Roles and Responsibilities :
- Define and own the enterprise group cybersecurity roadmap, aligning security initiatives with business priorities, digital transformation programs, and risk management objectives.
- Lead technical risk assessments to identify, prioritize & mitigate Infosec risks by driving actionable technology-driven solutions.
- Should be a trusted technical advisor to senior leadership on cybersecurity posture, technology risks, and strategic trade-offs.
- Lead technical risk assessments to identify, prioritize, and mitigate cybersecurity risks in line with organizational risk tolerance.
- Architect and govern the implementation of enterprise-wide security architectures, covering applications security including security of software stack, SBOM monitoring, source code repository, network, endpoint, identity, and cloud, by defining governing principles for security architecture.
- Ensure security-by-design principles into enterprise governance processes.
- Enterprise Software Security: Lead the governance and enterprise-wide security architectures,
ensuring security-by-design principles are embedded across applications, platforms, cloud services, and technology infrastructure.
- Own the application security program, including secure software development practices, source code repository security, software supply chain riskmanagement, and Software Bill of Materials (SBOM) monitoring to identify, assess, and remediate vulnerabilities and third-party component risks.
- Establish security standards, controls, and assurance processes to safeguard the software stack throughout its lifecycle while ensuring compliance with organizational policies, regulatory requirements, and industry best practices.
- Threat monitoring & analysis: Monitor SIEM detections, EDR/XDR alerts, and cloud security posture signals; triage, investigate, and document incidents using NIST incident response recommendations (SP 800-61 Rev. 3); map detections and playbooks to MITRE ATT&CK;®
📌 infosec Manager (Mumbai)
🏢 ICRA
📍 Mumbai