27 Aug
|
Reliance Industries (RIL)
|
Bengaluru
27 Aug
Reliance Industries (RIL)
Bengaluru
Role & responsibilities
About the Role
Operating at scale across beverages, staples, dairy, and personal care. Our IT landscape spans a rapidly scaling SAP S/4HANA programme, Databricks lakehouse, cloud-native SaaS platforms, Mendix low-code apps, Conversational AI, CRM, WMS, TMS, and a distributed network of plant and distribution centre endpoints.
As IT Cybersecurity Lead, will own and operationalise RCPL's enterprise IT security posture covering network and cloud security, endpoint protection, identity and access management, data security, application security for SAP and SaaS platforms, and governance. This role will lead the security operations function, manage the relationship with external security partners, and ensure full compliance with India's DPDP Act 2023, ISO 27001, and Reliance Group security standards. This role is a peer to the OT Cybersecurity Lead and together the two roles form unified cyber defence function.
Key Responsibilities
1. Security Architecture & Infrastructure
- Design, implement, and continuously mature enterprise IT security architecture covering on-premise, cloud , and hybrid environments.
- Own network security: firewall rule management, micro-segmentation, zero-trust network access (ZTNA), and secure remote access for corporate and plant users.
- Define and enforce endpoint security standards across corporate laptops, plant workstations, and mobile devices including EDR/XDR deployment and management.
- Lead cloud security posture management (CSPM) across all cloud workloads, including Databricks, SaaS platforms, and future AI infrastructure.
2. Identity & Access Management (IAM)
- Own enterprise IAM strategy: Active Directory, Azure AD / Entra ID, SSO, MFA, and privileged access management (PAM) across SAP, cloud, and SaaS platforms.
- Enforce least-privilege access principles, role-based access controls (RBAC), and periodic access certifications across all enterprise systems.
- Define and implement secure identity governance for external users vendors, contractors, distributors, and third-party integrators accessing systems.
- Partner with SAP programme team to ensure SAP GRC (Governance, Risk & Compliance) implementation covers SoD controls, role design, and audit readiness.
3. Application & Data Security
- Embed security into the SDLC for Mendix applications, API integrations, and custom development including SAST/DAST practices and security code review.
- Lead data classification and data loss prevention (DLP)
initiatives aligned with Data Protection and Privacy Policy and India's DPDP Act 2023.
- Ensure secure data handling across the Databricks lakehouse: encryption at rest and in transit, column-level security, and audit logging for sensitive datasets.
- Oversee security assessments for third-party SaaS applications including CRM, Conversational AI platforms, DMS, SFA, and logistics platforms (Shipsy, Haptik etc).
4. Security Operations & Incident Response
- Build and manage RCPL's Security Operations capability either in-house, via MSSP, or a hybrid model — covering SIEM, log management, and threat detection.
- Develop and own the IT Incident Response Plan; lead security incident handling, root cause analysis, and post-incident reviews.
- Manage vulnerability management lifecycle: regular scanning, prioritised remediation, patch compliance tracking, and executive reporting.
- Coordinate threat intelligence, red team / penetration testing programmes, and phishing simulation campaigns.
5. Compliance, Governance & Risk Management
- Own ISO 27001 compliance programme — including ISMS scope, risk register, controls implementation, internal audits, and certification roadmap.
- Lead RCPL's compliance with India's DPDP Act 2023: data inventory, consent management, breach notification procedures, and DPDP readiness assessments.
- Maintain and mature IT Governance Policy and Data Protection Policy, benchmarked against NIST CSF, ISO 27001, and Reliance Group standards.
- Report security posture, KPIs, and risk status to the Chief Digital Officer, CISO, and leadership forums on a regular cadence.
6. Vendor & Stakeholder Management
- Manage IT security technology vendors, MSSPs, and audit partners — including contract governance, SLA management, and performance reviews.
- Conduct third-party vendor security assessments (TPRM) for all significant technology and data-handling vendors onboarded.
- Partner with risk advisory, infrastructure teams, and external auditors on security reviews, compliance assessments, and programme delivery.
- Build security awareness culture across through training programmes, phishing simulations, and policy communication.
Key Interfaces
Internal
- Chief Digital Officer
- OT Cybersecurity Lead (peer — joint cyber defense function)
- SAP Programme Team
- Databricks / Data Engineering Team
- Infrastructure & Network Team
- Mendix / Application Development Teams
- Finance, Legal, and Compliance Teams
- Digital PMO
External
- Risk Advisory and IT Governance
- IT Security Technology Vendors and MSSPs
- SAP GRC Implementation Partners
- External Auditors and Certification Bodies (ISO 27001)
- SaaS and Cloud Platform Vendors (Microsoft, Databricks, CRM/AI vendors)
Preferred candidate profile Required Qualifications & Experience
A. Education
- B.E. / B.Tech in Computer Science, Information Technology, or related discipline.
- Postgraduate qualification (M.Tech / MBA in IT / Information Security) preferred.
B. Experience
- 8–12 years of total experience, with a minimum of 5 years in enterprise IT security roles.
- Demonstrated experience in FMCG, retail, or consumer goods environments with complex IT landscapes including SAP, cloud platforms, and SaaS ecosystems.
- Hands-on experience managing or implementing ISO 27001 ISMS and DPDP / data protection compliance programmes.
- Prior ownership of security operations, incident response, and vulnerability management programmes at scale.
- Experience working alongside SAP programme teams on security design, SAP GRC, and role-based access controls is a significant advantage.
Technical Skills
- Deep knowledge of enterprise security frameworks: ISO 27001, NIST CSF, CIS Controls.
- Proficiency in cloud security — CSPM, identity federation, workload protection, and SaaS security configuration.
- Solid IAM expertise: Active Directory, Azure Entra ID, PAM tools (CyberArk, BeyondTrust, or equivalent), SSO/MFA platforms.
- Working knowledge of SIEM platforms (Sentinel, Splunk, or equivalent), EDR/XDR tools, DLP, and vulnerability management platforms.
- Understanding of application security practices: OWASP Top 10, API security, SAST/DAST tooling.
- Familiarity with SAP security concepts (GRC, role design, SoD) is preferred.
C. Certifications (Preferred)
- CISM (Certified Information Security Manager) — highly preferred
- CISSP (Certified Information Systems Security Professional)
- ISO 27001 Lead Implementer or Lead Auditor
- CCSP (Certified Cloud Security Professional) or equivalent cloud security certification
CEH, OSCP, or equivalent offensive security certification is an advantage
📌 IT - Cybersecurity Lead (Bengaluru)
🏢 Reliance Industries (RIL)
📍 Bengaluru