|
Top dimensions:
Geography: India / Enterprise-wide
Direct reports: NA
Complexity of the role (Optional): High
Will this job require travel (Y/N): As per business requirements
|
Matrix Reports: NA
Type of Role: Individual Contributor
Primary Stakeholders (Optional):
|
|
What are the Key Deliverables in this role?
Financial Outcomes
- Support risk-based cybersecurity investment decisions by providing visibility on cyber risks, maturity gaps and control priorities.
- Drive governance over cybersecurity programs to ensure timely delivery, value realization and effective utilization of security investments.
- Reduce potential financial exposure from cyber incidents, audit gaps, regulatory non-compliance and third-party security failures.
Customer Service
- Enable secure and trusted digital services for internal and external stakeholders through effective cybersecurity governance.
- Partner with business, IT and digital teams to embed cybersecurity requirements into business and technology initiatives.
- Provide timely cyber risk insights, governance inputs and recommendations to support leadership decision-making.
Internal Processes
- Lead the enterprise Cyber Security Governance and Risk Management program, including frameworks, policies, standards and procedures.
- Drive development and execution of the Cyber Security Strategy and multi-year security roadmap.
- Establish cyber risk identification, assessment, treatment, acceptance, monitoring and executive reporting mechanisms.
- Drive cybersecurity maturity assessments using frameworks such as ISO 27001, NIST CSF and relevant regulatory expectations.
- Establish and monitor cyber KPIs, KRIs, dashboards and management reporting for governance forums.
- Provide governance oversight across IAM/PAM, vulnerability management, endpoint security, cloud security, application security, data protection, SOC/SIEM and incident management.
- Lead third-party cybersecurity risk management, audit coordination, compliance reviews and remediation tracking.
- Support cyber incident governance, post-incident reviews, business continuity, disaster recovery and cyber resilience initiatives.
- Lead AI Governance and AI Risk Management, including responsible AI controls, AI risk assessments
Innovation and Learning
- Drive continuous improvement of cybersecurity governance, assurance and risk management processes.
- Promote automation and data-driven reporting for cyber risk, compliance, KPIs and maturity tracking.
- Lead adoption of emerging governance practices in AI security, digital risk, cyber resilience and regulatory compliance.
- Mentor and develop cybersecurity governance team members and service-provider resources.
|
|
What are the Critical success factors for the Role?
- Strong experience in cybersecurity governance, risk management, assurance and compliance.
- Ability to translate technical cyber risks into business impact and executive-level insights.
- Strong knowledge of ISO 27001, NIST CSF, cyber risk management and enterprise security controls.
- Experience in managing cyber audits, regulatory assessments, risk registers and remediation programs.
- Strong stakeholder management skills across IT, business, digital, privacy, legal, risk and audit teams.
- Ability to lead cybersecurity programs, governance forums, service providers and cross-functional initiatives.
- Strong written and verbal communication skills for management and executive reporting. Mandatory Language Requirements (spoken), if any: English
What are the Desirable success factors for the Role?
- Experience in AI Governance, ISO 42001, privacy, business continuity and cyber resilience.
- Exposure to third-party risk management, security metrics automation and GRC platforms.
- Certifications such as CISM, CRISC, ISO 27001 Lead Auditor / Lead Implementer, or ISO 42001 preferred.
- Experience in large, distributed or consumer-focused enterprises would be an advantage.
|