02 Sep
|
Yokohama-ATG
|
Mumbai
02 Sep
Yokohama-ATG
Mumbai
SECTION I. BASIC INFORMATION
Job Title
IT Security Director
Location
ITA – Tivoli
IND - Mumbai
Entity
Yokohama TWS S.p.A.
Reporting to
Head of IT
Division
IT
Direct Reports (Nos)
1 - 3
Department
IT
Team Size (Nos)
2–4
Unique Job Code
(To be filled by HR)
SECTION II. PURPOSE OF THE ROLE
This role is responsible for defining and leading the enterprise information security strategy of the Organization, establishing the framework for information security management and ensuring that the impact and occurrence of information security incidents remain within the business’ risk appetite. As the senior accountable owner for cyber and IT risk (CISO-level role), the IT Security Director continually identifies, assesses and reduces IT-related risk within the tolerance levels set by the business; manages the protection of enterprise information; establishes information security roles and access privileges; and designs and oversees the security monitoring, incident response, business continuity, backup and recovery, eDiscovery and forensics capabilities across all entities and countries in scope.
SECTION III.
Key Result
Areas
- Security Strategy & Governance
- Develop, implement and monitor a strategic, comprehensive enterprise information security and IT risk management program
- Define and maintain the information security management framework, policies and standards in line with ISO/IEC 27001 and NIST, and ensure their consistent application across all technology projects, systems and services
- Establish information security roles, responsibilities and access privileges, and provide leadership to the enterprise’s information security organization
- Manage and report on the security posture to executive leadership and governance committees, keeping residual risk within the defined risk appetite
- Risk Management & Business Alignment
- Work directly with the business units to facilitate risk assessment and risk management processes, and continually identify, assess and reduce IT-related risk within agreed tolerance levels
- Partner with business stakeholders across the company to raise awareness of risk management concerns and embed a security-by-design culture.
- Ensure information security is embedded in Business Continuity Management (BCM), and define the policies for backup, recovery, eDiscovery and forensics.
- Manage contract and vendor negotiations and oversight for security-related managed services, ensuring compliance with applicable regulations (e.g. GDPR) across all countries in scope
- Security Operations, Incident Response & Innovation
- Define and manage security monitoring to minimize the business impact of operational information security vulnerabilities and incidents, and design and manage the implementation of security management practices to effectively respond to security incidents.
- Educate the business in the adoption of security best practices and emerging technologies, monitoring the threat landscape and industry/process best practices and driving their execution .
- Assist with overall business technology planning, providing current knowledge and a future vision of security technology and systems, and driving a security-aware culture within the organization
SECTION IV. Key Interactions
Internal Interactions
Party Interacting With Main Purpose of Interaction / Details
Frequency (Put a √)
Occasional
Frequent
Continuous
Business Unit Leaders / IT Teams / IT Business Partners / Process & Data Owners / Internal Audit / Legal & Compliance / DPO
Facilitating risk assessment and risk management processes, aligning the security strategy and roadmap with business priorities, ensuring consistent application of security policies and standards across projects, raising risk awareness, and coordinating incident response, BCM, data protection and compliance activities
√
External Interactions
Solution Partners
Keeping abreast of developments, functionality enhancements, technology architecture, licensing and deployment models in the cyber security solution space
√
Solution Implementation Partners
Engagements for Project / Solution Delivery, Keep track of the capability / current track record of Solution Implementation Partners, Maintaining a connect with the Solution Implementation Partners Ecosystem
√
Managed Security Service Providers (MSSP) / SOC Partners
Smooth functioning of monitoring,
detection and response engagements; periodic service review and SLA management
√
SMEs
Obtain expert opinion / threat intelligence / knowledge / support on specialized security topics; engage with regulators, auditors and CERT/industry bodies as needed
√
Knowledge, Skills And Experiences
Competencies
Educational Background
- Mandatory: MBA or degree in Business Administration / Computer Science / a technology-related field
- Preferred: Qualified security management certification (e.g. CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor)
Functional/ Technical Competencies
- Solid knowledge of information security management frameworks such as ISO/IEC 27001 and NIST
- Experience in risk management, security architecture, identity & access management, security monitoring (SIEM/SOC) and incident response
- Understanding of data protection / privacy regulations (GDPR) and of BCM, backup & recovery, eDiscovery and forensics
- Experience with contract and vendor negotiations and management, including managed security services
- Policy and security documentation skills
- Strong project management / delivery management skills; advanced use of MS Office tools
Behavioral/ Managerial Competencies
- Strong Change Management Skills
- Stake Holder Management
- Budget Management & Execution Skills
- Excellent Communication /Collaboration Skills
- Problem Solving
- Leadership capability: ability to lead and motivate cross-functional, interdisciplinary teams
- Fluent in English; high level of personal integrity; ability to manage complexity and work under pressure; willing to travel across plant/country locations as per need
Work Experience
- Minimum 5 to 12 years in a combination of risk management and information security
- Experience leading an information security function / CISO-level responsibilities in a multi-country enterprise will be preferred
Other Skills Budgeted Compensation (To be Filled by HR) ANNEXURE – I
Our Values
Customer Centricity
Actively developing & deploying ‘solutions’ which serve customer needs and alleviate their pain points
Integrity
Doing what you say you will do and doing what is right
Entrepreneurship
Taking accountability and driving results as an owner.
Taking initiative
Freedom to operate and take risks
Humility
Being courteous, modest and respectful towards everyone we interact with
📌 Information Technology-Security (Mumbai)
🏢 Yokohama-ATG
📍 Mumbai