Information Technology-Security

Yokohama-ATG

Mumbai

On-site

INR 3,500,000 - 6,000,000

Full time

7 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Yokohama TWS S.p.A. in Mumbai seeks an IT Security Director to define and lead enterprise information security strategy across the organization. This senior role is responsible for risk governance, policy frameworks, and security operations spanning multiple entities and countries.

You will manage security programs, incident response, BCM, and forensics, reporting to the Head of IT. Strong leadership, communication, and cross-functional collaboration are essential.

Qualifications

  • MBA or degree in Business Administration, Computer Science or a related field.
  • CISSP, CISM, CISA or ISO 27001 Lead Implementer/Auditor preferred.
  • Fluent in English and able to operate across multiple geographies.

Responsibilities

  • Define and lead enterprise information security strategy and risk management program.
  • Establish information security policies, standards and governance aligned with ISO/IEC 27001 and NIST.
  • Oversee security monitoring, incident response, BCM, backup and recovery, eDiscovery and forensics.
  • Liaise with executives and business units to embed security-by-design and maintain risk appetite.

Skills

Leadership
Stakeholder management
Communication
Risk management
Strategic thinking

Education

MBA or degree in Business Administration/CS

Job description

SECTION II. PURPOSE OF THE ROLE

This role is responsible for defining and leading the enterprise information security strategy of the Organization, establishing the framework for information security management and ensuring that the impact and occurrence of information security incidents remain within the business’ risk appetite. As the senior accountable owner for cyber and IT risk (CISO-level role), the IT Security Director continually identifies, assesses and reduces IT-related risk within the tolerance levels set by the business; manages the protection of enterprise information; establishes information security roles and access privileges; and designs and oversees the security monitoring, incident response, business continuity, backup and recovery, eDiscovery and forensics capabilities across all entities and countries in scope.

  • Security Strategy & Governance
  • Develop, implement and monitor a strategic, comprehensive enterprise information security and IT risk management program
  • Define and maintain the information security management framework, policies and standards in line with ISO/IEC 27001 and NIST, and ensure their consistent application across all technology projects, systems and services
  • Establish information security roles, responsibilities and access privileges, and provide leadership to the enterprise’s information security organization
  • Manage and report on the security posture to executive leadership and governance committees, keeping residual risk within the defined risk appetite
  • Risk Management & Business Alignment
  • Work directly with the business units to facilitate risk assessment and risk management processes, and continually identify, assess and reduce IT-related risk within agreed tolerance levels
  • Partner with business stakeholders across the company to raise awareness of risk management concerns and embed a security-by-design culture.
  • Ensure information security is embedded in Business Continuity Management (BCM), and define the policies for backup, recovery, eDiscovery and forensics.
  • Manage contract and vendor negotiations and oversight for security-related managed services, ensuring compliance with applicable regulations (e.g. GDPR) across all countries in scope
  • Security Operations, Incident Response & Innovation
  • Define and manage security monitoring to minimize the business impact of operational information security vulnerabilities and incidents, and design and manage the implementation of security management practices to effectively respond to security incidents.
  • Educate the business in the adoption of security best practices and emerging technologies, monitoring the threat landscape and industry/process best practices and driving their execution.
  • Assist with overall business technology planning, providing current knowledge and a future vision of security technology and systems, and driving a security-aware culture within the organization
Job Description
SECTION I. BASIC INFORMATION

Job Title

IT Security Director

Location

ITA – Tivoli

IND - Mumbai

Entity

Yokohama TWS S.p.A.

Reporting to

Head of IT

Division

IT

Direct Reports (Nos)

1 - 3

Department

IT

Team Size (Nos)

2–4

Unique Job Code

(To be filled by HR)

SECTION II. PURPOSE OF THE ROLE

This role is responsible for defining and leading the enterprise information security strategy of the Organization, establishing the framework for information security management and ensuring that the impact and occurrence of information security incidents remain within the business’ risk appetite. As the senior accountable owner for cyber and IT risk (CISO-level role), the IT Security Director continually identifies, assesses and reduces IT-related risk within the tolerance levels set by the business; manages the protection of enterprise information; establishes information security roles and access privileges; and designs and oversees the security monitoring, incident response, business continuity, backup and recovery, eDiscovery and forensics capabilities across all entities and countries in scope.

