24 Sep
|
Sony Pictures Networks India
|
Mumbai
24 Sep
Sony Pictures Networks India
Mumbai
PURPOSE:
Lead and continuously improve SPNI's information security program across governance, risk, compliance, architecture, cloud, identity, vulnerability management and incident response. Align business needs with Sony Global policies, ISO/IEC 27001:2022, SOX/ITGC and applicable legal, regulatory and contractual requirements, including India's DPDP Act readiness, while translating security requirements into practical controls across on-premises, AWS, Azure, Microsoft 365 and hybrid environments.
KEY RESPONSIBILITIES:
1. Governance, ISMS, Compliance & Assurance
- Own and continually improve the ISO/IEC 27001:2022-aligned ISMS; maintain scope, risk methodology, Statement of Applicability, treatment plans and evidence; manage certification/surveillance audits, management reviews and governance forums.
- Develop and periodically review security policies, standards, procedures and frameworks; establish control ownership, review cycles, exception handling, escalation, audit readiness and remediation assurance for Sony Global requirements, SOX/ITGC and applicable obligations.
- Define executive KPIs/KRAs and dashboards covering material risks, control gaps, compliance status, remediation priorities, critical exposure, aging, recurrence, vendor risk and operational performance.
2. Enterprise & Third-Party Risk Management
- Lead periodic and change-triggered risk assessments across business processes, technology, projects and suppliers; maintain a consolidated register with owners, ratings, actions, target dates, residual risk and formal acceptance; escalate overdue or material exposures.
- Assess emerging threats, technology and regulatory developments; agree proportionate mitigation with business and technology stakeholders and communicate significant weaknesses to leadership.
- Own the third-party risk framework: classify vendors by criticality, data, privilege and dependency; perform security/privacy due diligence; evaluate responses and assurance reports; track gaps and residual risk; periodically reassess and monitor critical/high-risk vendors.
- Partner with Procurement and Legal to embed security, confidentiality, personal-data protection, incident reporting, subcontracting and exit clauses, and report unresolved material vendor risk.
3. Security Architecture, Network, Cloud & Platform Security
- Review on-premises, cloud and hybrid designs, including firewalls, VPN, proxy/SWG,
IDS/IPS, DNS, TLS, load balancers, WAF, DDoS controls, AWS Direct Connect, Azure ExpressRoute and site-to-site VPN; apply Zero Trust and least privilege, validate implementation, and document exceptions/residual risk.
- Oversee hardening procedures for servers, databases, workstations, laptops and mobile devices; assess backup protection, recovery access and resilience controls.
- Assess AWS accounts and Azure subscriptions across IAM/Entra ID, privileged/service/workload identities, networking, compute, storage, management plane, KMS/Secrets Manager/Key Vault, CloudTrail, GuardDuty, Security Hub, Azure Activity Logs and Defender for Cloud; prioritize posture findings and support secure baselines, IaC reviews and automated checks.
- Assess Microsoft 365, including Exchange Online, SharePoint, OneDrive and Teams; review MFA, Conditional Access, PIM, authentication methods, legacy authentication, guest/external access, application consent, enterprise apps and service principals.
- Review phishing, malicious attachment, impersonation and BEC protection; evaluate Defender for Office 365/XDR; validate audit logging and centralized monitoring; review sensitivity labels, DLP and external sharing with data owners/compliance teams.
4. Vulnerability, Monitoring & Incident Response
- Continuously improve vulnerability platforms, processes and coverage across servers, endpoints, network devices, cloud workloads, web applications and internet-facing assets; perform authenticated scans, configuration reviews and authorized validation using Qualys, Nessus and Burp Suite.
- Validate findings and false positives; prioritize by exploitability, criticality, exposure and business impact; agree SLAs, compensating controls and risk acceptance; retest fixes, preserve closure evidence and coordinate with Global Vulnerability Management/regional teams.
- Monitor and investigate SIEM, endpoint, network, cloud, identity and Microsoft 365 alerts; correlate telemetry,
distinguish false positives/configuration issues/incidents, determine scope and attack paths, and execute authorized containment and remediation.
- Support recovery, evidence preservation, root-cause analysis and accurate timelines; improve detections, queries, playbooks, alert tuning and log onboarding; conduct threat hunting, simulations/tabletops, document lessons and track corrective actions. Escalate personal-data or regulatory matters to Legal, Privacy and GRC.
- Investigate identity compromise, suspicious sign-ins, malicious inbox rules, risky OAuth apps and unauthorized sharing.
5. AI Security, Awareness, Reporting & Collaboration
- Assess AI-enabled services for sensitive-data exposure, permissions, third-party processing, insecure connectivity, prompt injection, unsafe tool access and unintended disclosure; review approved use, access restrictions, logging and protection settings with Architecture, Legal, Privacy and GRC.
- Run a risk-based security/privacy awareness program using LMS training, phishing simulations and targeted education; measure completion, reporting behavior and repeat susceptibility, and promote valuable practice among employees, vendors and stakeholders.
- Maintain architecture reviews, assessment reports, incident records, technical procedures and remediation evidence; support audits with technical evidence and control validation; communicate clearly to technical and non-technical audiences.
- Collaborate with Global Information Security Operations, Global Vulnerability Management, Infrastructure, Cloud, Network, Applications and local teams; automate assessments, alert enrichment and reporting through scripting/APIs; stay current on threats, attack techniques and security technologies.
EXPERIENCE, QUALIFICATIONS & SUCCESS MEASURES:
• Minimum 8+ years of cybersecurity experience, including enterprise GRC ownership and at least 5 years of substantive vulnerability-management and incident-response experience.
- Hands-on ownership of an ISO/IEC 27001-aligned ISMS, audits, security risk/control assurance, policy governance, audit remediation, third-party risk and executive reporting.
- Hands-on security across AWS, Azure and Microsoft 365, with depth in at least one cloud; cloud IAM/Entra ID, PIM, MFA and Conditional Access; infrastructure, application, identity and data-protection controls.
📌 Information Security, GRC & Security Operations (Mumbai)
🏢 Sony Pictures Networks India
📍 Mumbai