02 Oct
|
GlobalStep
|
Pune
Security Manager / Lead Information Security
Position Types: Security Manager / Lead Information Security
Position Locations: India
City: Pune
Experience: 8-15 Years
Shift Timing: 3 PM-12 AM
Role Purpose
This role is responsible for designing, building, and operationalizing GlobalStep s cybersecurity program across a distributed, hybrid, and high-growth environment. You will act as the single-threaded owner of security, while working closely with internal IT teams and external partners to implement scalable, enterprise-grade security controls.
Key Responsibilities
- Security Architecture Strategy: Design and implement end-to-end security architecture across Identity Access, Endpoints Devices, Network Segmentation, Logging Monitoring, Data Protection; Establish identity as the primary control plane: MFA, RBAC, PAM, Conditional Access; Drive Zero Trust-aligned access models; Implement client/project-level workplace segregation.
- Cross-Functional Collaboration: Work closely with Network Administrators (segmentation, firewall policies, VPN); M365 / Identity specialists (Entra ID, Conditional Access, collaboration security); Align security architecture with IT infrastructure and cloud strategy; Act as the bridge between security and IT operations teams.
- Identity Access Management (Critical Focus Area): Manage access for a high-churn workforce (FTEs, contractors, freelancers); Implement strong Joiner Mover Leaver (JML) lifecycle controls; Enforce least privilege access; Privileged access separation; Elimination of orphaned accounts; Align access provisioning with project-based roles and groups.
- Endpoint, Device BYOD Security: Define and enforce controls for corporate devices, lab/testing devices, BYOD endpoints; Implement Endpoint Detection and Response (EDR); Device compliance and hardening; Establish differentiated trust models: Full access managed devices; Restricted access BYOD.
- Security Monitoring,
SIEM SOC: Select, deploy, and operationalize SIEM platform; Onboard logs across identity, endpoint, network, and infrastructure systems; Design and build a multi-tier SOC, including Tier 1 monitoring, Tier 2 investigation, Detection engineering, Threat hunting, and develop detection use cases and response playbooks.
- SOC/NOC Leadership Capability Building: Lead and manage a team of network and security professionals supporting SOC (Security Operations) and NOC (Network Operations); Define roles and responsibilities; Escalation models; Performance metrics; Career paths through skill gap analysis and focused training programs; Ensure 24/7 monitoring readiness as the program matures.
- Incident Response Threat Management: Lead response to security incidents; Threats and vulnerabilities; Develop playbooks for ransomware, account compromise, data exfiltration / IP leakage; Drive root cause analysis and continuous improvement.
- Data Game IP Protection (Core Business Risk): Design and implement controls to protect high-value game IP; Implement Data Loss Prevention (DLP); File access monitoring; Access traceability; Enforce USB restrictions; Screen capture controls; Monitor for unusual data access and movement patterns.
- Network Infrastructure Security: Work with network teams to implement studio-level segmentation; Reduce lateral movement and enforce controlled east-west traffic; Secure remote access (VPN and evolving models).
- Vendor Partner Management: Engage with third-party vendors and service providers for security tool deployment, implementation support, ongoing platform management, and evaluate vendors to ensure alignment with security architecture and standards.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Security Manager / Lead - Information Security (Pune)
🏢 GlobalStep
📍 Pune