The successful candidate shall be responsible for the following across multiple Business Units within PSA India:
- Lead and support cybersecurity governance, risk management, and compliance programs, including IT security operations and risk assessments.
- Develop, implement, and enforce cybersecurity policies, standards, and guidelines for IT and OT environments.
- Strengthen cybersecurity readiness and resilience by managing security tools and services such as vulnerability management systems, phishing exercises, red teaming, and bug bounty programs.
- Collaborate with BU IT and business leadership to understand unique risks and tailor controls accordingly.
- Work with Regional IT and BU IT to enhance cyber awareness through training, circulars, and table-top exercises.
- Provide guidance, procedures, and control frameworks for cybersecurity matters.
- Track and report progress of initiatives, projects, KRIs, and KPIs at BU and consolidated levels.
- Perform regular security assessments, gap analyses, and improvement planning based on compliance requirements.
- Manage Vulnerability Assessments (VA) and validate Penetration Testing (PT) findings, ensuring timely remediation.
- Monitor Security Operations Center (SOC) metrics, alerts, and response activities, ensuring proper triage and incident reaction.
- Handle security incidents including detection, response, resolution, and forensic investigation.
- Review system design (network and application architecture) to identify risks and recommend mitigation measures.
- Stay updated on the evolving cybersecurity landscape, regulations, and industry standards.
Qualifications
- Degree (BSc or B.Tech) in Computer Science, Information Security, or a related field.
Required Skills
- At least 4 years of relevant IT security experience, with strong focus on GRC and managing cybersecurity across multiple business units or locations.
- At least 1 year of system administration and/or network experience.
- Strong knowledge of IT controls frameworks including ISO 27001/2, PCI-DSS, NIST, SOC2, etc.
- Understanding of on-premises and cloud infrastructures (AWS, Azure).
- Experience in security incidents, security testing, and security operations.
- Experience with VA/PT processes, SOC operations, and alert management.
- Proven ability to work with diverse teams and communicate effectively with non-technical stakeholders.
- Cohesive team player with a positive, eager-to-learn attitude.
Preferred Skills
- Understanding of OT security standards (e.g., IEC 62443)
- CompTIA Security+, CEH, ISO 27001 Lead Implementer/Auditor, or equivalent.