Director of Cybersecurity

Virtual Engineering Services

Dadri

On-site

INR 1,800,000 - 3,400,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Virtual Engineering Services is seeking a senior cybersecurity leader to establish and steer the company’s security program across IT, products, and cloud services. You will shape policy, risk management, and governance while coordinating with executives and stakeholders to protect customer environments and data.

You will drive secure software practices, incident response, security awareness, and third-party risk management, ensuring alignment with frameworks and regulatory requirements.

Responsibilities

  • Establish and maintain the company's cybersecurity strategy, policies, standards, and procedures.
  • Maintain the NIST CSF Current Profile and Target Profile.
  • Identify, assess, and prioritize cybersecurity risks across IT, products, hosted services and third-party dependencies.
  • Maintain the cybersecurity risk register with remediation or risk-acceptance decisions.
  • Set cybersecurity objectives, metrics and reporting for executive management.
  • Define clear cybersecurity responsibilities across the organization.
  • Advise executive management on cybersecurity risks, priorities and investments.
  • Maintain a cybersecurity debt register and track remediation actions.
  • Establish secure SDLC and security requirements for apps and cloud services; oversee testing and remediation.
  • Define identity and access management, MFA, and remote access controls; monitor IT security controls.
  • Coordinate incident-response planning, exercises, and post-incident reviews.
  • Promote cybersecurity awareness and training for employees; enforce onboarding and provisioning security.
  • Manage third-party security risk programs and vendor security assessments.
  • Ensure compliance with applicable frameworks and coordinate security certifications.

Job description

Role Summary:
  • Objective. Establish, maintain, and continuously improve the company's cybersecurity program.
  • Mission. Provide organizational leadership for managing cybersecurity risk and protecting company information, software products, cloud services, infrastructure, and customer environments from cybersecurity threats.
  • Scope. Maintain enterprise-wide responsibility for cybersecurity risk across multiple security domains, including Corporate IT, Operations and Data; Products and Services; and Third-Party Technologies.
  • Authority & Empowerment. Establish cybersecurity requirements and standards that are subsequently implemented and operated as controls by other parts of the organization. These requirements encompass security policies, risk management, security architecture, vulnerability management, incident response, product security, security testing, security awareness, customer security, and compliance/assurance.
Key Responsibility Areas:
Cybersecurity Governance and Risk Management
  • Establish and maintain the company's cybersecurity strategy, policies, standards, and procedures.
  • Maintain the company's NIST CSF Current Profile and Target Profile.
  • Identify, assess, and prioritize cybersecurity risks across corporate IT, software products, hosted services and third-party dependencies.
  • Maintain the cybersecurity risk register and ensure significant risks have assigned owners and documented remediation or risk-acceptance decisions.
  • Establish cybersecurity objectives, metrics, and reporting for executive management.
  • Ensure cybersecurity responsibilities and accountability are clearly defined across the organization.
  • Advise executive management regarding cybersecurity risks, priorities, and investments.
  • Maintain a cybersecurity debt register that records identified security weaknesses, control gaps, deferred remediation, exceptions, and other unresolved cybersecurity risks; prioritize and track these items through remediation or formal risk acceptance (these permeate across all responsibility areas).
Product and Software Security
  • Establish and maintain secure software-development practices.
  • Establish security requirements for desktop applications, cloud applications, APIs, and hosted services.
  • Participate in security reviews of product architecture and significant product changes.
  • Establish requirements for authentication, authorization, encryption, secrets management and secure communications.
  • Oversee application-security testing, vulnerability assessment, and penetration testing.
  • Establish processes for identifying and remediating vulnerabilities in third-party components and software dependencies.
  • Establish software supply-chain security practices.
  • Establish vulnerability disclosure and remediation processes.
  • Participate in security-related release decisions for products and hosted services.
  • Partner with Development and Product Leadership to incorporate security throughout the software-development lifecycle.
Infrastructure and IT Security
  • Establish security requirements for corporate networks, endpoints, servers, cloud infrastructure, and internal systems.
  • Establish requirements for identity and access management, including MFA and privileged-access management.
  • Establish requirements for remote access and administrative access.
  • Establish vulnerability-management standards and remediation requirements.
  • Establish requirements for backup, recovery, and disaster-recovery controls.
  • Work with IT to ensure appropriate security controls are implemented and maintained.
  • Periodically assess the effectiveness of IT security controls.
  • Monitor security risks associated with significant infrastructure changes.
Security Monitoring and Incident Response
  • Establish and maintain security monitoring and logging requirements.
  • Define security event severity classifications and escalation criteria.
  • Establish procedures for identifying, analyzing, and responding to suspected security incidents.
  • Maintain the company's cybersecurity incident-response plan.
  • Coordinate investigation, containment, eradication, and recovery activities.
  • Coordinate with external forensic, legal, insurance and other specialists when required.
  • Establish procedures for preserving appropriate evidence.
  • Conduct post-incident reviews and ensure corrective actions are implemented.
  • Conduct periodic incident-response exercises and tabletop exercises.
Security Awareness and Employee Practices
  • Establish and maintain cybersecurity awareness and training programs.
  • Educate employees regarding phishing, social engineering, credential protection, and appropriate use of company resources.
  • Establish security requirements for employee onboarding, role changes, and termination.
  • Establish security requirements for access provisioning and deprovisioning.
  • Periodically assess employee cybersecurity awareness.
  • Promote a culture in which cybersecurity responsibilities are understood throughout the organization.
Third-Party and Customer Security
  • Establish and maintain a third-party cybersecurity risk-management program.
  • Identify and risk-classify critical technology suppliers and service providers.
  • Establish appropriate security requirements for critical vendors.
  • Conduct or coordinate security assessments of critical third parties.
  • Support customer and OEM cybersecurity assessments.
  • Respond to customer security questionnaires and information requests.
  • Provide appropriate security documentation and evidence to customers.
  • Coordinate cybersecurity requirements associated with customer contracts.
  • Support cybersecurity insurance assessments and requirements.
  • Establish procedures for addressing cybersecurity incidents involving critical third parties or customer environments.
Compliance and Assurance
  • Establish a cybersecurity assurance program appropriate to the company's size, products, services and customer requirements.
  • Maintain alignment with applicable cybersecurity frameworks and contractual requirements.
  • Coordinate penetration testing, vulnerability assessments and other independent security assessments.
  • Track findings and ensure remediation.
  • Maintain cybersecurity policies, procedures and evidence required for audits and customer assessments.
  • Support cyber-insurance requirements and assessments.
  • Coordinate preparation for security certifications or attestations when authorized by management.
  • Periodically assess the effectiveness of the cybersecurity program against the NIST CSF Target Profile.
Security Leadership
  • Serve as the company's senior cybersecurity subject-matter expert.
  • Establish cybersecurity priorities based upon business risk.
  • Advise the Managing Director and other senior leaders regarding cybersecurity risk.
  • Coordinate cybersecurity activities across IT, Development, Product Management, Operations, HR, and other functions.
  • Establish cybersecurity budgets and resource requirements.
  • Manage external cybersecurity consultants, penetration testers, managed security providers, and other security vendors.
  • Develop the cybersecurity function as the company grows.
  • Establish cybersecurity metrics and report program performance to management.
  • Promote a practical, risk-based cybersecurity culture throughout the organisation.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Technology Security Specialist
Information Technology Security Specialist

