Job Purpose
The IT Risk Manager is responsible for end‑to‑end management of Technology risks, including conducting RCSAs, identifying, monitoring, mitigating risks, and ensuring adherence to internal and regulatory policies. The role oversees audits, compliance requirements, issue identification and closure, and supports regulatory and internal reporting obligations. It requires strong coordination across Technology, Operations, Compliance, and stakeholders to ensure a resilient and well‑governed Technology environment.
Key Accountabilities/Responsibilities:
Technology Governance & Risk Management:
Conduct and manage the full lifecycle of the Risk Control Self‑Assessment (RCSA), including control identification, testing, effectiveness assessment, and documentation.
Identify, monitor, track, and mitigate Technology risks across applications, infrastructure, processes, and third‑party engagements.
Facilitate and sign‑off risk acceptance (RA) proposals in accordance with internal policies and governance requirements.
Review, monitor, and support remediation for Change Management, Incident Management, and Problem Management activities to ensure risks are assessed and adequately addressed.
Drive timely creation and execution of mitigation plans, ensuring closure of risk items within committed timelines.
Strengthen ongoing risk monitoring through proactive checks, stakeholder dialogues, and thematic risk assessments.
Audit & Compliance:
Manage all types of audits including regulatory (RBI/SEBI/MAS), internal audit, statutory audit, and concurrent audit. Support requirements for certifications including PCI DSS, ISO.
Front-end audit engagements by coordinating with auditors, managing walkthroughs, responses, and preparing teams for examination activities.
Conduct proactive internal checks prior to audits to assess readiness, validate evidence, and identify potential gaps in advance.
Lead evidence collection, quality assurance, submission, escalation handling, and end‑to‑end closure of observations.
Ensure accurate and timely reporting of audit statuses, progress updates, and action closure to senior stakeholders.
Minimize repeat findings through structured remediation, control enhancements, and process health checks.
Self Identification of Issues:
Proactively identify issues, control gaps, deviations, and process weaknesses through continuous monitoring, thematic reviews, and internal assessments.
Track and monitor identified issues to ensure timely and effective closure with accountability across Technology teams.
Maintain accurate issue logs, update dashboards, and ensure evidence‑backed closure as per governance requirements.
Promote a culture of proactive risk detection and transparent reporting across Technology units.
Regulatory & Internal Reporting
Prepare and submit regulatory reports including RBI tranche reporting, Cyber Security KRO and any other Technology‑related compliance submissions, and supervisory artefacts as required.
Manage and track Key Risk Indicators (KRIs), perform trend analysis, and highlight emerging risks through structured KRI governance.
Support internal risk reporting including dashboards, governance packs, periodic updates for senior management, and management forums.
Ensure accuracy, completeness, and timely delivery of all regulatory and internal risk reporting commitments.
Developing internal controls checks to check adherence and reporting from time to time
Driving Automation of control checks and adaption of AI, data and automation in to governance and risk practices
Risk Awareness & Culture
Drive a strong risk‑aware culture across Technology by promoting proactive identification of risks, early escalation, and transparent communication.
Conduct regular training sessions, awareness programs, and targeted workshops to strengthen understanding of Technology Risk, compliance expectations, and audit preparedness.
Partner with leaders and teams to embed risk‑first thinking into day‑to‑day operations, project governance, and decision‑making processes.
Foster continuous learning by sharing lessons from incidents, audits, and thematic assessments to prevent recurrence and enhance capability maturity.
Encourage teams to internalize accountability for controls, risk ownership, and adherence to regulatory and internal standards.
Collaboration and Communication:
Collaborating with cross-functional teams to ensure Tech risk deliverables are met within committed deadlines
Ensuring effective communication and collaboration across different technology teams and stakeholders
Driving initiatives to enhance Tech Risk culture across units and create environment for proactive actions with regards to Tech Risks
Requirements
Education / Preferred Qualifications
Bachelor’s degree in IT, Computer Science, Engineering, or related field.
Preferred: Master’s in technology/IS or MBA.
Certifications like CISA, CRISC, CISM, CISSP, ISO Lead Auditor are beneficial
Core Competencies
Technical Competencies
Location:
Mumbai
Job:
Technology
Schedule:
Regular
Employee Status:
Full time
Introduction Welcome to Gallagher – a global community of people who bring bold ideas, deep expertise, and a shared commitment...
Apply For This JobAbout the company Lexitas is a high growth company. The Company is built on a belief that having strong personal...
Apply For This JobCompany: Techryde Pvt. Ltd. Position: Content Writer Executive Experience Required: 0 to 2 years Location: Sector-62, Noida Working Days: 5...
Apply For This JobJob Description The Loan Servicing & Credit Support Supervisor – Team Leader is a pivotal role within our Loans group,...
Apply For This JobJob description About the projects : we are building LLM evaluation and training datasets to train LLM to work on...
Apply For This JobHome About Us Services Job Listings Scholarships School/Baccalaureate Certificate/Diploma Bachelors Masters Post Graduates PhD Research Projects Research & Development Education...
Apply For This Job