24 Sep
|
PVR INOX
|
Gurugram
Role & responsibilities
- Own the information security and infrastructure strategy, operating model, roadmap, policies, standards and annual budget in alignment with business priorities.
- Lead cybersecurity governance, enterprise risk assessments, security architecture reviews and remediation tracking; present risk posture, key metrics and exceptions to senior management.
- Drive participation in Digital Personal Data Protection Act (DPDPA) readiness, including data discovery, privacy-by-design controls, consent and retention dependencies, incident coordination and evidence support to Legal/Privacy teams.
- Own PCI DSS compliance for cardholder-data environments across cinemas, digital channels and corporate systems; coordinate scoping, control implementation, assessments, evidence, remediation and third-party dependencies.
- Manage endpoint security, EDR/XDR, anti-malware, device hardening, patching, encryption and privileged access controls across corporate and cinema endpoints and servers.
- Establish and mature security monitoring and incident response capabilities, including SIEM/SOC integration, use-case development, threat intelligence, playbooks, investigation, containment, recovery and post-incident reviews.
- Lead vulnerability management, penetration testing, configuration compliance, attack-surface management and timely closure of critical findings through accountable risk owners.
- Oversee identity and access management, MFA, SSO, role-based access, joiner-mover-leaver controls, privileged access management and periodic access reviews.
- Direct enterprise network operations covering LAN, WAN, SD-WAN, MPLS, internet, Wi-Fi, DNS/DHCP, firewalls, VPN,
routing and switching across a large multi-location environment.
- Lead cloud and data-centre security and infrastructure across public cloud and on-premises environments, covering secure landing zones, workload protection, backup, capacity, availability and cost optimisation.
- Ensure business continuity and disaster recovery readiness through BIA inputs, resilient architecture, backup assurance, DR drills, recovery testing and closure of observations.
- Define security requirements and conduct due diligence for technology projects, applications, APIs, SaaS platforms, payment integrations, vendors and managed service providers.
- Manage OEMs, system integrators, SOC/MSSP, cloud and telecom partners through explicit SLAs, service reviews, escalation governance, licence optimisation and contract performance.
- Lead IT audits and compliance engagements, including internal audit, statutory/third-party reviews and customer or partner assessments; maintain a sustainable evidence and control-testing framework.
- Build a security-aware culture through role-based training, phishing simulations, targeted communication and measurable awareness programmes for corporate and cinema teams.
- Recruit, mentor and manage security, network, cloud and infrastructure teams; establish goals, succession plans,
on-call coverage, capability development and performance standards.
- Track and report KPIs/KRIs such as security incidents, MTTD/MTTR, endpoint coverage, vulnerability ageing, patch compliance, availability, capacity, audit observations, PCI status and DR readiness.
- Collaborate with Business, Operations, Finance, Legal, HR, Internal Audit, Digital, Application and Engineering teams to balance risk, customer experience, availability and commercial outcomes.
Preferred candidate profile
- Bachelors or Masters degree in Engineering, Computer Science, Information Technology or a related discipline.
- Preferred certifications: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Lead Auditor, CCNP/CCIE, cloud security certification, ITIL and/or PCI Professional credentials.
- Practical experience and leadership outcomes will be considered alongside certifications.
- High integrity, sound judgement and discretion when handling sensitive security, privacy and employee/customer information.
- Business-oriented leader who can protect the enterprise without creating unnecessary friction for operations or customer experience.
- Calm and decisive under pressure, with disciplined incident leadership and clear communication to technical and non-technical stakeholders.
- Strong ownership, execution rigour and ability to drive closure across cross-functional teams and external partners.
- Collaborative, adaptable and comfortable operating in a fast-paced, multi-site environment with competing priorities.
- Excellent written, verbal, presentation and interpersonal skills.
📌 General Manager - Cybersecurity (Gurugram)
🏢 PVR INOX
📍 Gurugram