Search Jobs

Search by job, company or skills

Information Security, GRC & Security Operations

Information Security, GRC & Security Operations

Sony Pictures Networks India
  • Posted 11 hours ago
  • Be among the first 10 applicants

Job Description

PURPOSE:

Lead and continuously improve SPNI's information security program across governance, risk, compliance, architecture, cloud, identity, vulnerability management and incident response. Align business needs with Sony Global policies, ISO/IEC 27001:2022, SOX/ITGC and applicable legal, regulatory and contractual requirements, including India's DPDP Act readiness, while translating security requirements into practical controls across on-premises, AWS, Azure, Microsoft 365 and hybrid environments.

KEY RESPONSIBILITIES:

1. Governance, ISMS, Compliance & Assurance

• Own and continually improve the ISO/IEC 27001:2022-aligned ISMS; maintain scope, risk methodology, Statement of Applicability, treatment plans and evidence; manage certification/surveillance audits, management reviews and governance forums.

• Develop and periodically review security policies, standards, procedures and frameworks; establish control ownership, review cycles, exception handling, escalation, audit readiness and remediation assurance for Sony Global requirements, SOX/ITGC and applicable obligations.

• Define executive KPIs/KRAs and dashboards covering material risks, control gaps, compliance status, remediation priorities, critical exposure, aging, recurrence, vendor risk and operational performance.

2. Enterprise & Third-Party Risk Management

• Lead periodic and change-triggered risk assessments across business processes, technology, projects and suppliers; maintain a consolidated register with owners, ratings, actions, target dates, residual risk and formal acceptance; escalate overdue or material exposures.

• Assess emerging threats, technology and regulatory developments; agree proportionate mitigation with business and technology stakeholders and communicate significant weaknesses to leadership.

• Own the third-party risk framework: classify vendors by criticality, data, privilege and dependency; perform security/privacy due diligence; evaluate responses and assurance reports; track gaps and residual risk; periodically reassess and monitor critical/high-risk vendors.

• Partner with Procurement and Legal to embed security, confidentiality, personal-data protection, incident reporting, subcontracting and exit clauses, and report unresolved material vendor risk.

3. Security Architecture, Network, Cloud & Platform Security

• Review on-premises, cloud and hybrid designs, including firewalls, VPN, proxy/SWG, IDS/IPS, DNS, TLS, load balancers, WAF, DDoS controls, AWS Direct Connect, Azure ExpressRoute and site-to-site VPN; apply Zero Trust and least privilege, validate implementation, and document exceptions/residual risk.

• Oversee hardening procedures for servers, databases, workstations, laptops and mobile devices; assess backup protection, recovery access and resilience controls.

• Assess AWS accounts and Azure subscriptions across IAM/Entra ID, privileged/service/workload identities, networking, compute, storage, management plane, KMS/Secrets Manager/Key Vault, CloudTrail, GuardDuty, Security Hub, Azure Activity Logs and Defender for Cloud; prioritize posture findings and support secure baselines, IaC reviews and automated checks.

• Assess Microsoft 365, including Exchange Online, SharePoint, OneDrive and Teams; review MFA, Conditional Access, PIM, authentication methods, legacy authentication, guest/external access, application consent, enterprise apps and service principals.

• Review phishing, malicious attachment, impersonation and BEC protection; evaluate Defender for Office 365/XDR; validate audit logging and centralized monitoring; review sensitivity labels, DLP and external sharing with data owners/compliance teams.

4. Vulnerability, Monitoring & Incident Response

• Continuously improve vulnerability platforms, processes and coverage across servers, endpoints, network devices, cloud workloads, web applications and internet-facing assets; perform authenticated scans, configuration reviews and authorized validation using Qualys, Nessus and Burp Suite.

• Validate findings and false positives; prioritize by exploitability, criticality, exposure and business impact; agree SLAs, compensating controls and risk acceptance; retest fixes, preserve closure evidence and coordinate with Global Vulnerability Management/regional teams.

• Monitor and investigate SIEM, endpoint, network, cloud, identity and Microsoft 365 alerts; correlate telemetry, distinguish false positives/configuration issues/incidents, determine scope and attack paths, and execute authorized containment and remediation.

• Support recovery, evidence preservation, root-cause analysis and accurate timelines; improve detections, queries, playbooks, alert tuning and log onboarding; conduct threat hunting, simulations/tabletops, document lessons and track corrective actions. Escalate personal-data or regulatory matters to Legal, Privacy and GRC.

• Investigate identity compromise, suspicious sign-ins, malicious inbox rules, risky OAuth apps and unauthorized sharing.

5. AI Security, Awareness, Reporting & Collaboration

• Assess AI-enabled services for sensitive-data exposure, permissions, third-party processing, insecure connectivity, prompt injection, unsafe tool access and unintended disclosure; review approved use, access restrictions, logging and protection settings with Architecture, Legal, Privacy and GRC.

• Run a risk-based security/privacy awareness program using LMS training, phishing simulations and targeted education; measure completion, reporting behavior and repeat susceptibility, and promote good practice among employees, vendors and stakeholders.

• Maintain architecture reviews, assessment reports, incident records, technical procedures and remediation evidence; support audits with technical evidence and control validation; communicate clearly to technical and non-technical audiences.

• Collaborate with Global Information Security Operations, Global Vulnerability Management, Infrastructure, Cloud, Network, Applications and local teams; automate assessments, alert enrichment and reporting through scripting/APIs; stay current on threats, attack techniques and security technologies.

EXPERIENCE, QUALIFICATIONS & SUCCESS MEASURES:

• Minimum 8+ years of cybersecurity experience, including enterprise GRC ownership and at least 5 years of substantive vulnerability-management and incident-response experience.

• Hands-on ownership of an ISO/IEC 27001-aligned ISMS, audits, security risk/control assurance, policy governance, audit remediation, third-party risk and executive reporting.

• Hands-on security across AWS, Azure and Microsoft 365, with depth in at least one cloud; cloud IAM/Entra ID, PIM, MFA and Conditional Access; infrastructure, application, identity and data-protection controls.

More Info

Job Type:
Industry:
Function:
Employment Type:

Similar Jobs

10-15 yrs
Mumbai, India
Skills:
Iso 27001, Incident Response Frameworks, Access Control, Cyber Security Framework, Disaster Recovery Planning, Risk Management
10-12 yrs
Mumbai, India
Skills:
Incident Response, Iso 27001, Application Security, cloud security, Data Protection, Information Security, Identity And Access Management, Security Operations, NIST CSF, security frameworks, SOC 2
5-8 yrs
Mumbai, India
Skills:
openvas , Ceh, Application Security, Qualys, Nessus, Cisa, ISO 27001 LA LI, SIEM platforms, encryption standards, vulnerability scanning tools, Cissp, data privacy regulations
7-10 yrs
Mumbai, India
Skills:
Cloud security, Metasploit, Penetration Testing, Nmap, Burp Suite, Iso 27001, Incident Response, Grc, Siem, Data Protection, Application Security, DPDP Act 2023, Phishing simulations, Social engineering tests, Security Architecture, DPIAs, nist, Security governance
5-10 yrs
Delhi, Kolkata, Mumbai
Skills:
Digital Forensics, Siem, Incident Response, Active Directory, MITRE ATT&CK, SOAR