Information Security, GRC & Security Operations (Mumbai)

Information Security, GRC & Security Operations (Mumbai)

24 Sep
|
Sony Pictures Networks India
|
Mumbai

24 Sep

Sony Pictures Networks India

Mumbai

PURPOSE:

Lead and continuously improve SPNI's information security program across governance, risk, compliance, architecture, cloud, identity, vulnerability management and incident response. Align business needs with Sony Global policies, ISO/IEC 27001:2022, SOX/ITGC and applicable legal, regulatory and contractual requirements, including India's DPDP Act readiness, while translating security requirements into practical controls across on-premises, AWS, Azure, Microsoft 365 and hybrid environments.

KEY RESPONSIBILITIES:

1. Governance, ISMS, Compliance & Assurance

- Own and continually improve the ISO/IEC 27001:2022-aligned ISMS; maintain scope, risk methodology, Statement of Applicability, treatment plans and evidence; manage certification/surveillance audits, management reviews and governance forums.
- Develop and periodically review security policies, standards, procedures and frameworks; establish control ownership, review cycles, exception handling, escalation, audit readiness and remediation assurance for Sony Global requirements, SOX/ITGC and applicable obligations.
- Define executive KPIs/KRAs and dashboards covering material risks, control gaps, compliance status, remediation priorities, critical exposure, aging, recurrence, vendor risk and operational performance.

2. Enterprise & Third-Party Risk Management

- Lead periodic and change-triggered risk assessments across business processes, technology, projects and suppliers; maintain a consolidated register with owners, ratings, actions, target dates, residual risk and formal acceptance; escalate overdue or material exposures.
- Assess emerging threats, technology and regulatory developments; agree proportionate mitigation with business and technology stakeholders and communicate significant weaknesses to leadership.
- Own the third-party risk framework: classify vendors by criticality, data, privilege and dependency; perform security/privacy due diligence; evaluate responses and assurance reports; track gaps and residual risk; periodically reassess and monitor critical/high-risk vendors.
- Partner with Procurement and Legal to embed security, confidentiality, personal-data protection, incident reporting, subcontracting and exit clauses, and report unresolved material vendor risk.

3. Security Architecture, Network, Cloud & Platform Security

- Review on-premises, cloud and hybrid designs, including firewalls, VPN, proxy/SWG,



IDS/IPS, DNS, TLS, load balancers, WAF, DDoS controls, AWS Direct Connect, Azure ExpressRoute and site-to-site VPN; apply Zero Trust and least privilege, validate implementation, and document exceptions/residual risk.
- Oversee hardening procedures for servers, databases, workstations, laptops and mobile devices; assess backup protection, recovery access and resilience controls.
- Assess AWS accounts and Azure subscriptions across IAM/Entra ID, privileged/service/workload identities, networking, compute, storage, management plane, KMS/Secrets Manager/Key Vault, CloudTrail, GuardDuty, Security Hub, Azure Activity Logs and Defender for Cloud; prioritize posture findings and support secure baselines, IaC reviews and automated checks.
- Assess Microsoft 365, including Exchange Online, SharePoint, OneDrive and Teams; review MFA, Conditional Access, PIM, authentication methods, legacy authentication, guest/external access, application consent, enterprise apps and service principals.
- Review phishing, malicious attachment, impersonation and BEC protection; evaluate Defender for Office 365/XDR; validate audit logging and centralized monitoring; review sensitivity labels, DLP and external sharing with data owners/compliance teams.

4. Vulnerability, Monitoring & Incident Response

- Continuously improve vulnerability platforms, processes and coverage across servers, endpoints, network devices, cloud workloads, web applications and internet-facing assets; perform authenticated scans, configuration reviews and authorized validation using Qualys, Nessus and Burp Suite.
- Validate findings and false positives; prioritize by exploitability, criticality, exposure and business impact; agree SLAs, compensating controls and risk acceptance; retest fixes, preserve closure evidence and coordinate with Global Vulnerability Management/regional teams.
- Monitor and investigate SIEM, endpoint, network, cloud, identity and Microsoft 365 alerts; correlate telemetry,



distinguish false positives/configuration issues/incidents, determine scope and attack paths, and execute authorized containment and remediation.
- Support recovery, evidence preservation, root-cause analysis and accurate timelines; improve detections, queries, playbooks, alert tuning and log onboarding; conduct threat hunting, simulations/tabletops, document lessons and track corrective actions. Escalate personal-data or regulatory matters to Legal, Privacy and GRC.
- Investigate identity compromise, suspicious sign-ins, malicious inbox rules, risky OAuth apps and unauthorized sharing.

5. AI Security, Awareness, Reporting & Collaboration

- Assess AI-enabled services for sensitive-data exposure, permissions, third-party processing, insecure connectivity, prompt injection, unsafe tool access and unintended disclosure; review approved use, access restrictions, logging and protection settings with Architecture, Legal, Privacy and GRC.
- Run a risk-based security/privacy awareness program using LMS training, phishing simulations and targeted education; measure completion, reporting behavior and repeat susceptibility, and promote valuable practice among employees, vendors and stakeholders.
- Maintain architecture reviews, assessment reports, incident records, technical procedures and remediation evidence; support audits with technical evidence and control validation; communicate clearly to technical and non-technical audiences.
- Collaborate with Global Information Security Operations, Global Vulnerability Management, Infrastructure, Cloud, Network, Applications and local teams; automate assessments, alert enrichment and reporting through scripting/APIs; stay current on threats, attack techniques and security technologies.

EXPERIENCE, QUALIFICATIONS & SUCCESS MEASURES:

• Minimum 8+ years of cybersecurity experience, including enterprise GRC ownership and at least 5 years of substantive vulnerability-management and incident-response experience.

- Hands-on ownership of an ISO/IEC 27001-aligned ISMS, audits, security risk/control assurance, policy governance, audit remediation, third-party risk and executive reporting.
- Hands-on security across AWS, Azure and Microsoft 365, with depth in at least one cloud; cloud IAM/Entra ID, PIM, MFA and Conditional Access; infrastructure, application, identity and data-protection controls.

📌 Information Security, GRC & Security Operations (Mumbai)
🏢 Sony Pictures Networks India
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: information security, grc & security operations (mumbai) / mumbai

Subscribe to this job alert:

Get the latest job offers by email for: information security, grc & security operations (mumbai) / mumbai