04 Aug
|
Common Service Centres (CSC)
|
Noida
04 Aug
Common Service Centres (CSC)
Noida
About the Role:
The Chief Information Security Officer (CISO) is responsible for providing strategic leadership and direction for the organization's information and cybersecurity program. The role is accountable for safeguarding CSC's information assets, digital infrastructure, applications, and data against evolving cyber threats while ensuring compliance with applicable regulatory, legal, and industry standards.
The CISO will establish and drive the enterprise information security strategy, strengthen cyber resilience, oversee security operations, and foster a security-first culture across the organization. As a key member of the technology leadership team, the CISO will work closely with business leaders, regulators, and external stakeholders to align cybersecurity initiatives with organizational objectives.
Key Responsibilities:
1. Information Security Strategy & Governance
Develop and execute the organization's enterprise information security strategy and roadmap.
Establish and maintain information security governance frameworks, policies, standards, and procedures.
Align cybersecurity initiatives with business objectives and enterprise risk management practices.
Present cybersecurity posture, risk assessments, and strategic recommendations to executive leadership.
2. Cyber Risk Management
Identify, assess, monitor, and mitigate cybersecurity risks across the enterprise.
Lead enterprise-wide risk assessments, vulnerability management, and threat modelling initiatives.
Implement appropriate security controls to reduce business and operational risks.
Oversee third-party, vendor, and supply chain security risk management.
3. Security Operations & Incident Management
Lead Security Operations Centre (SOC) functions, security monitoring, and threat intelligence activities.
Direct cybersecurity incident response, forensic investigations, and breach management.
Ensure timely detection, containment, recovery, and reporting of security incidents.
Drive continuous improvement through post-incident reviews and lessons learned.
4. Compliance, Audit & Regulatory Management
Ensure compliance with applicable information security laws, regulations, and industry standards.
Lead internal and external security audits and certification initiatives.
Coordinate with Legal, Compliance, Privacy, and Audit teams on security governance.
Support regulatory inspections, certifications, and compliance reporting requirements.
5. Security Architecture & Technology
Provide strategic oversight for security architecture across on-premise, cloud, network, and application environments.
Evaluate, recommend, and govern implementation of security technologies and solutions.
Promote secure system design, secure software development (DevSecOps), and Zero Trust security architecture.
Ensure security considerations are integrated into enterprise technology initiatives.
6. Leadership & People Management
Build, mentor, and lead a high-performing information security team.
Define performance objectives, succession planning, and capability development initiatives.
Manage departmental budgets, resource planning, and vendor relationships.
Promote cybersecurity awareness and accountability throughout the organization.
7.
Business Collaboration & Stakeholder Management
Serve as the organization's principal advisor on cybersecurity matters.
Translate technical security risks into business impacts and strategic recommendations.
Collaborate with Technology, Engineering, HR, Legal, Procurement, and Business teams to embed security into business processes.
Lead enterprise-wide security awareness, training, and cyber resilience programs.
Requirements:
1. Educational Qualifications
B.E./B.Tech in Computer Science, Information Technology, Information Security, or related discipline.
MCA/M.Tech or equivalent postgraduate qualification is preferred.
2. Experience
Minimum 12 years of experience in Information Security, Cybersecurity, or IT Risk Management.
At least 5 years in a senior leadership role managing enterprise information security functions.
Demonstrated experience in developing and leading enterprise-wide cybersecurity strategies and security governance programs.
Experience in large enterprises, government organizations, or digital service platforms will be an added advantage.
3. Preferred Certifications
CISSP (Certified Information Systems Security Professional)
CISM (Certified Information Security Manager)
CISA (Certified Information Systems Auditor)
CRISC (Certified in Risk and Information Systems Control)
ISO 27001 Lead Implementer / Lead Auditor
CCSP or other recognized Cloud Security certifications
Perks:
Access to health and wellness initiatives - MEDICIAL INSURANCE for employee is upto 5 Lakh per annum.
Performance-based rewards and recognition programs.
Supportive policies that promote work-life balance.
NPS ( NATIONAL PENSION SYSTEM) for all the employees as per their designations.
📌 Chief Information Security Officer (Noida)
🏢 Common Service Centres (CSC)
📍 Noida