Pause
Read
Crédit Agricole CIB vacancy search engine

Information Security Risk Manager


Vacancy details

General information

Entity

About Crédit Agricole Corporate and Investment Bank (Crédit Agricole CIB)

Crédit Agricole CIB is the corporate and investment bank of the Crédit Agricole group, the 10th largest banking group in the world *.

We support major companies and financial institutions in their development and the financing of their projects.

As pioneers in responsible finance, social and environmental commitments are at the heart of our activities.

Joining our teams means working in a multicultural environment, both dynamic and stimulating, where you will contribute to developing a sustainable economy.

We support employees throughout their journey: you will develop your skills and access various mobility opportunities among the diversity of our businesses in more than 30 international locations.

Our culture is built on collaboration, innovation and openness, where everyone is valued and empowered.

By working every day in the interest of society, Crédit Agricole CIB aligns with the Group values committed to diversity and inclusion and placing people at the heart of all its transformations.

All our jobs are open to people with disabilities. We welcome applications from candidates of all backgrounds and experiences.

Ready to take part in our mission ?

*By balance sheet size - The Banker, Juillet 2025  

Reference

2026-114701  

Update date

03/08/2026

Job description

Business type

Types of Jobs - IT, Digital et Data

Job title

Information Security Risk Manager

Contract type

Permanent Contract

Expected start date

20/10/2026

Job summary

An experienced Information Security Risk Manager to strengthen our IS Risk management and control environment. The candidate shall also be responsible for managing audits and ensuring timely compliance including tracking of audit recommendations/findings. The ideal candidate must possess strong IS Risk management experience, preferably within the BFSI sector.

Supplementary Information

Key Responsibilities

•Contribute to the development and maintenance of a robust Information Security Risk management framework including Cyber Security, ensuring alignment with legal entity regulatory requirements for CACIB India.


•Handling regulatory (primarily Reserve Bank of India) internal and external audits including closure of audit recommendations by coordinating with all the relevant stakeholders across the globe.


•Coordinate tracking and closure of risk recommendations arising from audits, assessments,& risk reviews, ensuring timely remediation and escalation where necessary.


•Engage with multiple stakeholders, including global teams, to ensure effective implementation of IS Risk management initiatives.


•Establish and ensure implementation of IS Risk policies, procedures, and standards across the organization.


•Perform risk-based deep dives to identify IS Risks, validate root causes for IS-related events, and recommend corrective actions

•Stay abreast of changes in Indian regulations pertaining to Information Security Risk Management and escalate relevant updates to Head Office (HO) as applicable.


•Participate in and contribute to the implementation of the global control plan.


•Assess and control the Information Security implications of local changes to processes or systems, ensuring adherence to group policies by coordinating with relevant stakeholders.


•Assist CISO in implementing and maintaining security controls across the organization.

Position location

Geographical area

Asia, India

City

MUMBAI

Candidate criteria

Minimal education level

Bachelor Degree / BSc Degree or equivalent

Academic qualification / Speciality

Education Qualification

Bachelor of Technology (B.Tech) or Bachelor of Engineering (B.E.) OR
Bachelor of Science in Computer Science (B.Sc. Computers)

Preferred Certifications 

CRISC (Certified in Risk and Information Systems Control), CISA (Certified Information Systems Auditor), ISO 27001 Lead Auditor/Implementer, ISO 31000 Risk Management, COBIT (Control Objectives for Information and Related Technologies), ITIL (Information Technology Infrastructure Library)

Level of minimal experience

6-10 years

Experience

• Minimum 8 years of professional experience in Information Security or related fields, preferably within the BFSI domain.

• Prior experience in handling audits- regulatory (preferably, Reserve Bank of India), internal and external audits including closure of audit recommendations by coordinating with all the relevant stakeholders including IT, preferably across the globe.

• Strong understanding of the Banking regulatory landscape in India.

• Strong Information Security background with knowledge across various domains such as Network Security, Data Security, Security Operations Center (SOC), etc.

• Prior experience engaging with multiple stakeholders, preferably across global entities.

• Hands-on experience working with IT teams on information security projects.

• Experience in coordinating and tracking recommendations from audits, assessments, and risk reviews to ensure timely closure.

Required skills

• Communication: Excellent interpersonal and communication skills in English (written and spoken) to effectively communicate at all organizational levels, from staff to senior management.

• Analytical Thinking: Strong rational, critical thinking, and reasoning skills.

• Proactive & Motivated: Self-driven with excellent people skills and the ability to work collaboratively.

• Multitasking: Ability to multitask and quickly learn about diverse subjects.

• Technical Proficiency: Advanced user of Microsoft Office tools (Excel, Word, PowerPoint).

Technical skills required

• Solid understanding of IS Risk and control frameworks (certifications such as COBIT, ISO 27001, ISO 31000, ITIL, or equivalent are highly preferred).

• Knowledge of IT networks, ISO Controls, NIST framework for IT security, and cyber security controls.

• In-depth knowledge of banking systems, Information System general architecture, and various IT actors (support teams, development teams, etc.).