01 Oct
|
Tata AutoComp
|
Pune
01 Oct
Tata AutoComp
Pune
Role & responsibilities The Senior Manager IT Security is responsible for leading the organizations cybersecurity strategy, operations, and risk management initiatives. This role ensures the protection of enterprise IT assets, applications, networks, and data against cyber threats, while aligning security with business objectives and regulatory requirements.
- Security Strategy & Governance
- Define and execute enterprise IT security strategy aligned with business goals.
- Establish and maintain security governance frameworks, policies, and standards.
- Ensure alignment with global standards such as ISO 27001, NIST, CIS Controls.
- Drive continuous improvement of the organizations security posture
- Risk Management & Compliance (across the Business Units of Tata AutoComp)
- Lead enterprise-wide risk assessments and mitigation planning
- Manage vulnerability assessment and penetration testing (VAPT) programs.
- Ensure compliance with regulatory and legal requirements (e.g., DPDP Act).
- Manage internal and external security audits and ensure closure of findings.
- Security Operations
- Oversee Security Operations Center (SOC) functions including monitoring, detection, and response.
- Define and track KPIs such as MTTD, MTTR, and incident severity.
- Enhance threat intelligence capabilities and proactive defense mechanisms.
- Ensure 24x7 monitoring of security events and incidents.
- Incident Response & Crisis Management
- Lead cyber incident response planning and execution.
- Coordinate with internal teams and external agencies during major incidents.
- Conduct root cause analysis (RCA) and implement corrective measures.
- Develop and test cyber crisis and business continuity plans.
- Security Architecture & Engineering
- Define secure architecture for enterprise IT systems (on-premise and loud).
- Implement / Manage controls across:
o Network security (firewalls, IDS/IPS)
o Endpoint security (EDR/XDR)
o Identity & Access Management (IAM, PAM)
o Data security (DLP, encryption)
- Drive Zero Trust architecture adoption.
- Cloud & Digital Security
- Ensure secure adoption of cloud platforms (Azure, AWS).
- Oversee cloud security posture management (CSPM) and workload protection.
- Ensure secure APIs, applications, and DevSecOps pipelines.
- Third-Party & Vendor Risk Management
- Assess and manage risks from third-party vendors and partners.
- Implement vendor security assessment frameworks.
- Ensure contractual security requirements are enforced.
- Leadership & Stakeholder Management
- Lead and mentor cybersecurity teams.
- Collaborate with IT, business units, HR, Admin, legal, and compliance teams
- Present security posture and risk insights to senior leadership.
- Manage budgets and strategic security investments
- Awareness & Training
- Drive organization-wide security awareness programs.
- Conduct phishing simulations and user training.
- Promote a security-first culture across the enterprise
Preferred candidate profile
1218 years of experience in IT security, with:
o 5 years in leadership/managerial roles o Experience managing enterprise-scale environments
ISO 27001 Lead Implementer / Auditor
Certifications (Preferred)
• CISSP (Highly preferred)
• CISM / CISA
• CCSP / CCSK
• CEH / OSCP
📌 Sr. Manager- IT Security (Pune)
🏢 Tata AutoComp
📍 Pune