Role Summary :
The incumbent will lead the organisation's end-to-end cybersecurity function, ensuring robust protection of enterprise systems, networks, and data. The role will be responsible for defining security strategy, driving compliance, managing cyber risks, and building a resilient security posture aligned with business and regulatory requirements.
Key Responsibilities :
1. Cybersecurity Strategy & Leadership :
- Define and implement enterprise-wide cybersecurity strategy aligned with business objectives.
- Establish long-term roadmap for security transformation and maturity enhancement.
- Drive adoption of modern security frameworks (Zero Trust, defence-in-depth).
- Act as the central authority for all cybersecurity-related decisions and governance.
2. Security Operations & Risk Management :
- Oversee end-to-end security operations including :
1. Threat detection, monitoring, and response (SOC).
2. Incident response and crisis management.
- Lead vulnerability management, VAPT cycles, and risk assessments.
- Establish proactive threat intelligence and mitigation mechanisms.
- Maintain enterprise risk register and drive risk remediation.
3. Identity & Access Management (IAM/PAM) :
- Govern identity and access frameworks including :
1. Role-based access control (RBAC).
2. Privileged Access Management (PAM e.g., CyberArk).
- Ensure secure onboarding/offboarding and access lifecycle management.
- Strengthen authentication mechanisms (MFA, SSO).
4. Network, Endpoint & Cloud Security :
- Oversee security across :
1. Network infrastructure (firewalls, IDS/IPS).
2. Endpoints (EDR/XDR solutions).
3. Cloud environments (AWS/Azure/GCP security controls).
- Ensure secure configuration, monitoring, and compliance across environments.
- Drive continuous improvement in security posture across IT landscape.
5. Data Security & Privacy :
- Implement data protection strategies including :
1. Data Loss Prevention (DLP).
2. Encryption and secure data storage.
- Ensure compliance with data protection regulations (e.g., DPDPA).
- Safeguard sensitive business and employee data.
6. Governance, Risk & Compliance (GRC) :
- Ensure compliance with security standards such as :
1. ISO 27001 : 2022.
2. Other regulatory and audit requirements.
- Define and enforce IT security policies, procedures, and controls.
- Drive audit readiness and closure of audit findings.
- Maintain compliance documentation and reporting.
7. Vendor & Third-Party Security :
- Assess and manage cybersecurity risks associated with vendors and partners.
- Ensure third-party compliance with security standards and contractual obligations.
- Define security requirements in vendor agreements and SLAs.
8. Security Awareness & Culture :
- Drive organisation-wide security awareness and training programs.
- Build a strong security-first culture across business functions.
- Educate leadership and employees on cyber risks and best practices.
9. Leadership & Team Management :
- Lead and mentor cybersecurity, SOC, and GRC teams.
- Drive capability building, certifications, and skill enhancement.
- Establish clear accountability, governance, and performance metrics.
- Collaborate with CIO/CTO and business leaders for integrated security approach.
Ideal Candidate Profile :
- 10 to 15 years of experience in cybersecurity, IT security, or risk management.
- Strong exposure to enterprise security architecture, SOC operations, and GRC frameworks.
- Experience in manufacturing or large enterprise environments preferred.
- Proven track record in handling audits, regulatory compliance, and cyber incidents.
- Leadership experience managing large, cross-functional security teams.
- Certifications such as CISSP, CISM, CISA, or equivalent preferred.
Location : Ludhiana.
Education :
UG : B.Com in IT, B.Tech / B.E. in Information Technology, Diploma in IT, B.Sc in Information Technology (IT).
PG : MBA/PGDM in Information Technology, Master in IT Management in Any Specialization.
Key Skills :
Cyber Security, IT Risk Management, Information Security, IT Governance.
(ref:hirist.tech)