19 Aug
|
HCLTech
|
Chennai
Role: Product Owner - CyberResilience
Location: Noida / Chennai
Role Purpose
Owns the Cyber Resilience portfolio end-to-end — a junior-CISO-calibre profile spanning the full security story (posture, defense, identity, cloud) plus the recovery/resilience differentiator. Fronts CISOs as a peer, and builds, prices and presells the portfolio as builder + presales dual-hat.
Key Responsibilities
- Own the end-to-end roadmap, P&L; input, and go-to-market narrative for all four Cyber Resilience propositions (Posture, Defense, Recovery, Assurance) until deal volume justifies dedicated proposition-level Product Owners.
- Act as lead presales solutioner and CISO-facing voice on cyber resilience pursuits — shaping RFP/bid responses, running technical win themes, and closing recovery- and resilience-heavy deals alongside account teams.
- Define and evolve the portfolio's commercial constructs — service catalogue, tiering, SLAs/service credits, at-risk and resource-unit (RU) pricing — in partnership with finance, legal, and delivery.
- Direct and prioritize the technical pool (Solution Architect and partner delivery teams) against a single backlog, translating deal and audit commitments into build decisions.
- Own the regulatory, audit, and cyber-insurance narrative — DORA/operational-resilience evidence, SOX/PCI/ISO posture, and insurer/underwriter conversations on exposure and recoverability.
- Manage the strategic partner bench (recovery platform vendors, IR retainers, SOC/MDR delivery partners) — sourcing and back-to-back contracting — while building the case for proposition-level splits.
Hard Skills
- Security domain breadth (prevent → detect → respond → recover) — vulnerability/exposure and posture management, SOC/MDR/EDR operating constructs, incident response and DFIR — junior-CISO span across the full lifecycle.
- Security architecture & zero trust — NIST SP 800-207 zero trust, network segmentation/containment design, AD/Entra attack paths and privileged-access design; SASE/SSE awareness.
- Threat & exposure management — CTEM methodology across Tenable One/Qualys/Rapid7-class platforms and CNAPP/CSPM (Wiz, Defender for Cloud); MITRE ATT&CK; literacy.
- Security operations oversight — SIEM/XDR ecosystem fluency (Microsoft Sentinel, Splunk, CrowdStrike/Defender XDR), MDR service constructs, detection-maturity assessment — enough to own the offer without running the SOC.
- Cloud security — securing hybrid multi-cloud estates (Azure/AWS/GCP) — posture, identity and workload protection constructs.
- Cyber recovery & resilience engineering — immutable/air-gapped backup, cleanroom recovery, identity recovery (AD/Entra/Okta); Rubrik/Commvault-class platforms; regulated/bank-grade failover and recovery testing.
- Outcome-based commercial design & productization — SLAs and service credits, at-risk and resource-unit (RU) pricing, unit-cost modelling; service catalogue/tiering, build-vs-partner sourcing, back-to-back contracting.
- Regulatory, frameworks & insurance — NIST CSF 2.0, ISO 27001, DORA/operational resilience, SOX/PCI; cyber-insurance readiness and exposure quantification.
- AI security & credentials — securing AI/agents and AgentOps governance (identity, audit, guardrails); CISSP/CCSP-class credential expectation.
📌 Product Owner - CyberResilience (Chennai)
🏢 HCLTech
📍 Chennai