Group Head of Information Security

Davies Group

Pune District

On-site

INR 4,000,000 - 7,000,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Davies Group is seeking the Group Head of Information Security to lead enterprise-wide security governance, ISMS, and risk leadership from the Office of the CISO. Based in Pune, this role commands authority across Davies entities globally and reports to the Group CISO.

The role drives security strategy including identity security, AI governance, PQC readiness, and resilience engineering, shaping security posture for 2026 and beyond.

Qualifications

  • Significant experience in a senior information security leadership role.
  • Expertise in enterprise security risk management and governance.
  • Proven track record with ISO 27001 certification and audits.

Responsibilities

  • Define and operate Group-wide information security governance with measurable outcomes.
  • Own the Group ISMS and drive ISO 27001 surveillance and audits.
  • Lead security-by-design governance across architecture and change delivery.
  • Oversee AI governance, security for identity, and cloud security posture.
  • Strengthen supplier and ecosystem assurance with ongoing risk management.
  • Oversee incident reporting, root cause analysis, and lessons learned.
  • Lead security due diligence for M&A and integration of acquisitions.
  • Develop and mentor security leadership across the Group.

Skills

Security leadership
ISMS governance
ISO 27001
Cloud security
Identity security
Risk management
Stakeholder communication

Job description

Group Head of Information Security

Department: Risk and Compliance

Employment Type: Permanent - Full Time

Location: Pune


Description

The Head of Information Security is a senior leadership position within the Office of the CISO, reporting directly to the Group CISO. The role carries accountability for the design, implementation, and continuous improvement of the Group Information Security Management System (ISMS) across all Davies entities globally, including newly acquired businesses.

The role is based in the India Global Capability Centre (GCC) and carries enterprise-wide authority for Group information security governance, assurance and risk leadership across all Davies entities globally.

This is a strategic role that goes beyond traditional ISMS stewardship. The Group Head of Information Security is expected to provide business-driven security and information risk leadership, influencing outcomes at Board and Executive Committee level and enabling growth within risk appetite.

In a rapidly evolving threat landscape, the role now explicitly encompasses risk identification across identity security strategy, AI governance oversight, post-quantum cryptography readiness, and operational resilience engineering — ensuring Davies is prepared not only for today’s threats but for the emerging challenges of 2026 and beyond.


Key Responsibilities

Governance, Risk & Board Engagement

  • Define and operate Group-wide information security governance, including risk appetite translation, risk acceptance/exception processes, and escalation through Group risk and governance forums with measurable outcomes.
  • Own the Group assurance model (control assurance, audit readiness, continuous monitoring) to provide risk owners with objective, decision-grade evidence of security posture.
  • Deliver monthly Board reporting on security risk posture, control effectiveness, and emerging threats, translating technical risk into clear business options and trade-offs.
  • Maintain and continuously improve the Group risk register, ensuring alignment with enterprise risk management frameworks and regulatory expectations.

ISMS Ownership & Compliance

  • Own and continuously improve the Group ISMS (aligned to ISO 27001), ensuring it remains fit for business purpose and scaled appropriately across all Davies entities globally.
  • Drive the annual ISO 27001 surveillance/recertification cycle, coordinating internal audits, management reviews, and external audit engagements.
  • Ensure the Group policy framework is current, proportionate, and effectively communicated, with demonstrable compliance monitoring and exception management.
  • Maintain alignment with relevant regulatory and contractual obligations (including data protection regulations, client contractual security requirements, and sector-specific standards).

Security-by-Design & Identity

  • Chair or set direction for security-by-design governance across architecture and change delivery, including control patterns/standards, design assurance, and pragmatic exception handling.
  • Establish a Group identity security strategy covering workforce, privileged access, third parties, and service/bot identities, including defences against deepfake/impersonation attacks and insider/fake employee scenarios.
  • Ensure security requirements are embedded in enterprise and solution architecture decisions, balancing risk, policy, and cost of controls.
  • Govern cloud security posture including consumption/cost-abuse controls, resource guardrails, anomaly detection, and FinOps+SecOps integration.

