Director of Cybersecurity (Noida)

Director of Cybersecurity (Noida)

12 Sep
|
Virtual Engineering Services
|
Noida

12 Sep

Virtual Engineering Services

Noida

Role Summary:

- Objective. Establish, maintain, and continuously improve the company's cybersecurity program.

- Mission. Provide organizational leadership for managing cybersecurity risk and protecting company information, software products, cloud services, infrastructure, and customer environments from cybersecurity threats.

- Scope. Maintain enterprise-wide responsibility for cybersecurity risk across multiple security domains, including Corporate IT, Operations and Data; Products and Services; and Third-Party Technologies.

- Authority & Empowerment. Establish cybersecurity requirements and standards that are subsequently implemented and operated as controls by other parts of the organization. These requirements encompass security policies, risk management, security architecture, vulnerability management, incident response, product security, security testing, security awareness, customer security, and compliance/assurance.

Key Responsibility Areas:

1. Cybersecurity Governance and Risk Management

- Establish and maintain the company's cybersecurity strategy, policies, standards, and procedures.

- Maintain the company's NIST CSF Current Profile and Target Profile.

- Identify, assess, and prioritize cybersecurity risks across corporate IT, software products, hosted services and third-party dependencies.

- Maintain the cybersecurity risk register and ensure significant risks have assigned owners and documented remediation or risk-acceptance decisions.

- Establish cybersecurity objectives, metrics, and reporting for executive management.

- Ensure cybersecurity responsibilities and accountability are clearly defined across the organization.

- Advise executive management regarding cybersecurity risks, priorities, and investments.

- Maintain a cybersecurity debt register that records identified security weaknesses, control gaps, deferred remediation, exceptions, and other unresolved cybersecurity risks; prioritize and track these items through remediation or formal risk acceptance (these permeate across all responsibility areas).

1. Product and Software Security

- Establish and maintain secure software-development practices.

- Establish security requirements for desktop applications, cloud applications, APIs, and hosted services.

- Participate in security reviews of product architecture and significant product changes.

- Establish requirements for authentication, authorization, encryption, secrets management and secure communications.

- Oversee application-security testing, vulnerability assessment, and penetration testing.





- Establish processes for identifying and remediating vulnerabilities in third-party components and software dependencies.

- Establish software supply-chain security practices.

- Establish vulnerability disclosure and remediation processes.

- Participate in security-related release decisions for products and hosted services.

- Partner with Development and Product Leadership to incorporate security throughout the software-development lifecycle.

1. Infrastructure and IT Security

- Establish security requirements for corporate networks, endpoints, servers, cloud infrastructure, and internal systems.

- Establish requirements for identity and access management, including MFA and privileged-access management.

- Establish security requirements for remote access and administrative access.

- Establish vulnerability-management standards and remediation requirements.

- Establish requirements for backup, recovery, and disaster-recovery controls.

- Work with IT to ensure appropriate security controls are implemented and maintained.

- Periodically assess the effectiveness of IT security controls.

- Monitor security risks associated with significant infrastructure changes.

1. Security Monitoring and Incident Response

- Establish and maintain security monitoring and logging requirements.

- Define security event severity classifications and escalation criteria.

- Establish procedures for identifying, analyzing, and responding to suspected security incidents.

- Maintain the company's cybersecurity incident-response plan.

- Coordinate investigation, containment, eradication, and recovery activities.

- Coordinate with external forensic, legal, insurance and other specialists when required.

- Establish procedures for preserving appropriate evidence.

- Conduct post-incident reviews and ensure corrective actions are implemented.

- Conduct periodic incident-response exercises and tabletop exercises.

1. Security Awareness and Employee Practices

- Establish and maintain cybersecurity awareness and training programs.

- Educate employees regarding phishing, social engineering, credential protection, and appropriate use of company resources.

- Establish security requirements for employee onboarding, role changes, and termination.





- Establish security requirements for access provisioning and deprovisioning.

- Periodically assess employee cybersecurity awareness.

- Promote a culture in which cybersecurity responsibilities are understood throughout the organization.

1. Third-Party and Customer Security

- Establish and maintain a third-party cybersecurity risk-management program.

- Identify and risk-classify critical technology suppliers and service providers.

- Establish appropriate security requirements for critical vendors.

- Conduct or coordinate security assessments of critical third parties.

- Support customer and OEM cybersecurity assessments.

- Respond to customer security questionnaires and information requests.

- Provide appropriate security documentation and evidence to customers.

- Coordinate cybersecurity requirements associated with customer contracts.

- Support cybersecurity insurance assessments and requirements.

- Establish procedures for addressing cybersecurity incidents involving critical third parties or customer environments.

1. Compliance and Assurance

- Establish a cybersecurity assurance program appropriate to the company's size, products, services and customer requirements.

- Maintain alignment with applicable cybersecurity frameworks and contractual requirements.

- Coordinate penetration testing, vulnerability assessments and other independent security assessments.

- Track findings and ensure remediation.

- Maintain cybersecurity policies, procedures and evidence required for audits and customer assessments.

- Support cyber-insurance requirements and assessments.

- Coordinate preparation for security certifications or attestations when authorized by management.

- Periodically assess the effectiveness of the cybersecurity program against the NIST CSF Target Profile.

1. Security Leadership

- Serve as the company's senior cybersecurity subject-matter expert.

- Establish cybersecurity priorities based upon business risk.

- Advise the Managing Director and other senior leaders regarding cybersecurity risk.

- Coordinate cybersecurity activities across IT, Development, Product Management, Operations, HR, and other functions.

- Establish cybersecurity budgets and resource requirements.

- Manage external cybersecurity consultants, penetration testers, managed security providers, and other security vendors.

- Develop the cybersecurity function as the company grows.

- Establish cybersecurity metrics and report program performance to management.

- Promote a practical, risk-based cybersecurity culture throughout the organisation.

📌 Director of Cybersecurity (Noida)
🏢 Virtual Engineering Services
📍 Noida

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: director of cybersecurity (noida) / noida

Subscribe to this job alert:

Get the latest job offers by email for: director of cybersecurity (noida) / noida