Securing the Infrastructure Behind India's EV Movement
At Greaves Electric Mobility (GEML), we are building connected, sustainable transportation for millions. From automated smart manufacturing plants to IoT-connected vehicle platforms and cloud-native application stacks, robust cybersecurity, resilience, and data integrity are fundamental to our growth.
We are looking for an Assistant Manager / Manager, IT Security & Audits to own our IT General Controls (ITGC), audit defense operations, MSSP oversight, and enterprise cybersecurity compliance frameworks.
Reporting directly to the Head IT Infrastructure & InfoSec, you will serve as the primary technical Single Point of Contact (SPOC), driving seamless internal and external audits, hardening our enterprise technology landscape, and ensuring complete Digital Personal Data Protection (DPDP) readiness across our digital ecosystem.
What You Will Do
- Audit Operations & Defense Strategy: Serve as the central SPOC for all internal, statutory (ITGC), ISO 27001, and regulatory audits. Lead evidence collection, audit walkthroughs, and technical remediation, driving Corrective and Preventive Action (CAPA) plans to 100% closure within strict timelines.
- ITGC & Identity Governance Execution: Enforce access control policies, user access reviews (UAR), change management workflows via Change Advisory Board (CAB) protocols, SAP Segregation of Duties (SoD) matrix evaluations, and Privileged Access Management (PAM) implementation.
- MSSP & Security Operations Center (SOC) Supervision: Oversee our 24/7 Managed Security Service Provider (MSSP). Monitor real-time threat telemetry, supervise incident response SLAs, and enforce rapid vulnerability patch remediation pipelines across all endpoints and servers.
- Data Privacy & Compliance Roadmap (DPDP): Drive the technical controls implementation for India's Digital Personal Data Protection (DPDP) Act. Ensure data minimization, consent management, access rights, and secure data storage mechanisms across all customer-facing, dealer, and internal enterprise applications.
- Third-Party Risk Management (TPRM): Perform technical vendor security assessments, Vulnerability Assessment and Penetration Testing (VAPT) tracking, and cloud security reviews across SIs, SaaS providers, and third-party tech partners before onboarding and repeatedly.
- Security Architecture & Cloud Hardening: Review, refine, and enforce technical security configurations, cloud security posture management (CSPM across AWS/Azure, firewall rulesets, and network segmentations across corporate offices and plant facilities.
What We Look For
- 5+ Years of Core Experience: Proven track record in IT Security, ITGC, Governance, Risk & Compliance (GRC), or IT Audit within Automotive, Manufacturing, EV, or Technology Consulting environments (Big 4 experience is a massive plus).
- Solid Technical Fluency: In-depth understanding of SAP authorization models, Cloud Security controls (AWS/Azure), ISO 27001/NIST frameworks, VAPT platforms (Qualys, Nessus, Burp Suite), and enterprise SIEM/EDR/XDR tools.
- Hands-on Governance & Regulatory Mastery: Strong capability to map IT risks to business impact, interpret regulatory guidelines (DPDP, CERT-In advisories), and structure auditable evidence trails for enterprise systems.
- Cross-Functional Communication: Clear, articulate communication style to bridge technical security teams, business unit heads, external audit teams, and executive management.
- Education & Certifications: B.Tech/B.E. in Computer Science, IT, Electronics, or related technical fields. CISA, CRISC, ISO 27001 Lead Auditor, CISM, or CEH certifications are strongly preferred.