Cyber Security Manager (Chennai)

Cyber Security Manager (Chennai)

27 Sep
|
Bonfiglioli Technology Space
|
Chennai

27 Sep

Bonfiglioli Technology Space

Chennai

- Cyber Security Manager

Role Purpose

The Cyber Security Manager will lead the organizations cybersecurity strategy, governance, risk management, security operations, and continuous-improvement program. The role is accountable for aligning cybersecurity with business objectives, protecting enterprise IT, cloud, data, and manufacturing technology environments, coordinating incident response, and communicating cyber risk to Group leadership, business functions, auditors, and external stakeholders.

Key Accountabilities

1. Cybersecurity Strategy and Governance

- Develop and maintain a risk-based cybersecurity strategy, roadmap, policies, standards, control objectives, and operating model aligned with business priorities.
- Provide clear cyber-risk reporting, recommendations, investment priorities, and decision support to senior leadership and relevant governance forums.
- Define security ownership, risk acceptance, exceptions, remediation governance, and measurable outcomes across business units and geographies.
- Maintain the enterprise cyber-risk register and ensure timely tracking and closure of agreed remediation actions.

1. IT/OT and Industrial Cybersecurity

- Own the cybersecurity approach for manufacturing plants, industrial networks, and IT/OT convergence while balancing safety, availability, quality, and security.
- Establish segmentation and secure-access principles for corporate IT, industrial DMZs, production networks, engineering workstations, PLCs, HMIs, SCADA-connected environments, and remote vendor access.
- Drive OT asset visibility, risk assessment, vulnerability treatment, backup and recovery readiness, and compensating controls for legacy or difficult-to-patch systems.
- Coordinate with plant operations, engineering, maintenance, HSE, business continuity teams, and specialist suppliers on incident readiness and recovery.
- Apply recognized industrial-security principles, including IEC 62443 and the Purdue Model, where appropriate.

1. Cloud, Infrastructure and Application Security

- Define secure architecture and governance for Azure, AWS, and other approved cloud platforms, including identity, network, workload, data, encryption, logging, and configuration controls.
- Embed security-by-design, threat modelling, secure DevSecOps, and Policy-as-Code into cloud adoption, infrastructure changes, and the software delivery lifecycle.
- Oversee security posture management, vulnerability remediation, privileged access, endpoint protection, email security, network security, and secure remote access.
- Assess security technologies and services based on risk reduction, operational fit, integration, scalability, and total cost.

1. Security Operations and Incident Response





- Lead preparation for and coordination of major cyber incidents affecting users, cloud services, corporate networks, applications, data, or manufacturing operations.
- Maintain and test incident-response playbooks, escalation paths, crisis communications, forensic readiness, business-continuity dependencies, and ransomware recovery procedures.
- Ensure effective security monitoring, alert triage, threat detection, threat intelligence, vulnerability management, penetration testing, and closure of remediation actions.
- Coordinate post-incident reviews, root-cause analysis, lessons learned, executive reporting, and preventive improvements.
- Make risk-informed containment decisions during high-pressure incidents, including service isolation or shutdown when required to protect the business.

1. Risk, Compliance and Assurance

- Maintain alignment with applicable security, privacy, and regulatory obligations and recognized frameworks, including ISO/IEC 27001, NIST Cybersecurity Framework, GDPR, NIS2, PCI DSS, and relevant industry requirements.
- Support internal and external audits, customer assurance, control testing, evidence management, and timely remediation of findings.
- Manage third-party cyber risk, including due diligence, contractual security requirements, service-provider oversight, and remediation tracking.
- Oversee data-classification, encryption, data-loss-prevention, privacy, retention, and secure information-exchange controls.
- Assess emerging risks, including artificial-intelligence governance, AI security testing, and cryptographic-agility planning.

1. Leadership, Budget and Stakeholder Management

- Lead and develop a focused cybersecurity team and coordinate contributors across infrastructure, workplace, applications, cloud, manufacturing sites, and service providers.
- Define capability needs, resource plans, objectives, performance measures, and development priorities for the security function.
- Prepare business cases, contribute to budget planning, manage approved security spend, and monitor supplier and service performance.
- Build effective working relationships with Group leadership, local management, Legal, Privacy, HR, Internal Audit, Finance, plant teams, and external partners.
- Deliver role-based security awareness, simulations, campaigns, and targeted communications for employees and leadership.





Required Experience and Qualifications
- Minimum 10 years of progressive cybersecurity experience spanning architecture, engineering, governance, risk, compliance, or security operations.
- Demonstrated experience leading people, projects, suppliers, budgets, or cross-functional security programs in a multinational or complex enterprise setting.
- Practical experience with enterprise infrastructure and cloud security across Azure and/or AWS.
- Working knowledge of OT/ICS security, industrial network segmentation, IEC 62443, and the Purdue Model.
- Experience with incident response, vulnerability management, identity and privileged access, network security, endpoint security, SIEM/SOC operations, data protection, and third-party risk.
- Experience supporting ISO/IEC 27001, NIST, GDPR, NIS2, SOC 2, PCI DSS, or comparable compliance and assurance programs.
- Ability to translate technical risk into clear business impact, options, and recommendations for executives.
- Excellent written and spoken English for global collaboration, governance reporting, incident communication, and audit engagement. Italian language capability is an advantage.

Preferred Certifications
- CISSP, CISM, CISA, or CCSP.
- ISO/IEC 27001 Lead Implementer or Lead Auditor.
- Relevant Azure, AWS, or Google Cloud security certification.
- Industrial cybersecurity certification or formal IEC 62443 training.

Expected Deliverables in the First 12 Months
- Current-state cyber-risk and maturity assessment covering corporate IT, cloud, data, third parties, and priority manufacturing sites.
- Approved cybersecurity roadmap with prioritized initiatives, owners, dependencies, costs, timelines, and measurable outcomes.
- Validated inventory and risk view for critical IT and OT assets, privileged accounts, external connectivity, and key third parties.
- Prioritized IT/OT segmentation and secure remote-access improvement plan for manufacturing sites.
- Tested incident-response and ransomware-recovery exercises involving business, IT, and plant stakeholders.
- Executive dashboard covering key risks, incidents, vulnerabilities, remediation status, audit findings, supplier risks, and security-awareness outcomes.

Success Measures
- Delivery of the approved cybersecurity roadmap and timely closure of priority risks.
- Improved incident readiness, detection, containment, recovery, and completion of lessons-learned actions.
- Improved control compliance, audit readiness, and remediation of findings.
- Reduced exposure across IT, cloud, data, third-party, and OT environments.
- Effective executive reporting, stakeholder engagement, supplier performance, and security-culture improvement.

📌 Cyber Security Manager (Chennai)
🏢 Bonfiglioli Technology Space
📍 Chennai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cyber security manager (chennai) / chennai

Subscribe to this job alert:

Get the latest job offers by email for: cyber security manager (chennai) / chennai