- Develop and execute the organization's cybersecurity strategy, ensuring alignment with business objectives and regulatory requirements.
- Lead the Information Security function and oversee security operations, governance, risk management, and compliance initiatives.
- Design and implement enterprise-wide security architecture, policies, standards, and best practices to protect critical systems and data.
- Establish and manage Security Operations Center (SOC), incident response, threat detection, vulnerability management, and cyber resilience programs.
- Drive cloud security, application security (AppSec), DevSecOps, identity and access management (IAM), and network security initiatives.
- Conduct security risk assessments, penetration testing, audits, and compliance reviews to identify and mitigate security risks.
- Collaborate with Engineering, IT, DevOps, Product, Legal, and business stakeholders to integrate security into the software development lifecycle and operational processes.
- Ensure compliance with industry standards and regulations such as ISO 27001, NIST, PCI-DSS, GDPR, and other applicable frameworks.
- Lead incident response activities, forensic investigations, disaster recovery planning, and business continuity initiatives.
- Evaluate emerging cybersecurity threats, technologies, and security solutions to strengthen the organization's security posture.
- Build, mentor, and lead high-performing cybersecurity teams while fostering a security-first culture across the organization.
- Manage third-party security vendors, security tools, budgets, and executive reporting on cybersecurity risks and performance.
Preferred candidate profile :
- Bachelor's degree in Computer Science, Information Technology, Cyber Security, Information Security, or a related field.
- 5 to 10 years of experience in cybersecurity, information security, or IT security, including experience leading security programs or teams.
- Strong expertise in Cyber Security, Information Security, Security Architecture, Cloud Security, Network Security, Application Security (AppSec), and Identity & Access Management (IAM).
- Hands-on experience with SIEM platforms (Splunk, Microsoft Sentinel, QRadar), Security Operations (SOC), Incident Response, Threat Intelligence, Vulnerability Management, and Penetration Testing (VAPT).
- Experience securing cloud environments on AWS, Microsoft Azure, or Google Cloud Platform, with knowledge of DevSecOps and Secure SDLC practices.
- Strong understanding of ISO 27001, NIST Cybersecurity Framework, PCI-DSS, GDPR, CIS Controls, and Governance, Risk & Compliance (GRC).
- Experience with firewalls, IDS/IPS, endpoint security, web application firewalls (WAF), and security monitoring tools.
- Professional certifications such as CISSP, CISM, CISA, CEH, CCSP, AWS Security Specialty, or Azure Security Engineer are highly preferred.