent recurrence.Ensure cybersecurity policies and procedures are effectively communicated and enforced across the organization.Continuously monitor for cyber threats, attacks, and intrusions.Present regular reports to the executive team on cybersecurity status, risks, and mitigation strategies.Capture and share best practices within the cybersecurity team.
Secondary Responsibilities
Collaborate with cybersecurity experts and industry representatives to stay updated on emerging threats, technologies, and prevention techniques.Foster a collaborative learning environment that promotes shared responsibility and continuous improvement.Build, groom, and retain a high-performing cybersecurity talent pool to drive process efficiency.Attract and retain top-tier talent for key roles within the reporting structure.
What We Are Looking For
Education
Graduation: Full time BE, B. Tech in any discipline from a recognised institution.Post-graduation: ME, M. Tech in any discipline from a recognised institution.
Experience
Minimum of 5 years of relevant experience in cybersecurity, IT risk management, or related fields within BFSI, IT/ITES industry.
Skills and Attributes
Strong technical expertise in cybersecurity infrastructure, tools, and processes.Experience in managing device control, encryption tools, and access management systems.Proficiency in conducting audits, risk assessments, and incident investigations.Ability to implement and manage business continuity and disaster recovery plans.Strong leadership and team development skills.Excellent communication and reporting abilities, especially with senior stakeholders.Commitment to fostering a culture of security awareness and compliance.Strategic thinking with a proactive approach to threat detection and mitigation.