Head of Cyber Security, AI & Information Governance (Vadodara)

Head of Cyber Security, AI & Information Governance (Vadodara)

20 Aug
|
Goodcare It Management Services
|
Vadodara

20 Aug

Goodcare It Management Services

Vadodara

About the Role

Goodcare IT is seeking an experienced, strategic and technically accomplished Head of Cyber Security & AI Security to lead the organization's global cyber security program across our operations in the United Kingdom, Europe, the Netherlands, and India.

Based within our Vadodara office, this is a senior leadership role responsible for developing and delivering the organization's cyber security strategy, ensuring that security is embedded across our technology platforms, software development, infrastructure, AI initiatives and healthcare operations.

The successful candidate will combine strategic leadership with deep technical expertise, enabling them to advise executive leadership, develop security roadmaps, oversee technical security controls and ensure compliance with international information security standards.

This individual will play a key role in supporting our continued growth as a regulated digital healthcare provider and technology organisation.

Key Responsibilities

Cyber Security Strategy & Leadership

- Develop and own the organisation's Cyber Security and AI Security Strategy..
- Produce and maintain a rolling 3-5 year cyber security roadmap aligned to business objectives..
- Present cyber security risks, investment proposals and strategic updates to Executive Leadership..
- Build a security-first culture across all business functions..
- Ensure cyber security supports business innovation whilst maintaining regulatory compliance..
- Lead cyber security governance across multiple international jurisdictions..

Governance, Risk & Compliance Lead and continually improve our Information Security Management System (ISMS), ensuring compliance with recognized industry standards and healthcare regulations, including:

- ISO 27001.
- ISO 27701.
- ISO 42001 (Artificial Intelligence Management Systems).
- NIST Cybersecurity Framework.
- Cyber Essentials Plus.
- GDPR & UK GDPR.
- NEN 7510.
- DCB0129 Clinical Risk Management.
- HIPAA (desirable).
- DORA (desirable).

The successful candidate will be responsible for:

- Leading internal compliance programes..
- Preparing the organization for external audits and certification..
- Supporting and maintaining our annual NEN 7510 self-assessment, ensuring appropriate evidence, policies and technical controls are maintained..
- Working closely with operational, technical and clinical teams to support compliance with DCB0129, ensuring that clinical safety risks associated with digital health technologies are appropriately identified,



assessed, mitigated and documented..
- Developing risk registers and treatment plans..
- Managing third-party supplier assurance and security reviews..

Technical Security Leadership

Provide technical leadership across:

- Microsoft Azure Security.
- Microsoft 365 Security.
- Cloud Security Architecture.
- Identity & Access Management (IAM).
- Zero Trust Architecture.
- Network Security.
- Endpoint Security.
- SIEM & Security Monitoring.
- Vulnerability Management.
- Penetration Testing.
- Secure Software Development Lifecycle (SSDLC).
- DevSecOps.
- Incident Response.
- Business Continuity & Disaster Recovery.
- Security Architecture Reviews.

The successful candidate will work closely with software engineering teams to ensure secure-by-design principles are embedded within all products and services. AI Security & Emerging Technologies

Lead the organisation's AI Security programme by:

- Developing AI governance policies and standards..
- Conducting AI security risk assessments..
- Supporting the secure adoption of Large Language Models (LLMs) and AI technologies..
- Understanding the capabilities, opportunities and security implications of frontier AI models, including Anthropic's Mythos-class models and comparable enterprise AI systems..
- Advising on AI model governance, prompt security, data protection, model risk and emerging AI threats..
- Supporting responsible AI adoption across the organisation..

Security Operations
- Lead cyber incident response activities..
- Oversee vulnerability management..
- Manage external penetration testing programmes..
- Develop security metrics and executive dashboards..
- Conduct cyber resilience and disaster recovery exercises..
- Improve organisational cyber maturity..
- Develop policies, standards and security procedures..
- Oversee third-party cyber security assessments..

Leadership
- Build, mentor and develop the cyber security function..
- Work collaboratively with Product, Engineering, Clinical, Compliance and Infrastructure teams..
- Manage external cyber security suppliers and consultants..
- Provide technical guidance to senior stakeholders..




- Promote continuous improvement across all security disciplines..

Essential Experience
- Minimum 7 years' experience in Information Security or Cyber Security..
- Proven experience developing and implementing enterprise cyber security strategies..
- Strong technical knowledge across cloud, infrastructure and application security..
- Experience working within regulated industries such as healthcare, financial services or technology..
- Experience supporting ISO 27001 certification and ongoing compliance programmes..
- Practical experience supporting or managing NEN 7510 self-assessments and implementing associated security controls..
- Understanding of DCB0129 Clinical Risk Management or equivalent clinical safety governance frameworks within digital healthcare..
- Experience working with executive leadership and presenting cyber security strategy to senior stakeholders..
- Experience managing security programmes across multiple jurisdictions..

Essential Technical Skills
- Microsoft Azure.
- Microsoft Defender.
- Microsoft Sentinel.
- Microsoft Entra ID.
- Identity & Access Management.
- Cloud Security.
- Network Security.
- Security Architecture.
- Vulnerability Management.
- Penetration Testing.
- Security Monitoring.
- Incident Response.
- DevSecOps.
- AI Security.
- Security Automation.

Desirable Certifications
- CISSP.
- CISM.
- CCSP.
- ISO 27001 Lead Implementer.
- ISO 27001 Lead Auditor.
- Microsoft Certified: Azure Security Engineer Associate.
- Certified Cloud Security Qualified (CCSP).
- ISO 42001 Lead Implementer (desirable).
- Certified in Risk and Information Systems Control (CRISC) (desirable).

What Success Looks Like Within the first 12 months, the successful candidate will:
- Develop and implement a comprehensive Cyber Security and AI Security Strategy..
- Produce a multi-year cyber security roadmap..
- Strengthen governance across all international operations..
- Successfully support the organisation's NEN 7510 self-assessment and ongoing compliance activities..
- Embed cyber security controls supporting DCB0129 Clinical Risk Management requirements..
- Improve organisational cyber maturity against recognised frameworks..
- Enhance cloud, infrastructure and application security..
- Establish effective AI governance and security controls..
- Build trusted relationships with senior leadership and technical teams while ensuring security remains a strategic business enabler..

📌 Head of Cyber Security, AI & Information Governance (Vadodara)
🏢 Goodcare It Management Services
📍 Vadodara

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: head of cyber security, ai & information governance (vadodara) / vadodara

Subscribe to this job alert:

Get the latest job offers by email for: head of cyber security, ai & information governance (vadodara) / vadodara