ISMS & Security Governance
-
Own and operate the Enterprise Information Security Governance & IT Risk Management program aligned to ISO 27001:2022, NIST CSF and DPDP Act.
-
Develop, review and renew policies, standards and SOPs; maintain the policy renewal tracker and secure stakeholder/management approvals.
-
Evaluate the organization’s security posture periodically and report to stakeholders.
Security Assessment & Technology Due Diligence
-
Conduct InfoSec assessments for new/existing projects and applications on a Secure-by-Design basis — review architecture, data flows and controls, and perform threat modelling.
-
Assess controls, identify gaps, provide residual-risk assessments and track risk-treatment actions.
-
Validate implementation (controls, VAPT, secure code review, logging/monitoring) and provide initial and final production sign-offs.
Application, API & Infrastructure Security
-
Govern application & API security — assess against InfoSec/AppSec checklists, oversee VA, PT and secure code reviews, and drive DevSecOps integration and application-layer attack mitigation.
-
Maintain MBSS / Secure Configuration Documents (SCD); oversee configuration VA and compliance reviews.
-
Maintain infrastructure security baselines, assess assets periodically, track and close observations with stakeholders.
Enterprise Vulnerability Management
-
Lead the Enterprise Vulnerability Management program across applications, infrastructure and configurations.
-
Prioritise vulnerabilities by severity, business impact and exploitability; manage exceptions and escalate overdue items.
-
Monitor remediation progress and ensure timely closure and reporting.
Cloud Security Governance
-
Implement and oversee cloud security best practices across AWS & Azure — IAM, encryption, network security and logging.
-
Conduct cloud security, gap and compliance assessments for IaaS/PaaS/SaaS and remediate misconfigurations.
-
Monitor and manage CNAPP tooling (CSPM, CIEM, CWPP) for continuous cloud posture management.
Security Operations, SIEM & Incident Management
-
Govern SIEM/SOC monitoring — asset onboarding, monthly reconciliation, use-case/detection enhancement and alert triage & closure.
-
Oversee operational management of security tools (SIEM, EDR, DLP, WAF, IDS/IPS).
-
Own incident management — detection, RCA, mitigation, monthly incident reporting and a learning matrix driving preventive controls.
Audit, Compliance & Regulatory Management
-
Manage internal, statutory, regulatory and certification audits — coordinate evidence, provide management responses/remediation plans and track observations to closure.
-
Address queries from Compliance, Internal/External Audit and Regulators; implement policy/process updates for regulatory changes.
-
Participate in CAB and assess the security implications of planned and emergency changes.
Business Continuity & Disaster Recovery
-
Maintain the annual DR drill calendar and secure committee approvals; govern DR drills for critical applications/infrastructure.
-
Validate RTO/RPO achievement, close DR observations and maintain DR documentation for audit/regulatory purposes (BIA, BCRA, FRP, IT DR drills).
Third-Party Risk & Vendor Governance
-
Drive Vendor Risk Assessment (VRA) and TPRM — maintain vendor inventory & criticality and the annual review calendar.
-
Ensure timely completion of vendor assessments, review risk ratings and track closure of identified risks.
Awareness, Resilience & Executive Reporting
-
Run monthly awareness campaigns, annual training and phishing simulations with targeted remediation; execute annual CCMP tabletop / IR simulations.
-
Prepare and present ITSC, IT Strategy Committee, RMC and Board reporting — InfoSec metrics, risk dashboards, KPI/KRI, compliance and audit status, and incident summaries; track decisions and action closure.