02 Oct
|
Nido Machineries
|
Mumbai
02 Oct
Nido Machineries
Mumbai
Role mandate
Own NIDOs enterprise cybersecurity governance, risk and assurance programme, using a lean internal model supported by vCISO/MSSP/specialist partners where appropriate.
What success looks like
- Establish a practical cyber risk baseline and prioritised improvement roadmap.
- Strengthen identity, privileged access, vulnerability and incident readiness.
- Create third-party, application, AI/data and cloud security governance.
- Build evidence-based GRC suitable for customers, audits and future scale.
- Improve employee security awareness without creating excessive bureaucracy.
Key responsibilities
- Maintain cyber risk register, policies, standards, control framework and remediation tracking.
- Own IAM/MFA/privileged-access governance with Infrastructure and Applications.
- Coordinate vulnerability management, security monitoring/MSSP, penetration testing and remediation.
- Own incident-response plans, exercises, escalation and post-incident learning.
- Assess third-party/SaaS/cloud security and customer security questionnaires.
- Define security requirements for ERP, NIDO AI Hub, My NIDO,
data/BI and enterprise integrations.
- Run awareness/phishing programmes and compliance evidence management.
- Coordinate vCISO, MSSP, auditors and specialist security partners.
Decision rights & boundaries
- Infrastructure operates systems; Cybersecurity independently defines/checks controls and risk.
- Product/OT cybersecurity for NIDOs customer-deployed technology remains with Product/Technology unless a specific governance interface is defined.
- Legal owns legal interpretation; Cybersecurity owns security controls/evidence.
Experience & qualifications
- 712+ years cybersecurity, risk or GRC experience with hands-on control implementation exposure.
- Strong IAM, vulnerability, incident response, third-party risk, cloud/SaaS and governance understanding.
- ISO 27001/NIST/CIS/SOC-type framework exposure practical;
certifications such as CISSP/CISM/ISO lead implementer helpful, not sufficient alone.
- Experience in manufacturing/technology SME or mid-market environments preferred.
📌 Manager Cybersecurity, Risk & GRC (Mumbai)
🏢 Nido Machineries
📍 Mumbai