Information Systems Security Manager

IDFC FIRST Bank · Navi Mumbai

  • Experience5–6 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Levelsenior
  • Posted17 Sept 2026

About IDFC FIRST Bank

IDFC FIRST Bank is hiring in Navi Mumbai in financial services. This role looks for around 5+ years of experience.

Skills

  • cybersecurity infrastructure
  • device control
  • encryption tools
  • access management systems
  • security audits
  • risk assessments
  • incident investigations
  • business continuity
  • disaster recovery
  • threat detection
  • cybersecurity governance

The role

A security engineer at a financial services company manages cybersecurity infrastructure and access management, conducts risk assessments, and leads incident investigations and business continuity planning. The role applies encryption tools and threat detection to strengthen organizational security.

Full job description

Job Requirements

About the Role

The Information Systems Security Manager will be responsible for managing a comprehensive portfolio of cybersecurity services and implementing strategic initiatives to strengthen the organization’s cyber defence. Based in Mumbai, the role involves overseeing security infrastructure, conducting risk assessments, and ensuring compliance with cybersecurity policies. The role holder will play a key part in minimizing cyber risks through effective governance, process optimization, and team leadership.

Key Responsibilities

Primary Responsibilities

Supervise the device control server infrastructure, ensuring high availability, policy enforcement, patching, reporting, and logging.Install, configure, and upgrade security software such as antivirus programs.Conduct regular security audits and risk assessments to identify vulnerabilities and recommend mitigation strategies.Manage and govern in-house tools for access and inventory management.Oversee the governance of device control and encryption tools, including related products and processes.Administer security controls to manage access to the bank’s application systems.Translate cybersecurity insights into actionable risk mitigation plans to protect business operations.Ensure all service requests and changes comply with SLAs, approved procedures, and the security matrix.Implement business continuity plans to maintain uninterrupted service during security breaches or disaster recovery events.Lead investigations following security incidents, including impact analysis and recommendations to prevent recurrence.Ensure cybersecurity policies and procedures are effectively communicated and enforced across the organization.Continuously monitor for cyber threats, attacks, and intrusions.Present regular reports to the executive team on cybersecurity status, risks, and mitigation strategies.Capture and share best practices within the cybersecurity team.

Secondary Responsibilities

Collaborate with cybersecurity experts and industry representatives to stay updated on emerging threats, technologies, and prevention techniques.Foster a collaborative learning environment that promotes shared responsibility and continuous improvement.Build, groom, and retain a high-performing cybersecurity talent pool to drive process efficiency.Attract and retain top-tier talent for key roles within the reporting structure.

What We Are Looking For

Education

Graduation: Full time BE, B. Tech in any discipline from a recognised institution.Post-graduation: ME, M. Tech in any discipline from a recognised institution.

Experience

Minimum of 5 years of relevant experience in cybersecurity, IT risk management, or related fields within BFSI, IT/ITES industry.

Skills and Attributes

Strong technical expertise in cybersecurity infrastructure, tools, and processes.Experience in managing device control, encryption tools, and access management systems.Proficiency in conducting audits, risk assessments, and incident investigations.Ability to implement and manage business continuity and disaster recovery plans.Strong leadership and team development skills.Excellent communication and reporting abilities, especially with senior stakeholders.Commitment to fostering a culture of security awareness and compliance.Strategic thinking with a proactive approach to threat detection and mitigation.