Responsibilities
- Develop and implement a comprehensive cybersecurity strategy that supports business goals and complies with legal and regulatory standards
- Create and maintain security policies, baselines, and governance structures
- Lead the implementation of recognized security frameworks such as NIST CSF, ISO 27001, and CIS Controls
- Oversee security operations with a focus on risk management and governance
- Analyze security events, operational threats, emerging trends, and reporting mechanisms
- Assist in preparing for incidents and managing follow-up governance processes
- Manage enterprise-wide cyber risk programs covering risk discovery, evaluation, mitigation, and communication
- Keep updated risk registers and deliver reports to executive leadership
- Assess and integrate cyber risks across cloud environments, software applications, artificial intelligence systems, IT infrastructure, and external partners
- Lead certification and audit initiatives including SOC 2 Type II, ISO 27001 / ISO 27701, PCI-DSS, and HIPAA
- Manage IT audits, prepare for certifications, collect evidence, track corrective actions, and support client security assurance
- Oversee enterprise vulnerability management initiatives
- Supervise vulnerability assessment and penetration testing (VAPT) efforts and remediation follow-up
- Advance initiatives that prioritize risks and reduce exposure based on risk severity
- Establish security and risk management frameworks specific to artificial intelligence
- Identify potential threats in AI systems such as data leaks, model tampering, privacy violations, and algorithmic bias
- Lead governance and policy enforcement for Responsible AI practices
- Support secure development and deployment across the AI lifecycle
- Work with IT and engineering units to enhance secure architectural design
- Advocate for Zero Trust models, identity-centric security, and secure software development lifecycle (SDLC) practices
- Perform risk evaluations of vendors and third-party service providers
- Support governance of supplier security and enforce contractual security obligations
- Lead organization-wide security awareness campaigns and simulated phishing exercises
- Foster a strong security-conscious culture across the enterprise
Work Arrangement
Hybrid — Bengaluru