IT & Cyber_Technical_Risk_Metrics_Specialist
Apex Group · Banking & Financial Services
- Pune - Baner
- On-site
- Posted today
- Cybersecurity
About the job
The Apex Group was established in Bermuda in 2003 and is now one of the world’s largest fund administration and middle office solutions providers.
Our business is unique in its ability to reach globally, service locally and provide cross-jurisdictional services. With our clients at the heart of everything we do, our hard-working team has successfully delivered on an unprecedented growth and transformation journey, and we are now represented by over circa 13,000 employees across 112 offices worldwide.Your career with us should reflect your energy and passion.
That’s why, at Apex Group, we will do more than simply ‘empower’ you. We will work to supercharge your unique skills and experience.
Take the lead and we’ll give you the support you need to be at the top of your game. And we offer you the freedom to be a positive disrupter and turn big ideas into bold, industry-changing realities.
For our business, for clients, and for you
Role Overview:
This role governs, monitors, and continuously improves IT & Cyber risk metrics so they are
fit for purpose, aligned with Cyber Strategy, and meet expectations set by the Group CISO.
Operating within Banking, Finance, and Hedge Fund environments, the role ensures metrics
reflect financial risk exposure, operational resilience, and compliance with global regulatory
frameworks. The role leads the annual Risk & Control Self-Assessment (RCSA) and provides
strategic inputs to the Technology Risk Forum.
Key Responsibilities:
Cyber KRIs/KPIs in line with Cyber Strategy and Group CISO directives; map to risk
appetite thresholds and business services.
analysis and remediation plans. Implement a Metric Rewrite Protocol for metrics that
consistently fail or are misaligned.
remains within appetite and align methodology with Group CISO expectations.
Risk Forum: posture, trends, material events, remediation, and asks.
mapping and evidence across ISO/IEC 27001:2022, NIST CSF 2.0, COBIT, ISO 31000;
and regulations/obligations including SOX 404, GDPR, DORA (EU), PCI DSS v4.0, and
applicable regional rules (e.g., FFIEC/US, UK PRA/FCA, MAS TRM, HKMA, APRA CPS
234).
IT Ops, Risk, Compliance, and external auditors/regulators. Influence remediation and
strategic risk initiatives.
and single source of truth for metric definitions, thresholds, owners, and evidence.
empowered Group Cyber leadership authorities, ensuring timely and effective
completion in alignment with organizational priorities.
decisions, and deliverables with strategic objectives and business outcomes.
Candidate Profile:
Experience:
Skills:
response, DR/BC, change risk.
31000), SOX 404, DORA, GDPR, PCI DSS.
ticketing (ServiceNow/Jira).
narratives.
Preferred Certifications:
Disclaimer : Unsolicited CVs sent to Apex (Talent Acquisition Team or Hiring Managers) by recruitment agencies will not be accepted for this position. Apex operates a direct sourcing model and where agency assistance is required, the Talent Acquisition team will engage directly with our exclusive recruitment partners.