About IFACET
IFACET is a Section 8 company established to drive industry-oriented education, training, and outreach initiatives of IIT Kanpur. It aims to create a self-sustaining, professionally managed ecosystem for continuing education, industry engagement, and digital learning platforms. It operates with a startup-like agility while adhering to governance structures defined under the companies Act, 2013.
About (DDIA)
DDIA is responsible for all the Digital requirements of the IIT Kanpur such as planning, purchasing, executing, support-providing and maintaining all the digital assets and services including the cybersecurity, telephone exchange, Internet Services, etc
Role Summary
Safeguarding the organization’s information systems, digital infrastructure, networks, applications, and data assets against cyber threats, unauthorized access, and security breaches.
Key Responsibilities
1. Develop and implement cybersecurity policies, standards, procedures, and controls.
2. Monitor and protect organizational IT infrastructure from cyber threats and vulnerabilities.
3. Ensure compliance with GOI cybersecurity frameworks, CERT-In advisories, and relevant regulations.
4. Conduct risk assessments, vulnerability assessments, and security audits.
5. Lead incident detection, response, investigation, and recovery activities.
6. Manage security tools, monitoring systems, and access control mechanisms.
7. Support business continuity and disaster recovery planning.
Detailed Responsibilities
1. Cybersecurity Governance and Policy Management: Draft, review, update, and implement cybersecurity policies, SOPs, standards, and guidelines. Ensure alignment with Government of India cybersecurity mandates and organizational objectives. Establish security governance mechanisms and reporting structures.
Support implementation of ISO 27001, IT Act 2000, CERT-In directions, and other applicable standards.
2. Security Operations and Monitoring: Develop and implement system to monitor networks, servers, endpoints, and applications for suspicious activities and security incidents. Manage and oversee deployment and operation of firewalls, IDS/IPS, antivirus, SIEM, DLP, and endpoint security solutions. Analyze logs and security events to identify threats and vulnerabilities. Ensure timely patch management and system hardening activities.
3. Risk Assessment and Vulnerability Management: Conduct periodic vulnerability assessments and penetration testing (VAPT). Identify cybersecurity risks and recommend mitigation measures. Maintain risk registers and track remediation activities. Perform security reviews for new systems, applications, and technology deployments.
4. Incident Response and Cyber Crisis Management: Lead cybersecurity incident response activities including identification, containment, eradication, recovery, and post-incident analysis. Maintain incident response plans and cyber crisis management procedures. Prepare incident reports and lessons-learned documentation.
5. Compliance and Audit Management: Ensure compliance with applicable cybersecurity laws, policies, and government directives. Support internal and external security audits. Track compliance gaps and oversee corrective actions. Maintain audit records, evidence, and compliance documentation.
6. Data Protection and Information Security: Ensure protection of sensitive and confidential organizational data.
Oversee implementation of encryption, backup, archival, and data retention mechanisms. Support secure data sharing and secure communication practices. Monitor compliance with data protection requirements.
7. Security Awareness and Capacity Building: Conduct cybersecurity awareness campaigns, workshops, and training sessions. Educate employees on phishing, social engineering, password security, and safe digital practices. Promote cybersecurity culture within the organization. Support development of cyber hygiene initiatives.
8. Disaster Recovery: Support preparation and testing of Business Continuity Plans (BCP) and Disaster Recovery (DR) procedures. Ensure cybersecurity resilience for critical systems and infrastructure. Participate in cyber drills and tabletop exercises. Coordinate recovery activities during disruptions.
9. Vendor and Third-Party Security Management: Assess cybersecurity posture of vendors and service providers.
Ensure security requirements are incorporated into contracts and SLAs. Monitor third-party compliance with organizational security standards. Conduct periodic security reviews of outsourced services.
Desired Qualifications
B.Tech./B.E. with 60% mark with 6 years of relevant experience.
Or
M. Tech./M.E. after B.E./B. Tech with 60% mark with 4 years of relevant experience.
Desirable Professional Certifications:
Certified Information Systems Security Professional (CISSP)
Certified Ethical Hacker (CEH)
CompTIA Security+
Certified Information Security Manager (CISM)
ISO 27001 Lead Implementer / Lead Auditor
Certified SOC Analyst (CSA)
GIAC Certifications
Certified Cloud Security Professional (CCSP)
Desired Relevant experience domain:
Cybersecurity operations, information security, network security, SOC operations, risk management, or incident response. Familiarity with SIEM tools, security monitoring platforms, VAPT tools, and incident response frameworks.
Pay: From ₹60,000.00 per month
Work Location: In person