06 Aug
|
Adani Group
|
Ahmedabad
06 Aug
Adani Group
Ahmedabad
Purpose/Objective The BU CISO is a senior leadership role responsible for overseeing the cybersecurity posture, strategy, and risk management within a specific business unit (BU) of the organization.
This role will ensure that cybersecurity initiatives are aligned with the strategic goals of the business unit, while maintaining overall compliance with corporate security standards, policies, and regulatory requirements.
The BU CISO will work closely with business unit leaders, IT, legal, and compliance teams to create and implement robust cybersecurity frameworks, address emerging risks, and safeguard the organization’s critical assets.
Key Responsibilities of Role
BU CISO Cybersecurity Strategy and Governance: Develop, implement, and lead the cybersecurity strategy for the assigned business unit, ensuring alignment with organizational goals group cyber security strategy and industry best practices.
Establish and enforce cybersecurity policies, procedures, and governance frameworks specific to the business unit.
Ensure cybersecurity initiatives are in compliance with applicable regulatory frameworks and internal standards (e.
g.
, GDPR, ISO 27001, NIST, etc.
).
Ensure business level cyber security KPIs are achieved and maintained.
Risk Management and Threat Assessment: Lead the identification, assessment, and management of cybersecurity risks within the business unit, prioritizing mitigation strategies based on business impact.
Conduct regular risk assessments and threat modeling exercises to identify vulnerabilities and threats relevant to the business unit.
Collaborate with other business units and teams to ensure a holistic approach to risk management across the organization.
Minimize the cybersecurity exceptions at business level.
Cybersecurity Operations: Oversee the day-to-day cybersecurity operations within the business unit, ensuring that security controls are effectively implemented and maintained.
Ensure timely detection, response, and resolution of security incidents, working closely with the SOC (Security Operations Center) and incident response teams.
Manage the security incident management lifecycle, including investigation, root cause analysis, and remediation efforts.
Collaboration with Business Leaders:
Collaborate with senior leadership and business unit managers to understand business goals and ensure that cybersecurity investments and strategies support those objectives.
Act as the primary point of contact for cybersecurity matters within the business unit, providing expert advice and guidance to business unit stakeholders.
Ensure cybersecurity risks and priorities are effectively communicated and understood at the business unit leadership level.
Cybersecurity Awareness and Training: Lead initiatives to enhance cybersecurity awareness and build a culture of security within the business unit, including organizing training and awareness programs.
Work with Group Awareness and BU HR teams to develop cybersecurity training programs tailored to the specific needs of the business unit.
Promote secure behavior across teams by fostering positive security hygiene practices and continuous education.
Security Architecture and Design: Collaborate with the architecture and engineering teams to ensure that cybersecurity is integrated into the design and architecture of business unit systems, applications, and infrastructure.
Review and approve security architecture for projects, ensuring that secure coding, encryption, and other security best practices are followed.
Incident Response and Crisis Management: Lead the business unit’s response to cybersecurity incidents, ensuring timely coordination and escalation to executive leadership when necessary.
Develop and maintain incident response plans and disaster recovery protocols specific to the business unit, ensuring they align with the organization’s overall plans.
Conduct tabletop exercises and incident simulations to improve readiness and response capabilities.
Metrics and Reporting: Develop and track key performance indicators (KPIs) to measure the effectiveness of the business unit's cybersecurity efforts.
Provide regular reports to senior leadership on the status of cybersecurity activities, risks,
and incidents within the business unit.
Utilize data and metrics to continuously improve security processes and identify areas for improvement.
Third-Party Risk Management: Oversee the security posture of third-party vendors and partners that interact with the business unit, ensuring that they comply with organizational security standards.
Conduct regular assessments of third-party risks, including vendor assessments, contract negotiations, and due diligence processes.
Budgeting and Resource Management: Manage the cybersecurity budget for the business unit, ensuring that investments are aligned with priority risks and initiatives.
Identify resource needs and lead recruitment and retention efforts to build and maintain a high-performing cybersecurity team within the business unit.
Key Stakeholders - Internal Executive Leadership Department Heads Legal and Compliance IT Team Risk Management Team Security Awareness and Training Teams Incident Response Team Procurement and Vendor Management Teams Internal Security and Penetration Testing Teams Engineering and Development Teams Key Stakeholders - External Cloud Service Providers Consultants and Industry Experts Regulatory Bodies and Compliance Authorities External Auditors Managed Security Service Providers (MSSPs) Industry Associations and Cybersecurity Forums
Technical Competencies
Cybersecurity Governance & Compliance-CYS,Data Protection & Data Loss Prevention-CYS,Network Security & Perimeter Defense-CYS,Operational Technology & Industrial Control System Security-CYS,Research and Innovation-CYS,Risk Management & Threat Modelling-CYS,Security Assessment and Testing-CYS,Security Engineering & Architecture-CYS,Security Operations & Incident Response Management-CYS
Qualifications and Experience
Educational Qualification: Minimum Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
Advanced degree (e.
g.
, Master's, MBA) in Cybersecurity, Information Assurance, or a relevant discipline is highly desirable.
.
Certification: Relevant certifications such as CISSP, CISM, CISA, CISA, or ISO 27001 Lead Implementer are highly desirable.
Work Experience (Range of years): Minimum 10 years of experience in cybersecurity.
📌 Chief Information Security Officer - Cyber Security (Ahmedabad)
🏢 Adani Group
📍 Ahmedabad