Key results expected from the job and the supporting actions for each key result area.
Key Result Areas
Supporting Actions
ISMS & Security Governance
Own and operate the Enterprise Information Security Governance & IT Risk Management program aligned to ISO 27001:2022, NIST CSF and DPDP Act.
Develop, review and renew policies, standards and SOPs; maintain the policy renewal tracker and secure stakeholder/management approvals.
Evaluate the organization’s security posture periodically and report to stakeholders.
Security Assessment & Technology Due Diligence
Conduct InfoSec assessments for current/existing projects and applications on a Secure-by-Design basis — review architecture, data flows and controls, and perform threat modelling.
Assess controls, identify gaps, provide residual-risk assessments and track risk-treatment actions.
Validate implementation (controls, VAPT, secure code review, logging/monitoring) and provide initial and final production sign-offs.
Application, API & Infrastructure Security
Govern application & API security — assess against InfoSec/AppSec checklists, oversee VA, PT and secure code reviews, and drive DevSecOps integration and application-layer attack mitigation.
Maintain MBSS / Secure Configuration Documents (SCD); oversee configuration VA and compliance reviews.
Maintain infrastructure security baselines, assess assets periodically, track and close observations with stakeholders.
Enterprise Vulnerability Management
Lead the Enterprise Vulnerability Management program across applications, infrastructure and configurations.
Prioritise vulnerabilities by severity, business impact and exploitability; manage exceptions and escalate overdue items.
Monitor remediation progress and ensure timely closure and reporting.
Cloud Security Governance
Implement and oversee cloud security best practices across AWS & Azure — IAM, encryption, network security and logging.
Conduct cloud security, gap and complianc
📌 Lead - Information Security and GRC (India)
🏢 ABC - Aditya Birla Housing Finance
📍 India
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.