14 Sep
|
Senvion India
|
Mumbai
14 Sep
Senvion India
Mumbai
Job Description
Key Responsibilities
n
Cyber Security Operations & Governance
n
n
- Lead and manage enterprise cyber security operations across on-premises infrastructure, cloud platforms, applications, and end-user environments.
n
- Define and implement cyber security strategies, policies, standards, and operational procedures aligned with business objectives.
n
- Ensure adherence to security governance frameworks including NIST, ISO 27001, MITRE ATT&CK;®, COBIT, ITIL, and other industry best practices
n
- Drive continuous improvement initiatives to enhance organizational cyber resilience and security maturity.
n
n
Security Incident Response
n
n
- Lead cyber security incident detection, analysis, containment, eradication, recovery, and post-incident review activities.
n
- Develop, maintain, and periodically test incident response plans, runbooks, and playbooks.
n
- Coordinate with business stakeholders, IT teams, MSSPs, and external partners during security incidents.
n
- Ensure timely reporting, escalation, and communication of security incidents according to defined escalation matrices.
n
- Conduct root cause analysis and implement preventive controls to reduce recurrence of security incidents.
n
n
Vulnerability Management & Security Assurance
n
n
- Own and manage enterprise vulnerability management programs across infrastructure, applications, cloud platforms, and endpoints.
n
- Conduct and oversee Vulnerability Assessment and Penetration Testing (VAPT) activities.
n
- Drive operating system, infrastructure, and application patch management programs.
n
- Prioritize remediation activities based on business impact and risk exposure.
n
- Validate security fixes and remediation effectiveness through regular assessments and reviews.
n
- Identify security weaknesses and recommend risk mitigation strategies.
n
n
Risk Management, Compliance & Audits
n
n
- Conduct enterprise security risk assessments and security reviews.
n
- Ensure compliance with regulatory, legal, and internal security requirements.
n
- Support internal audits, external audits, customer audits, and certification activities for ISO 27001:2022.
n
- Establish and maintain security controls to protect organizational assets and sensitive information.
n
- Develop security metrics, dashboards, and executive-level reporting.
n
n
Risk Management, Compliance & Audits
n
n
- Conduct enterprise security risk assessments and security reviews.
n
- Ensure compliance with regulatory, legal, and internal security requirements viz CERT in, CEA,PDP, ISO 27001 etc
n
- Support internal audits, external audits, customer audits, and certification activities for ISO 27001:2022.
n
- Establish and maintain security controls to protect organizational assets and sensitive information.
n
- Develop security metrics, dashboards, and executive-level reporting.
n
n
Vendor, Partner & Service Management
n
n
- Manage MSSPs, OEMs, consultants, and technology partners.
n
- Establish and govern security service delivery processes, SLAs, SLOs, and performance metrics.
n
- Conduct regular service reviews and ensure contractual compliance.
n
n
Drive partner accountability for security deliverables and operational effectiveness.
n
Certifications preferred:
n
n
- CISSP
n
- CISM
n
n
Qualification
n
BSC /BE with 8 +Years of experience
📌 Information Technology Security Specialist (Mumbai)
🏢 Senvion India
📍 Mumbai