29 Sep
|
Apar Technologies
|
Mumbai
29 Sep
Apar Technologies
Mumbai
Role Overview:
The Cybersecurity & IT Administration Manager is primarily responsible for establishing, developing, and enforcing group-wide cybersecurity governance and information security policies aligned with the ISO/IEC 27001 standard. Reporting directly to the Group IT Manager, this role acts as the central cybersecurity authority, ensuring robust perimeter, endpoint, platform, and identity defenses. Secondarily, the role directs and supervises the two regional IT Administrators (based in France and Malaysia), who carry out hands-on IT infrastructure maintenance, endpoint provisioning, and user support. The Manager establishes the technical baselines, change control procedures, and operational standards across our approved technology stack—including Google Workspace Enterprise, Jira, Clavister firewalls, WithSecure EDR, and our in-house application platform.
Key Responsibilities
1. Cybersecurity Governance & ISO/IEC 27001 Leadership (Primary Focus)
Lead the authoring, rollout, and continuous enforcement of information security policies, standards, and standard operating procedures (SOPs) aligned with ISO/IEC 27001.
Coordinate, track, and verify the implementation of ISO 27001 Annex A controls across cloud platforms, internal systems, network perimeters, and endpoints.
Plan, conduct, and supervise periodic internal security audits, entitlement reviews, and vulnerability assessments across all global business units.
Compile, organize, and maintain auditable technical evidence to achieve and preserve ISO/IEC 27001 certification during external surveillance and recertification audits.
Oversee and enforce IT change management workflows covering firewall rule modifications, identity entitlements, server environments, and system configurations.
2. Perimeter, Endpoint & Threat Defense
Define baseline configurations, security rules for Firewalls across all global operating facilities.
Oversee and govern secure remote client access policies and client VPN profiles for authorized personnel.
Supervise the centralized administration of EDR across all group endpoints (workstations, plant-floor devices, and servers).
Lead incident response procedures for escalated security alerts; direct the regional IT Administrators in isolating compromised endpoints and executing remediation steps.
Manage vulnerability scanning and patch management cycles for operating systems, firewall firmware, and servers hosting internal and public-facing services.
3. Platform & Identity Governance
Direct security configurations, access rules, and data protection policies within Google Workspace Enterprise.
Establish and govern access control baselines, permission schemes, and user entitlement hygiene for:
Google Workspace Enterprise Jira In-house application platforms LumApps Intranet Others
Oversee recurring privilege reviews to systematically detect and revoke inactive, orphaned, or excessive administrative rights.
4. Security Awareness & Culture
Plan, schedule, and oversee mandatory security awareness campaigns.
Prepare, organise and track phishing campaigns.
Author and circulate security bulletins, policy updates, and threat alerts company-wide through the Intranet.
5. IT Administration & Infrastructure Supervision (Secondary Focus)
Supervise, guide, and direct the daily deliverables of the two Regional IT Administrators.
Standardize Joiner, Mover, and Leaver (JML) workflows, hardware provisioning templates, asset tracking registers, and endpoint setups executed by the IT Admins.
Works with local IT external support companies and organise security and infrastructure updates
Supervise helpdesk ticket workflows, incident response timelines, and escalation queues managed through Jira Service Management / Jira.
Consolidate regional operational metrics, IT health reports, and ticket SLAs into concise monthly briefings for the Group IT Manager.
Serve as the senior escalation point for operational roadblocks or complex infrastructure challenges faced by the regional IT Admins.
Required Qualifications & Experience
Experience: Minimum 10+ years of total experience in IT systems administration, infrastructure security, and cybersecurity governance.
Leadership: Proven track record (5+ years) supervising, delegating to, and directing distributed technical personnel (systems administrators or support engineers).
Cybersecurity Frameworks: Deep practical experience authoring, implementing, and defending policies against the ISO/IEC 27001 framework (prior involvement in achieving or maintaining certification is essential).
Platform Administration: Direct experience securing and administering Google Workspace Enterprise
Network & Endpoint Defense: Demonstrated proficiency with next-generation firewall governance and endpoint detection/response platforms.
Proprietary & Web Systems: Experience securing internal/in-house application platforms and auditing web hosting server baselines.
Education: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent practical industry experience.
Preferred Skills & Certifications
Professional security certifications such as ISO/IEC 27001 Lead Implementer / Internal Auditor, CISSP, CISM.
Robust technical authoring skills to produce clear, audit-ready policies, SOPs, and executive risk reports in English.
Experience navigating the operational realities of global manufacturing facilities and commercial branch networks across diverse time zones.
📌 Cybersecurity & IT Administration Manager - Remote (Mumbai)
🏢 Apar Technologies
📍 Mumbai