Senvion India • Mumbai

On-site
INR 2,500,000 - 4,200,000
Cybersecurity Lead
Cybersecurity Lead

Epergne Solutions • Chennai District

On-site
INR 1,500,000 - 2,500,000
Senior Manager – Cyber Security
Senior Manager – Cyber Security

Tata Consumer Products • Bengaluru

On-site
INR 4,000,000 - 6,000,000
Program Manager - Cyber Security
Program Manager - Cyber Security

GAVS Technologies N.A., Inc • Chennai District

On-site
INR 3,000,000 - 6,000,000
Lead - Information Security and GRC
Lead - Information Security and GRC

ABC - Aditya Birla Housing Finance Limited • Maharashtra

On-site
INR 1,200,000 - 1,800,000
Lead - Information Security and GRC
Lead - Information Security and GRC

ABC - Aditya Birla Housing Finance Limited • Maharashtra

On-site
INR 2,400,000 - 4,200,000
Manager, Cyber Fusion Center
Manager, Cyber Fusion Center

Jobtailor • Hyderabad

On-site
INR 3,000,000 - 6,000,000
Cybersecurity
Cybersecurity

Logic Planet • India

On-site
INR 1,200,000 - 1,800,000
Cyber Security Manager
Cyber Security Manager

Altimetrik • Bengaluru

Hybrid
INR 1,800,000 - 2,600,000
Sr Lead - IT Risk & GRC
Sr Lead - IT Risk & GRC

Star Union Dai-ichi Life Insurance Company Limited • Navi Mumbai

On-site
INR 1,500,000 - 2,500,000