31 Jul
|
Spot Your Leaders u0026 Consulting
|
India
31 Jul
Spot Your Leaders u0026 Consulting
India
: Head - Internal Corporate Cyber Secuirty
Location: Bengaluru, India
Function: Cybersecurity Services, MCDC, DFIR, GRC & AI Security Platforms
Role Summary
We are seeking a senior cybersecurity leader to head internal corporate cybersecurit y, including our MCDC (Managed Cyber Defense Center ) operating as an internal enterprise security functio n. The role is responsible for protecting our people, data, infrastructure, applications, cloud, and AI ecosyste m across global locations. The incumbent will lead enterprise security operations, digital forensics & incident response, GRC, security architecture, and AI governanc e, with accountability for risk reduction, regulatory compliance, and resilienc e of our organization's environment.
Key Responsibilities
1. Enterprise Cybersecurity Strategy & Governance
- Define and execute the internal cybersecurity strategy and roadm ap aligned to business priorities and global regulatory expectations
- Establish enterprise security policies, standards, and control framewor ks
- Drive Zero Trust, secure access, cloud security, identity governance, and AI securi ty strategies for the corporate environment
- Act as trusted advisor to CRO/CISO and executive leadersh ip on cyber risk posture, investments, and exceptions
3. Digital Forensics & Incident Response
- Define forensic readiness framewo rks and chain-of-custody protoc ols aligned to legal, HR, and regulatory expectations
- Build and maintain incident response playbo oks for ransomware, APTs, insider threats, data breaches, and cloud-native attacks
- Integrate endpoint, network, identity, and cloud teleme try into unified forensic workflows
- Drive automation of DFIR ta sks using orchestration, LLMs, and agents
- Automated evidence collection
- Triage and timeline reconstruction
- IOC enrichment and correlation
- Lead major internal incident investigati ons, coordinating with Legal, HR, IT, Compliance, regulators, and law enforcem ent as needed
4. Security Architecture & Engineering
- Lead design and implementation of enterprise security architec ture, including:
- Zero Trust architecture
- Cloud & SaaS security (cloud posture management, workload protection, secure access
- Endpoint protection and detection
- Email and collaboration security
- Vulnerability and exposure management
- Backup, recovery, and cyber resilience
- Identity & Access Management (IAM, PAM)
- Data protection and DLP
- Ensure secure-by-design principles are embedded across internal IT, engineering, and delivery platforms.
5. Enterprise GRC, Risk & Compliance
- Establish and govern internal cyber risk management frame works aligned to:
- ISO 27001
- ISO/IEC 42001 (AI Management Systems)
- NIST CSF / NIST AI RMF / NIST SP 800-86 (Forensics)
- GDPR, EU AI Act, India DPDP Act
- PCI DSS, SOC 2
6. AI Governance & Secure AI Adoption
- Lead secure adoption of enterprise AI platforms and generative AI tools across the organization.
- Define controls for:
- Data protection (no training on enterprise data, DLP, audit logs)
- Access governance and license provisioning
- Contractual safeguards and exemption tracking
- Embed ISO/IEC 42001 AI governance prin ciples into the internal AI lifecycle.
7. Cyber Insurance, Audit & Regulatory Interface
- Own internal cyber insurance re adiness and control validation.
- Interfacewith:
- External auditors
- Regulators
- Internal audit & compliance
- Coordinate with Finance (cyber insurance), Legal (contracts), HR (insider risk), and IT (oper ations) for cross-functional risk management.
8. Network Security & Advanced Threat
- DefenseDrive deep technical capabilities for:
- Network detection & response
- Packet inspection and protocol analysis
- Network forensics and traffic mo nitoring
- Strengthen perimeter, internal segmentation, and east-west traffic visibility.
10. Program Governance & Multi-Vendor
- AssuranceLead complex, multi-vendor security programs under stringent timelines and regulatory expectations
- Drive:Requirements decomposition
- Interface control
- V&V; strategy
- Multi-vendor / third-party risk management
11. Team Build-out & Leadership
- Build, lead, and scale a global, multi-disciplinary internal cybersec urity team across:
- MCDC / SOC
- operationsDFIR and threat hunting
- Security engineering & architecture
- GRC, compliance & AI governance
- Establish a high-performance, risk-awa re culture with continuous capability building (certifications, red/blue/purple teaming, SOC & forensic automation).
Required
- Experience20+ years of leadership across enterprise cybersecurity operations, risk & compliance, AI-powered security platforms, digital forensics, and critical-infrastructure
- protection. Proven experience in building and leading internal Global SOC / Cyber Defense Center c apabilities — operating model, tooling, team, and processes.
- Solid background in GRC & control
- assurance. Demonstrated experience in AI-first security platforms and AI governance (ISO 42001, AI RMF).
- Hands-on background in network security, traffic monitoring, and networ k forensics.
- Experience with risk data aggregation and executive reporting inf rastructure at large enterprise scale.
- Exposure to safety-critical, regulated e nvironments (defense, aerospace, BFSI) with multi-vendor program governance.
Preferred Education & Credentials
- M.Tech in Computer Science/ AI or equivalent
- Professional development in:
- Product Ownership
- ISO 27001 — Information Security Management
- ISO 42001 — AI Management Systems
📌 VP - Internal Cyber Security Defence (India)
🏢 Spot Your Leaders u0026 Consulting
📍 India