SECTION III. Key Result Areas
  • Security Strategy & Governance
    • Develop, implement and monitor a strategic, comprehensive enterprise information security and IT risk management program
    • Define and maintain the information security management framework, policies and standards in line with ISO/IEC 27001 and NIST, and ensure their consistent application across all technology projects, systems and services
    • Establish information security roles, responsibilities and access privileges, and provide leadership to the enterprise’s information security organization
    • Manage and report on the security posture to executive leadership and governance committees, keeping residual risk within the defined risk appetite
  • Risk Management & Business Alignment
    • Work directly with the business units to facilitate risk assessment and risk management processes, and continually identify, assess and reduce IT-related risk within agreed tolerance levels
    • Partner with business stakeholders across the company to raise awareness of risk management concerns and embed a security-by-design culture.
    • Ensure information security is embedded in Business Continuity Management (BCM), and define the policies for backup, recovery, eDiscovery and forensics.
    • Manage contract and vendor negotiations and oversight for security-related managed services, ensuring compliance with applicable regulations (e.g. GDPR) across all countries in scope
  • Security Operations, Incident Response & Innovation
    • Define and manage security monitoring to minimize the business impact of operational information security vulnerabilities and incidents, and design and manage the implementation of security management practices to effectively respond to security incidents.
    • Educate the business in the adoption of security best practices and emerging technologies, monitoring the threat landscape and industry/process best practices and driving their execution.
    • Assist with overall business technology planning, providing current knowledge and a future vision of security technology and systems, and driving a security-aware culture within the organization
SECTION IV. Key Interactions
Internal Interactions

Party Interacting With

Business Unit Leaders / IT Teams / IT Business Partners / Process & Data Owners / Internal Audit / Legal & Compliance / DPO

Main Purpose of Interaction / Details

Facilitating risk assessment and risk management processes, aligning the security strategy and roadmap with business priorities, ensuring consistent application of security policies and standards across projects, raising risk awareness, and coordinating incident response, BCM, data protection and compliance activities

Frequency (Put a √)

Occasional

Frequent

Continuous

External Interactions

Solution Partners

Keeping abreast of developments, functionality enhancements, technology architecture, licensing and deployment models in the cyber security solution space

Solution Implementation Partners

Engagements for Project / Solution Delivery, Keep track of the capability / current track record of Solution Implementation Partners, Maintaining a connect with the Solution Implementation Partners Ecosystem

Managed Security Service Providers (MSSP) / SOC Partners

Smooth functioning of monitoring, detection and response engagements; periodic service review and SLA management

SMEs

Obtain expert opinion / threat intelligence / knowledge / support on specialized security topics; engage with regulators, auditors and CERT/industry bodies as needed

Knowledge, Skills And Experiences
Competencies
Educational Background
  • Mandatory: MBA or degree in Business Administration / Computer Science / a technology-related field
  • Preferred: Professional security management certification (e.g. CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor)
Functional/ Technical Competencies
  • Solid knowledge of information security management frameworks such as ISO/IEC 27001 and NIST
  • Experience in risk management, security architecture, identity & access management, security monitoring (SIEM/SOC) and incident response
  • Understanding of data protection / privacy regulations (GDPR) and of BCM, backup & recovery, eDiscovery and forensics
  • Experience with contract and vendor negotiations and management, including managed security services
  • Policy and security documentation skills
  • Strong project management / delivery management skills; advanced use of MS Office tools
Behavioral/ Managerial Competencies
  • Strong Change Management Skills
  • Stake Holder Management
  • Budget Management & Execution Skills
  • Excellent Communication /Collaboration Skills
  • Problem Solving
  • Leadership capability: ability to lead and motivate cross-functional, interdisciplinary teams
  • Fluent in English; high level of personal integrity; ability to manage complexity and work under pressure; willing to travel across plant/country locations as per need
Work Experience
  • Minimum 5 to 12 years in a combination of risk management and information security
  • Experience leading an information security function / CISO-level responsibilities in a multi-country enterprise will be preferred
Other Skills
Budgeted Compensation (To be Filled by HR)
ANNEXURE – I
Our Values
Customer Centricity

Actively developing & deploying ‘solutions’ which serve customer needs and alleviate their pain points

Integrity

Doing what you say you will do and doing what is right

Entrepreneurship

Taking accountability and driving results as an owner.

Taking initiative

Freedom to operate and take risks

Humility

Being courteous, modest and respectful towards everyone we interact with

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Manager
Information Security Manager

FCI CCM, Inc. • Dadri

On-site
INR 2,500,000 - 4,000,000
Group Head of Information Security
Group Head of Information Security

Davies • Pune District

On-site
INR 400,000 - 750,000
Group Head of Information Security
Group Head of Information Security

Davies Group • Pune District

On-site
INR 4,000,000 - 7,000,000
Information Security Manager
Information Security Manager

Dmi Finance • Dadri, Delhi

On-site
INR 1,200,000 - 1,800,000
Manager – Information Security Governance
Manager – Information Security Governance

Cognizant • Chennai District

On-site
INR 2,600,000 - 5,200,000
Security Engineering Lead
Security Engineering Lead

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 3,500,000 - 6,500,000
Lead - Cybersecurity
Lead - Cybersecurity

Adani Transmission (ATL) • Mumbai

On-site
INR 1,200,000 - 1,800,000
Director - Data Privacy & Information Security
Director - Data Privacy & Information Security

Indegene • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Comprehensive health insurance
Retirement benefits
Professional development opportunities
SOC Engineer
SOC Engineer

Mintskill HR Solutions LLP • Mumbai

On-site
INR 600,000 - 1,000,000
Security Manager
Security Manager

FM India Supply Chain • Pune District, Mumbai

On-site
INR 2,500,000 - 4,000,000