Job Description
Product Owner - CyberResilience Location : Noida /Chennai Role Purpose Owns the Cyber Resilience portfolio end-to-end — a junior-CISO-calibre profile spanning the full security story (posture, defense, identity, cloud) plus the recovery/resilience differentiator. Fronts CISOs as a peer, and builds, prices and presells the portfolio as builder + presales dual-hat. Key Responsibilities - Own the end-to-end roadmap, P&L; input, and go-to-market narrative for all four Cyber Resilience propositions (Posture, Defense, Recovery, Assurance) until deal volume justifies dedicated proposition-level Product Owners. - Act as lead presales solutioner and CISO-facing voice on cyber resilience pursuits — shaping RFP/bid responses, running technical win themes, and closing recovery- and resilience-heavy deals alongside account teams. - Define and evolve the portfolio's commercial constructs — service catalogue, tiering, SLAs/service credits, at-risk and resource-unit (RU) pricing — in partnership with finance, legal, and delivery. - Direct and prioritize the technical pool (Solution Architect and partner delivery teams) against a single backlog, translating deal and audit commitments into build decisions. - Own the regulatory, audit, and cyber-insurance narrative — DORA/operational-resilience evidence, SOX/PCI/ISO posture, and insurer/underwriter conversations on exposure and recoverability. - Manage the strategic partner bench (recovery platform vendors, IR retainers, SOC/MDR delivery partners) — sourcing and back-to-back contracting — while building the case for proposition-level splits.
Hard Skills - Security domain breadth (prevent → detect → respond → recover) — vulnerability/exposure and posture management, SOC/MDR/EDR operating constructs, incident response and DFIR — junior-CISO span across the full lifecycle. - Security architecture & zero trust — NIST SP 800-207 zero trust, network segmentation/containment design, AD/Entra attack paths and privileged-access design; SASE/SSE awareness. - Threat & exposure management — CTEM methodology across Tenable One/Qualys/Rapid7-class platforms and CNAPP/CSPM (Wiz, Defender for Cloud); MITRE ATT&CK; literacy. - Security operations oversight — SIEM/XDR ecosystem fluency (Microsoft Sentinel, Splunk, CrowdStrike/Defender XDR), MDR service constructs, detection-maturity assessment — enough to own the offer without running the SOC. - Cloud security — securing hybrid multi-cloud estates (Azure/AWS/GCP) — posture, identity and workload protection constructs. - Cyber recovery & resilience engineering — immutable/air-gapped backup, cleanroom recovery, identity recovery (AD/Entra/Okta); Rubrik/Commvault-class platforms; regulated/bank-grade failover and recovery testing. - Outcome-based commercial design & productization — SLAs and service credits, at-risk and resource-unit (RU) pricing, unit-cost modelling; service catalogue/tiering, build-vs-partner sourcing, back-to-back contracting. - Regulatory, frameworks & insurance — NIST CSF 2.0, ISO 27001, DORA/operational resilience, SOX/PCI; cyber-insurance readiness and exposure quantification. - AI security & credentials — securing AI/agents and AgentOps governance (identity, audit, guardrails); CISSP/CCSP-class credential expectation.
📌 Cyber Resilience - Product Owner (Noida)
🏢 HCLTech
📍 Noida