跳到內容

General Information

參考#
1234567890100117248
國家
印度
地區
Maharashtra
城市
Mumbai
Contract type
永久
Professional Family
F06 - INFORMATION TECHNOLOGY

描述

Job Title: Cybersecurity Expert / Control enforcement (CISO A3I Team)

Department: ITG CDF

About Business line/Function: CDF – CISO BUREAU is a unit which making sure that CISO key objectives are in line with Group strategy.

Position Purpose: A position is open for a Cybersecurity Expert / Control enforcement role within the CISO AI & Data team, supporting the “AI & IT Innovation” department (A3I). 

The role focuses on ensuring the effective implementation of the Group Cybersecurity Program across the A3I application landscape, with a strong emphasis on control execution, evidence collection, and operational follow-up with Application Owners. 

The Cybersecurity Expert acts as a key interface between Cyber governance and delivery teams, ensuring that security requirements are properly implemented, documented, and auditable.

Responsibilities

Direct Responsibilities

·         Cyber Program Implementation Oversight: Ensure the proper deployment of the Cybersecurity Program requirements across A3I applications and monitor the execution of security controls (policies, standards, guardrails). Identify implementation gaps and drive remediation actions with relevant stakeholders.

·         Evidence Collection & Control validation: Engage directly with Application Owners and project teams to collect security evidence supporting control implementation. Verify consistency, completeness, and quality of evidence (risk assessments, security documentation, controls, tests), and maintain a structured repository and traceability of evidences.

·         Interaction with Application Owners: Act as a trusted cybersecurity counterpart for Application Owners. Support them in understanding requirements, implementing controls and closing gaps; while ensuring they fulfill their accountability regarding risk documentation, security deliverables, and remediation plans.

·         Risk & Compliance Monitoring: Track the status of security controls, risk assessments, and remediation plans. Contribute to maintaining a consolidated view of cyber risk exposure, support the preparation of dashboards, KPIs, and reporting for CISO governance, and contribute to internal control, audit readiness, and regulatory compliance.

 

Contributing Responsibilities

 

·         Contribute to the industrialization and standardization of cybersecurity practices across the A3I perimeter.

·         Support the CISO in preparing governance committees and structuring control frameworks.

·         Promote a “security by design and by evidence” culture within the department.

·         Ensure all required artifacts are fully available for audit and internal control purposes.

Technical Competencies

·         Functional Skills

o    Strong experience in cybersecurity governance, IT risk management, or control frameworks.

o    Strong capability to handle audit expectations, internal control reviews, and regulatory compliance requirements.

o    Proven ability to track control compliance, risk status, and manage remediation plans effectively.

·         Technical Skills

o    Good understanding of security and cloud environments.

o    Good understanding of risk assessment methodologies (e.g., NIST, ISO 27001, EBIOS RM).

o    Experience in control validation, verifying consistency, completeness, and quality of security evidence and artifacts.

o    Ability to implement and support the preparation of operational dashboards, KPIs, and risk exposure reporting.

o    Experience maintaining structured data repositories and establishing clear traceability for security documentation. 

·         Behavioral Skills

o    Strong communication and influencing skills, especially when engaging and challenging Application Owners or project Teams.

o    High rigor, strict attention to detail and a deep focus on accuracy (quality of evidence).

o    Ability to drive topics independently within a complex, fast-moving environment (AI / innovation).

o    Structured, highly organized, and delivery-oriented mindset with high autonomy.

 

Specific Qualifications:

·         Methodologies & Frameworks: NIST Cybersecurity Framework, ISO 27001, and EBIOS RM.

·         Key Focus Areas: Control Execution, Evidence Collection, Audit Readiness, and Stakeholder Management.

·         CISA/CISSP/CISM/CRISC

 

 

 

Skills Referential (Required knowledge, skills and abilities)

Transversal Skills:

·         Analytical Ability

·         Ability to manage a project

·         Ability to understand, explain and support change

Behavioral Skills: 

·         Communication skills - oral & written

·         Attention to detail / rigor

·         Ability to deliver / Results driven

·         Creativity & Innovation / Problem solving

Education Level: Bachelor’s Degree or Equivalent with at least 8 years of Experience.

Location: Mumbai

 

About BNP Paribas Group:

BNP Paribas is the European Union’s leading bank and key player in international banking. It operates in 65 countries and has nearly 185,000 employees, including more than 145,000 in Europe. The Group has key positions in its three main fields of activity: Commercial, Personal Banking & Services for the Group’s commercial & personal banking and several specialized businesses including BNP Paribas Personal Finance and Arval; Investment & Protection Services for savings, investment, and protection solutions; and Corporate & Institutional Banking, focused on corporate and institutional clients. Based on its strong diversified and integrated model, the Group helps all its clients (individuals, community associations, entrepreneurs, SMEs, corporates and institutional clients) to realize their projects through solutions spanning financing, investment, savings and protection insurance. In Europe, BNP Paribas has four domestic markets: Belgium, France, Italy, and Luxembourg. The Group is rolling out its integrated commercial & personal banking model across several Mediterranean countries, Turkey, and Eastern Europe. As a key player in international banking, the Group has leading platforms and business lines in Europe, a strong presence in the Americas as well as a solid and fast-growing business in Asia-Pacific. BNP Paribas has implemented a Corporate Social Responsibility approach in all its activities, enabling it to contribute to the construction of a sustainable future, while ensuring the Group's performance and stability.

 

About BNP Paribas India Solutions:

Established in 2005, BNP Paribas India Solutions is a wholly owned subsidiary of BNP Paribas SA, European Union’s leading bank with an international reach. With delivery centers located in Bengaluru, Chennai and Mumbai, we are a 24x7 global delivery center. India Solutions services three business lines: Corporate and Institutional Banking, Investment Solutions and Retail Banking for BNP Paribas across the Group. Driving innovation and growth, we are harnessing the potential of over 10000 employees, to provide support and develop best-in-class solutions.

Commitment to Diversity and Inclusion

At BNP Paribas, we passionately embrace diversity and are committed to fostering an inclusive workplace where all employees are valued, respected and can bring their authentic selves to work. We prohibit Discrimination and Harassment of any kind and our policies promote equal employment opportunity for all employees and applicants, irrespective of, but not limited to their gender, gender identity, sex, sexual orientation, ethnicity, race, colour, national origin, age, religion, social status, mental or physical disabilities, veteran status etc. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in.