Nature and scope of responsibilities :
The Information Security Lead (ISL) is accountable for ensuring appropriate controls are in place for the security of information assets. The ISL safeguards information by seeing that security risks are identified, assessed, accurately reported, and remediated. Additionally, the ISO is charged with ensuring local procedures and activities comply with all regulatory requirements and internal and parent company policies, procedures, guidelines, and standards. The ISL is the centre of competence for Information Security providing an advisory services role and acting as the focal point for security compliance related activities and responsibilities.
Job Description & Key Responsibilities :
- Take the lead on developing, maintaining, and updating the Information Security Strategy and Information Security Program
- Diligently maintain Company's Information Security Framework and underlying policies, procedures, standards, and guidelines
- Actively ensure appropriate administrative, physical, and technical safeguards are in place to protect organization's information assets from internal and external threats
- Meticulously identify, introduce, and implement appropriate procedures, including checks and balances, are in place to test these safeguards on a regular basis
- Thoroughly conduct and complete annual reviews and audits as required engaging both internal business teams across the organization and external resources. Make sure that disaster recovery and emergency operating procedures are in place and tested on a regular basis
- Assists organization to ensure compliance to the applicable regulatory compliance requirements in the areas such as ISO : 27001, SOC II, PCI- DSS, and GDPR
- Act as the committed owner of the security incident and vulnerability management processes from design to implementation and beyond
- Manage and assist in performing on-going security monitoring of information systems including assessing information security risk through qualitative risk analysis on a regular basis, conducting functional and gap analyses to determine the extent to which key business areas and infrastructure comply with statutory and regulatory requirements as applicable, evaluating and recommending new information security technologies and counter-measures against threats to information or privacy, and developing security reports and dashboards. Work closely with Group Information Security team to implement and maintain security standards.
- Ensure effective staff training programs are in place to increase security awareness across the company.
Educational Qualifications :
Engineering Degree in Computer Science or Information Technology combined with 8 to 10 years of related experience in Cyber Security, Risk, ComplianceRecognized industry certification such as CISSP, CISSLP, GIAC, CISM, ISO27001-Lead ImplementerKnowledge & Skills :
Significant experience in applying ISO-27001 standards, and Indian regulatory and statutory security requirements (IT Act, GDPR etc.) to business and technical environments while providing a service-oriented approach to maintain compliance.Proficiency in performing IT and OT Security risk, business impact, control, and vulnerability assessments.Good understanding of business applications, including AI / ML, and e-commerce systems.Good exposure on SDLC, secure coding and the working culture of Software DevelopmentExperience in designing and implementing security controls and compliance activities within organization using multiple technologies and architectures deployed both on premises and cloud;Good technical knowledge and experience in designing and implementing security controls cloud-based Infrastructure and software tools eg. Operating systems, Databases, Middleware, Encryption, IAM, SIEM, Firewall, Identity Management system, IPS / IDS, DLP, APT and other security tools.Knowledge of network and server infrastructure, and the associated applications and concepts.Demonstrated ability to apply IT-related knowledge and experience in solving security issues.Strong project management and communication skills (written and oral) with internal organizations and external / internal auditors.Good communication skills and should take the confidence of the customer in all security aspects and play as trusted advisorUnderstanding of Industry security standards such as ISO 27001, PCI-DSS, ISO 31000, NISTInformation Security Risk management(ref : iimjobs.com)