Description
Prudential Health India (PHI) is seeking a talented candidate for the role of Lead- Tech Risk. The successful candidate will develop and implement a comprehensive technology Risk strategy and annual Risk plan aligned with PHI's business and regulatory requirements.
Responsibilities:
- Develop and implement a comprehensive technology Risk strategy and annual Risk plan aligned with PHI's business and regulatory requirements.
- Conduct risk-based Risks across infrastructure, applications, data platforms, and security controls.
- Ensure complete and tamper-proof Risk trails of user activities, data changes, and system events.
- Collaborate with InfoSec, DevSecOps, and AppSec teams to validate remediation of vulnerabilities and ensure patch compliance.
- Lead privacy impact assessments, penetration testing reviews, and security onboarding for new applications.
- Monitor and report on the implementation of Risk recommendations and track remediation progress.
- Maintain documentation and Risk logs in accordance with professional standards and Prudential Group policies.
- Support investigations into technology-related incidents, control breaches, or compliance failures.
- Present Risk findings and risk assessments to senior leadership and the Risk Committee.
- Stay updated on emerging risks, regulatory changes, and best practices in technology Risk and governance.
- Develop and maintain risk registers and mitigation plans.
- Monitor emerging risks (cloud, AI, third-party integrations).
- Collaborate with architecture and security teams to embed controls.
- Support risk reporting and governance forums.
- Conduct impact analysis and scenario modelling.
- Align risk controls with Prudential Group standards and regulatory expectations.
- Work with product and engineering teams to ensure risk-aware design and delivery.
- Maintain risk dashboards, metrics, and control effectiveness reports.
Security & Compliance Technologies:
- Implement and Risk SAST, DAST, and SCA scanning tools and processes.
- Ensure secure integration of CI/CD pipelines using Checkmarx, GitHub, GitHub Actions, HashiCorp Vault, and Azure AD.
- Oversee onboarding and compliance of WAF (Web Application Firewall) solutions including Imperva API Security and DDoS/WAAP protection.
- Validate controls for privileged access management using tools like CyberArk.
- Ensure compliance with data classification, encryption standards, and endpoint protection policies.
Requirements:
- Bachelor's in Engineering, Computer Science, or equivalent; certifications in CISA, CISSP, or ISO 27001 are a plus.
- 10–18 years of experience in technology Risk, risk management, or compliance, preferably in insurance or financial services.
- Strong understanding of GCP, CI/CD pipelines, DevSecOps, and infrastructure as code.
- Experience with tools such as Checkmarx, GitHub, Azure AD, HashiCorp Vault, CyberArk, and Imperva.
- Familiarity with SQL and NoSQL databases, encryption standards, and data classification frameworks.
- Proven ability to lead cross-functional Risk engagements and manage stakeholder expectations.
- Familiarity with enterprise risk frameworks (COSO, NIST).
- Experience in risk modelling and impact analysis.
- Exposure to cloud risk, data privacy, and third-party risk domains.
- Understanding of DevSecOps and secure SDLC practices.
- Experience with risk tooling and control libraries.
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://prudential.wd3.myworkdayjobs.com/en-US/prudential/job/Mumbai/PHI---Lead--Tech-Risk_25090112