Role purpose
Build and lead the new Cybersecurity & Trust tower and establish a very strong, board-credible cybersecurity posture for a listed media company undergoing deep modernization. The CISO owns end-to-end security strategy and execution Zero-Trust architecture, a 247 AI-powered SOC, DPDP Act compliance, OT/broadcast security and the security of an increasingly agentic-AI operating core, sustaining a zero-successful-ransomware posture throughout the transformation.
Key responsibilities
- Security strategy & roadmap — define and drive the enterprise cybersecurity strategy, multi-year roadmap and budget aligned to the DishTV 2.0 blueprint; report posture, risk and progress to the CIO, Executive Council and Board.
- Immediate risk remediation — lead the closure of known exposures in the legacy estate — plaintext credentials, unencrypted KYC/PII documents held in databases, confirmed SQL-injection vectors, over-broad database grants — with secrets vaulting, encryption, tokenization and access hardening.
- DPDP & regulatory compliance — own the Digital Personal Data Protection Act compliance program (consent, purpose limitation, retention, data-principal rights, breach playbooks), working with Legal/DPO; address exposure that carries penalties of up to 250 Cr per instance; support SEBI LODR and TRAI/MIB obligations.
- Zero-Trust & platform security — architect and roll out Zero-Trust across the hybrid Azure/on-prem estate; secure the new open stack — Kubernetes, API gateway, OIDC identity (Keycloak), Vault secrets, CI/CD pipelines — with DevSecOps embedded in every release.
- 247 SOC & incident response — stand up and run an AI-powered Security Operations Center with automated triage and response; own incident response, BCP/DR security, red-teaming and tabletop exercises; sustain a zero-successful-ransomware record.
- OT / broadcast security — extend security governance to broadcast headend,
transponder and STB/OTA infrastructure in line with IEC 62443, segmenting OT from IT.
- Securing agentic AI — define the security model for the agentic AI ecosystem — least-privilege MCP tool scopes, guardrails, prompt/agent registry controls, full audit trails — as a standing member of the AI Governance Council.
- GRC, vendor & people — build the GRC function (policies, ISO 27001-aligned ISMS, audits, risk register); assess vendor and third-party risk; recruit, develop and retain the Cybersecurity & Trust team, including SOC analysts and the GRC/DPDP officer; run security awareness for all employees.
Required skills & experience
- 15+ years in information security, with 5+ years leading a security function (CISO / Deputy CISO / Head of Security) — preferably in a listed enterprise in media, telecom, broadcast, BFSI or another regulated, consumer-scale industry.
- Proven experience building or transforming a SOC (SIEM/SOAR, threat intel, 247 operations) and running major incident response end-to-end.
- Solid command of Indian regulatory landscape: DPDP Act 2023, CERT-In directions, SEBI LODR disclosure obligations; working knowledge of ISO 27001, NIST CSF, IEC 62443.
- Hands-on depth in cloud security (Azure preferred), identity & access (OIDC/OAuth2), network security, application/API security and data protection (encryption, tokenization, DLP).
- Experience securing modern platforms — containers/Kubernetes, microservices, CI/CD — and legacy estates in transition; ability to prioritize remediation on a live revenue platform without disrupting operations.
- Executive presence: able to translate technical risk into business terms for the Board, and to say no with evidence.
Preferred / good to have
- CISSP, CISM, CISA, CCSP or equivalent certifications.
- Exposure to AI/LLM security (agent guardrails, model risk, adversarial testing) and interest in securing agentic systems.
- Experience with broadcast/OT environments, conditional-access systems or telecom-grade infrastructure.
📌 Chief Information Security Officer (Noida)
🏢 DishTV
📍 Noida