22 Sep
|
Tata Communications
|
Chennai
22 Sep
Tata Communications
Chennai
Job Summary
Accountable for managing the secured development, deployment, operations and lifecycle management for internal and external applications, AI platforms and projects as well as public and private cloud infrastructure across the organisation and al subsidiaries. Secure-by-design, DevSecOps transformation, AI model governance, and cloud security architecture across hybrid and multi-cloud environments.
- Build security domain capability
- Influence CoE, product and engineering functional leadership
- Drive security culture in development teams
Application security
Define and implement enterprise application security strategy across all digital products and services. Collaborate with business and technology stakeholders to maintain ongoing security governance and address security risks associated with applications and digital platforms to provide security assurance for customer facing application platforms/services.
- Embed secure SDLC (SSDLC) practices across engineering teams.
- Establish DevSecOps frameworks integrated with CI/CD pipelines.
- Oversee:
- SAST
- DAST
- SCA
- API security
- Mobile application security
- Container and microservices security
Cloud Security
Lead security for multi-cloud and hybrid cloud environments including AWS, GCP, Azure as well as private cloud services
Define and implement enterprise cloud security strategy across all digital products and platforms. Collaborate with business and technology stakeholders to maintain ongoing security governance and address security risks associated with cloud infrastructure and automation.
- Cloud security architecture and guardrails
- CSPM and CNAPP governance
- Identity and access security for cloud workloads
- Cloud-native security monitoring
- Container and Kubernetes security
- Serverless security
- Data security in cloud environments
AI Security and Governance
Develop enterprise framework for AI and ML security and risk management including,
- AI model security
- Protection against model theft and poisoning
- Secure training data pipelines
- Responsible AI governance
- Adversarial AI threat mitigation
- AI risk assessment and regulatory compliance
Establish AI security standards aligned with emerging frameworks such as: NIST AI RMF, ISO 42001, Responsible AI guidelines
Governance and Operational Responsibilities
Lead implementation of DevSecOps at scaleincluding:
- Security testing automation in CI/CD pipelines
- Container image security
- Software integrity and artifact signing
- Open-source software dependencies
- Threat modelling
- Security architecture reviews
API Security Governance
- API discovery and inventory
- API gateway security
Robust knowledge of
- Application Security
- OWASP Top 10
- Secure coding practices
- Application threat modelling
Cloud Security (Additional)
- AWS / Azure / GCP security architectures
- Kubernetes security
- CNAPP / CSPM platforms
- Zero Trust architecture
AI Security
- AI model lifecycle security
- ML pipeline security
- AI governance frameworks
Engineering Practices
- DevSecOps pipeline security
- Infrastructure as Code security
- Software supply chain security
📌 General Manager - Global Information Security (Chennai)
🏢 Tata Communications
📍 Chennai