AI & Automation Governance

  • Define and oversee security controls for AI-enabled tooling and automation across the Group, including acceptable use policies, data handling requirements, and monitoring/assurance.
  • Reduce exposure to AI-assisted social engineering through modern security awareness programmes that explicitly address AI-crafted persuasion and impersonation techniques.
  • Govern shadow AI risk through discovery, policy enforcement, and pragmatic onboarding pathways that balance productivity with control.
  • Contribute to enterprise AI/algorithm governance, ensuring controls, monitoring, auditability, and risk management for third-party models and automated decisioning.

Supplier & Ecosystem Assurance

  • Strengthen third-party and supply chain assurance beyond initial assessment, including contractual security controls, ongoing assurance cadence, concentration risk analysis, and cascading supply-chain compromise readiness.
  • Ensure supplier risk is integrated into Group risk reporting and that material third-party security risks are escalated to appropriate risk owners.

Incident Reporting & Monitoring

  • Oversee threat-led security planning and incident response maturity across the Group, working closely with the Cyber team.
  • Ensure robust incident reporting, classification, root cause analysis, and lessons-learned processes are embedded and continuously improved.
  • Maintain deepfake/impersonation preparedness for executives and high-risk business processes.

M&A Security Integration

  • Lead security due diligence and risk assessment for mergers, acquisitions, and divestitures.
  • Design and deliver security integration plans for newly acquired businesses, ensuring alignment with Group ISMS standards within defined timescales.
  • Identify and manage inherited security risks from acquisitions, including legacy technology, unmanaged identities, and contractual obligations.

Team Leadership & Development

  • Lead, develop and mentor the four Divisional Information Security Officers, creating consistent standards, clear accountability and a high-performing federated security leadership community across the Group
  • Build team capability in emerging disciplines (identity security, AI governance, resilience engineering, PQC readiness) through targeted development and recruitment.
  • Promote security culture across the wider organisation through engagement, awareness, and collaboration with business stakeholders.

Skills, Knowledge and Expertise
  • Significant experience in a senior information security leadership role, with demonstrable ability to influence senior risk owners and embed security decision-making across multiple business units and geographies.
  • Expert capability in enterprise security risk management, including risk appetite translation, risk acceptance pathways, measurable risk treatment plans and independent assurance reporting.
  • Proven track record of maintaining ISO 27001 certification and managing external audit cycles in a complex, multi-entity organisation.
  • Strong experience implementing security-by-design governance across architecture and change delivery, including control patterns, design assurance and pragmatic exception handling.
  • Strong understanding of identity-led security, including privileged access, third-party identity and anti-impersonation controls.
  • Excellent communication skills, with the ability to tailor messages for Board, CISO, technical and business audiences, including concise risk narratives and clear escalation.
  • Experience governing cloud security and modern attack surfaces, including vulnerability and exploit response expectations and secure operational patterns.
  • Strong supplier assurance experience beyond initial assessment, including contractual controls, ongoing assurance programmes and supply-chain compromise readiness.
  • Demonstrated success leading through federated and matrix structures, including directing divisional security leaders and aligning stakeholders without relying solely on line authority.
  • Demonstrated ability to lead and influence senior stakeholders across multiple cultures and geographies through clear governance, strong written communication and disciplined decision-making.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Group Head of Information Security
Group Head of Information Security

Davies • Pune District

On-site
INR 400,000 - 750,000
Director - Data Privacy & Information Security
Director - Data Privacy & Information Security

Indegene • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Comprehensive health insurance
Retirement benefits
Professional development opportunities
Information Technology-Security
Information Technology-Security

Yokohama-ATG • Mumbai

On-site
INR 3,500,000 - 6,000,000
CISO (Chief Information Security Officer)
CISO (Chief Information Security Officer)

JobItUs • Mumbai

On-site
INR 4,000,000 - 7,000,000
Security, Risk & Compliance Lead
Security, Risk & Compliance Lead

RedDoorz • Dadri

On-site
INR 2,400,000 - 4,800,000
Information Security Manager
Information Security Manager

FCI CCM, Inc. • Dadri

On-site
INR 2,500,000 - 4,000,000
Manager
Manager

HCLTech • Chennai District

On-site
INR 1,800,000 - 3,000,000
Chief Information Security Officer
Chief Information Security Officer

Adani Enterprises Ltd • Ahmedabad District

On-site
INR 4,500,000 - 7,500,000
AVP-Information Security Compliance.Information Security Group-ISG
AVP-Information Security Compliance.Information Security Group-ISG

Mashreq • Bengaluru

On-site
INR 3,000,000 - 5,400,000
GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000