Job Description
About the Organization
Our client is a leading and rapidly growing enterprise in the automotive and mobility sector with a strong presence across multiple locations in India. The organization is committed to operational excellence, digital transformation, and delivering world-class customer experiences. With a focus on innovation and technology-driven business operations, the company is investing significantly in strengthening its IT infrastructure, cybersecurity, and end-user services capabilities.
Role Overview
We are seeking an experienced Cyber Technology Lead to manage and operate the organization's
cybersecurity capabilities.
Reporting directly to the CISO, this role is responsible for the management of the outsourced Security Operations
Centre (SOC), Governance Risk & Compliance (GRC), Web & Email Security, and Operational Technology (OT)
Security. The role acts as the primary operational owner of these domains, ensuring that cyber threats are
detected, managed, and mitigated across IT and OT environments in line with business risk appetite and regulatory
requirements.
Key Responsibilities
Outsourced SOC Management
- Act as the primary internal owner and liaison for the outsourced Security Operations Centre (SOC). Manage
day to day service delivery against agreed SLAs and KPIs
- Review and validate SOC outputs including threat alerts, incident reports, and threat intelligence feeds;
ensure timely escalation and response for high-severity events
- Drive continuous improvement of SOC detection capabilities. Collaborate with the SOC provider to tune
SIEM rules, use cases and alerting thresholds relevant to Imperial Auto's environment
- Lead incident response coordination for significant cyber events. Act as the internal bridge between the
SOC, IT teams, and CISO during active incidents
- Conduct regular service reviews with the SOC vendor. Manage contract performance, renewals, and SLA
adherence reporting to the CISO
- Develop and maintain the incident response playbook library in collaboration with the SOC provider. Ensure
playbooks reflect current threat landscape and business context
- Oversee threat hunting and vulnerability intelligence activities provided by the SOC. Ensure findings are
tracked and remediated within agreed timelines
Governance, Risk & Compliance (GRC)
- Own and maintain the organisation's cybersecurity policy framework. Review, update, and publish policies,
standards, and procedures in line with regulatory and business requirements and in consultation with the
CISO and IT head
- Manage the cybersecurity risk register. Conduct regular risk assessments, track residual risks and present
risk posture updates to the CISO
- Lead compliance activities aligned to applicable frameworks including ISO 27001, NIST CSF, DPDP Act, and
any sector specific regulatory requirements.
- Coordinate and support internal and external cybersecurity audits. Manage audit findings, remediation
plans, and evidence collection
- Drive third party and supplier cyber risk assessments. Manage vendor security questionnaires and maintain
a supplier risk register
- Develop and deliver security awareness training and phishing simulation programmes across the
organisation
- Track and report on compliance metrics, risk KPIs, and GRC programme status to the CISO on a regular
cadence
Web & Email Security
- Own and manage web security controls including Secure Web Gateway (SWG), URL filtering, SSL inspection,
and proxy policies across all sites
- Administer and optimise email security platforms including Secure Email Gateway (SEG), anti-phishing, anti-
spoofing, and email authentication controls (DMARC, DKIM, SPF)
- Monitor and respond to web and email-based threats. Investigate blocked content anomalies and refine
policies to balance security and business productivity
- Manage DLP (Data Loss Prevention) policies integrated within web and email channels. Investigate policy
violations and adjust rules to reduce false positives
- Stay current on web and email threat vectors (BEC, phishing, malware delivery). Ensure controls and
configurations are updated proactively
- Coordinate with the SOC provider on web and email threat intelligence integration into SIEM use cases and
alert correlation
OT Security (Operational Technology)
- Own the OT/ICS cybersecurity programme for Imperial Auto's plant and manufacturing environments.
Develop and maintain the OT security roadmap aligned to IEC 62443 or NIST SP 800-82 frameworks
- Assess and manage OT/IT network segmentation. Ensure appropriate boundaries between corporate IT and
plant OT networks (DMZ, data diodes, conduits)
- Conduct OT asset discovery and maintain an inventory of ICS/SCADA systems, PLCs, HMIs, and industrial
network components across all plant sites
- Identify and manage OT specific vulnerabilities. Coordinate patching and compensating controls in
collaboration with plant operations and engineering teams
- Monitor OT network traffic for anomalies using OT specific security monitoring tools (e.g. Claroty, Dragos,
Nozomi Networks, or equivalent)
- Act as the cybersecurity advisor for OT related projects, new plant installations, and equipment upgrades.
Ensure security requirements are embedded at design stage
- Develop and test OT specific incident response and recovery procedures. Coordinate with plant operations
teams to ensure minimal production disruption during cyber events
- Manage relationships with OT equipment vendors and ICS integrators to address security requirements in
maintenance and support agreements
Cross-Functional Collaboration & Reporting
- Partner with the Head of IT Infrastructure & End User Services to ensure IT and OT security controls are
operationally integrated and consistently applied
- Provide regular reporting to the CISO on SOC performance, GRC status, threat landscape, and OT security
posture
- Support the CISO in presenting cybersecurity risk and programme updates to leadership and board
stakeholders as required
- Contribute to the annual cybersecurity strategy and budget planning process
Qualifications & Experience
- 8 to 14 years of cybersecurity experience, with demonstrated depth across at least three of the four
responsibility areas
- Experience managing an outsourced SOC or MSSP relationship, including SLA management and incident
escalation
- Solid understanding of GRC frameworks: ISO 27001, NIST CSF, DPDP Act; experience managing compliance
programmes or audits
- Hands on experience with Secure Web Gateway, Secure Email Gateway, and email authentication
technologies (DMARC, DKIM, SPF, DMARC reporting).
- OT/ICS security experience is strongly preferred, including familiarity with IEC 62443, NIST SP 800-82, or
plant network environments
- Experience working in manufacturing, automotive, energy, or industrial sectors is advantageous
- Strong incident response skills. Able to coordinate cross functional response under pressure
- Excellent communication skills. Aable to articulate technical risk clearly to non technical stakeholders
- Relevant certifications desirable: CISSP, CISM, ISO 27001 Lead Implementer/Auditor, GICSP (ICS/SCADA), or
equivalent.
Technical Competencies
SOC & SIEM: Splunk, Microsoft Sentinel, IBM QRadar, or equivalent
SOAR platforms.
GRC: Archer, ServiceNow GRC, OneTrust, or equivalent risk/compliance platforms
Web Security: Zscaler, Symantec ProxySG, Forcepoint, Cisco Umbrella
Email Security: Proofpoint, Mimecast, Microsoft Defender for Office 365; DMARC/DKIM/SPF
OT Security: Claroty, Dragos, Nozomi Networks; IEC 62443, NIST SP 800-82; Purdue Model / ISA-95 network
architecture
Pay: ₹1,500,000.00 - ₹2,000,000.00 per year
Work Location: In person