Information Technology-Security (Mumbai)

Information Technology-Security (Mumbai)

02 Sep
|
Yokohama-ATG
|
Mumbai

02 Sep

Yokohama-ATG

Mumbai

SECTION I. BASIC INFORMATION

Job Title

IT Security Director

Location

ITA – Tivoli

IND - Mumbai

Entity

Yokohama TWS S.p.A.

Reporting to

Head of IT

Division

IT

Direct Reports (Nos)

1 - 3

Department

IT

Team Size (Nos)

2–4

Unique Job Code

(To be filled by HR)

SECTION II. PURPOSE OF THE ROLE

This role is responsible for defining and leading the enterprise information security strategy of the Organization, establishing the framework for information security management and ensuring that the impact and occurrence of information security incidents remain within the business’ risk appetite. As the senior accountable owner for cyber and IT risk (CISO-level role), the IT Security Director continually identifies, assesses and reduces IT-related risk within the tolerance levels set by the business; manages the protection of enterprise information; establishes information security roles and access privileges; and designs and oversees the security monitoring, incident response, business continuity, backup and recovery, eDiscovery and forensics capabilities across all entities and countries in scope.

SECTION III.

Key Result

Areas

- Security Strategy & Governance

- Develop, implement and monitor a strategic, comprehensive enterprise information security and IT risk management program
- Define and maintain the information security management framework, policies and standards in line with ISO/IEC 27001 and NIST, and ensure their consistent application across all technology projects, systems and services
- Establish information security roles, responsibilities and access privileges, and provide leadership to the enterprise’s information security organization
- Manage and report on the security posture to executive leadership and governance committees, keeping residual risk within the defined risk appetite

- Risk Management & Business Alignment

- Work directly with the business units to facilitate risk assessment and risk management processes, and continually identify, assess and reduce IT-related risk within agreed tolerance levels
- Partner with business stakeholders across the company to raise awareness of risk management concerns and embed a security-by-design culture.
- Ensure information security is embedded in Business Continuity Management (BCM), and define the policies for backup, recovery, eDiscovery and forensics.




- Manage contract and vendor negotiations and oversight for security-related managed services, ensuring compliance with applicable regulations (e.g. GDPR) across all countries in scope
- Security Operations, Incident Response & Innovation
- Define and manage security monitoring to minimize the business impact of operational information security vulnerabilities and incidents, and design and manage the implementation of security management practices to effectively respond to security incidents.
- Educate the business in the adoption of security best practices and emerging technologies, monitoring the threat landscape and industry/process best practices and driving their execution .
- Assist with overall business technology planning, providing current knowledge and a future vision of security technology and systems, and driving a security-aware culture within the organization

SECTION IV. Key Interactions

Internal Interactions

Party Interacting With Main Purpose of Interaction / Details

Frequency (Put a √)

Occasional

Frequent

Continuous

Business Unit Leaders / IT Teams / IT Business Partners / Process & Data Owners / Internal Audit / Legal & Compliance / DPO

Facilitating risk assessment and risk management processes, aligning the security strategy and roadmap with business priorities, ensuring consistent application of security policies and standards across projects, raising risk awareness, and coordinating incident response, BCM, data protection and compliance activities



External Interactions

Solution Partners

Keeping abreast of developments, functionality enhancements, technology architecture, licensing and deployment models in the cyber security solution space



Solution Implementation Partners

Engagements for Project / Solution Delivery, Keep track of the capability / current track record of Solution Implementation Partners, Maintaining a connect with the Solution Implementation Partners Ecosystem



Managed Security Service Providers (MSSP) / SOC Partners

Smooth functioning of monitoring,



detection and response engagements; periodic service review and SLA management



SMEs

Obtain expert opinion / threat intelligence / knowledge / support on specialized security topics; engage with regulators, auditors and CERT/industry bodies as needed



Knowledge, Skills And Experiences

Competencies

Educational Background

- Mandatory: MBA or degree in Business Administration / Computer Science / a technology-related field
- Preferred: Qualified security management certification (e.g. CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor)

Functional/ Technical Competencies

- Solid knowledge of information security management frameworks such as ISO/IEC 27001 and NIST
- Experience in risk management, security architecture, identity & access management, security monitoring (SIEM/SOC) and incident response
- Understanding of data protection / privacy regulations (GDPR) and of BCM, backup & recovery, eDiscovery and forensics
- Experience with contract and vendor negotiations and management, including managed security services
- Policy and security documentation skills
- Strong project management / delivery management skills; advanced use of MS Office tools

Behavioral/ Managerial Competencies

- Strong Change Management Skills
- Stake Holder Management
- Budget Management & Execution Skills
- Excellent Communication /Collaboration Skills
- Problem Solving
- Leadership capability: ability to lead and motivate cross-functional, interdisciplinary teams
- Fluent in English; high level of personal integrity; ability to manage complexity and work under pressure; willing to travel across plant/country locations as per need

Work Experience

- Minimum 5 to 12 years in a combination of risk management and information security
- Experience leading an information security function / CISO-level responsibilities in a multi-country enterprise will be preferred

Other Skills Budgeted Compensation (To be Filled by HR) ANNEXURE – I

Our Values

Customer Centricity

Actively developing & deploying ‘solutions’ which serve customer needs and alleviate their pain points

Integrity

Doing what you say you will do and doing what is right

Entrepreneurship

Taking accountability and driving results as an owner.

Taking initiative

Freedom to operate and take risks

Humility

Being courteous, modest and respectful towards everyone we interact with

📌 Information Technology-Security (Mumbai)
🏢 Yokohama-ATG
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: information technology-security (mumbai) / mumbai

Subscribe to this job alert:

Get the latest job offers by email for: information technology-security (mumbai) / mumbai