Chief Information Security Officer (CISO) IT & OT Cybersecurity
Location: India
Function: Information & Cybersecurity
Level: Senior Leadership
Role Overview
We are seeking an experienced Chief Information Security Officer (CISO) to lead enterprise-wide cybersecurity across IT, Operational Technology (OT), Industrial Control Systems (ICS), SCADA, applications, cloud, and digital infrastructure.
The CISO will be responsible for developing and executing the cybersecurity strategy, strengthening the organization's IT/OT security posture, protecting critical infrastructure, and ensuring compliance with applicable regulatory and industry standards.
The role requires strong experience in OT/ICS/SCADA cybersecurity, enterprise security architecture, incident response, vulnerability management, and Application Security including SAST and DAST.
Key Responsibilities
Cybersecurity Strategy & Governance
- Develop and execute the enterprise cybersecurity strategy covering IT, OT, cloud, applications, networks, and critical infrastructure.
- Establish cybersecurity governance, policies, standards, risk frameworks, and security controls.
- Own enterprise cyber-risk management and provide regular risk reporting to senior management and the Board.
- Establish and monitor cybersecurity KPIs, KRIs, maturity assessments, and improvement programs.
- Drive security awareness and cybersecurity culture across the organization.
OT / IAS / SCADA Security
- Lead cybersecurity strategy for Operational Technology environments, SCADA, ICT, DCS, PLCs, industrial networks, and critical infrastructure.
- Establish OT security architecture, segmentation, zoning, secure remote access, monitoring, and access-control mechanisms.
- Conduct OT cybersecurity risk assessments and vulnerability assessments while considering operational and safety requirements.
- Implement and mature OT Security Operations / SOC capabilities, including monitoring and detection of anomalous activity.
- Develop OT incident-response and recovery plans for cyber incidents affecting industrial environments.
- Work closely with engineering, plant operations, automation, and infrastructure teams to embed security into OT environments.
- Ensure alignment with relevant standards such as IEC 62443, NIST, ISO 27001, NIST 800-82, and applicable regulatory requirements.
Application Security – SAST / DAST
- Establish and govern an enterprise Application Security / DevSecOps program.
- Implement SAST (Static Application Security Testing) across the software development lifecycle.
- Implement DAST (Dynamic Application Security Testing) for web applications, APIs, and digital platforms.
- Define secure coding standards, application security policies, vulnerability thresholds, and remediation SLAs.
- Integrate security testing into CI/CD pipelines and establish DevSecOps practices.
- Oversee application penetration testing, API security, vulnerability management, and secure software development.
- Drive remediation of critical and high-risk application vulnerabilities in partnership with engineering teams.
Security Operations & Incident Response
- Lead enterprise security operations, threat detection, incident response, vulnerability management, and cyber threat intelligence.
- Establish effective SOC, SIEM, SOAR, EDR/XDR, UEBA, and threat-hunting capabilities.
- Direct response to major cybersecurity incidents, including IT and OT incidents.
- Conduct cyber crisis simulations, tabletop exercises, and business continuity / disaster recovery exercises.
- Establish processes for threat intelligence, attack-surface monitoring, and proactive threat hunting.
Risk, Compliance & Audit
- Own cybersecurity risk assessments across IT, OT, applications, cloud, and third-party environments.
- Ensure compliance with applicable Indian regulations and industry requirements.
- Lead internal and external cybersecurity audits and remediation programs.
- Establish third-party / supplier cybersecurity risk management, particularly for OT vendors and technology partners.
Required Experience
- 15+ years of progressive experience in cybersecurity, information security, or cyber risk, with significant experience in senior leadership roles.
- Strong experience leading cybersecurity for large enterprises, critical infrastructure, industrial, energy, utilities, manufacturing, infrastructure, or similar environments.
- Demonstrated expertise in OT/ITS/SCADA cybersecurity.
- Strong understanding of SAST, DAST, DevSecOps, application security, API security, and secure SDLC.
- Experience building or leading enterprise SOC and incident-response capabilities.
- Strong knowledge of cybersecurity architecture, vulnerability management, penetration testing, IAM, network security, cloud security, and data protection.
- Experience managing large cybersecurity teams, budgets, vendors, and strategic transformation programs.
- Strong Board / CXO-level communication and stakeholder-management skills.
Preferred Certifications
- CISSP
- CISM
- GIAC / GICSP
- IEC 62443 certification
- ISO 27001 Lead Implementer / Lead Auditor
- Relevant cloud-security certifications
Key Competencies
- IT & OT Cybersecurity Leadership
- OT / IAS / SCADA Security
- Critical Infrastructure Protection
- SAST / DAST / DevSecOps
- Cyber Risk & Governance
- SOC & Incident Response
- Security Architecture
- Vulnerability Management
- Threat Intelligence & Threat Hunting
- Cloud & Application Security
- Regulatory Compliance
- Executive & Board Communication
- Crisis Management
Success in the Role
The successful CISO will build a unified IT + OT cybersecurity program, reduce enterprise cyber risk, strengthen the security of critical industrial environments, mature application security through SAST/DAST and DevSecOps, and establish resilient detection, response, and recovery capabilities across the organization.