
Business Information Security Officer
5 days ago
JOB PURPOSE
To manage & support Mumbai IT Operations conforming to Corporate IT Policies & Procedures, Vendor Management, corporate IT security, Compliance & governance defined to satisfy the business needs.
The purpose of the position is to manage and enhance Cyber Security posture of respective GMR Businesses, working closely with Group CISO. In the current environment of digital interconnectivity, GMR has accepted technological advances related to cloud computing and mobility solutions. Additionally, Legal and Regulatory compliance requirements for IT are influencing the landscape of IT. Securing information assets is therefore crucial for protecting the company s reputation and meeting its business objectives. The position is intended to give additional focus to the operational and compliance tasks of IT Security of the airports.
ORGANISATION CHART
KEY ACCOUNTABILITIES
Accountabilities Key Performance Indicators
Work under guidance of Group CISO and Business CIO, and be responsible for Information security operations, Risk management and Security Solutions for the business.
1. Information security program maturity
2. Effective compliance to Information security policies, processes and procedures
3. Ability to timely identify, communicate and mitigate business information security risks
4. Effective organizational information security culture
5. Performance of information security metrics within SLAs and project execution per plan
6. Continuous learning and certification attainment.
7. Stakeholder feedback on security initiatives and support.
8. Effectiveness of security controls and technologies.
9. Completion rates of security training programs.
10. Reduction in identified vulnerabilities and risks over time.
11. Compliance with regulatory standards (Cert-In, NISST, ISO, DPDP) and industry-specific OT security frameworks (e. g. , ISA/IEC 62443).
Establish and maintain governance frameworks, policies, and procedures to ensure effective management of information security risks, including those specific to Operational Technology (OT).
Build and maintain effective relationship with a Business and Technology stakeholders to effectively drive information security program vision.
Maintain and communicate the Information security controls health and program status to the management.
Own and communicate the roadmap for Information security, aligned with Group information security strategy and program.
Conduct regular risk assessments and vulnerability evaluations specific to airport and energy plant IT / OT environments.
Implement risk mitigation measures and monitor the effectiveness of controls to reduce security risks related to IT/ OT systems.
Lead incident response planning and execution for cybersecurity incidents affecting both IT and OT environments in airport and energy plant operations. Coordinate with internal teams and external stakeholders to investigate and respond to security breaches and incidents promptly, ensuring minimal disruption to operations.
KEY ACCOUNTABILITIES - Additional Details
Foster a culture of security awareness and compliance throughout the organization, including OT systems and their integration with IT
Ensure compliance with relevant regulatory requirements, industry standards, and best practices related to information security in airport and energy sectors
Collaborate with IT and OT teams to implement and manage security technologies, including firewalls, intrusion detection systems, endpoint protection, and specialized OT security solutions.
Monitor security infrastructure for vulnerabilities and recommend improvements to enhance overall security posture in both IT and OT domains.
Coordinate testing and validation of contingency plans to ensure readiness for potential disruptions or disasters affecting critical infrastructure
Plan, build and deliver Information Security services and initiatives to:
support Information security compliance activities and audits, including regular policies and configuration reviews
run projects for security capability / maturity improvement in line with group s Information security vision
deliver point services such as vulnerability assessments, project risk assessments, architecture reviews
perform technical security review (infra, apps, processes) for business/ technology initiatives and any changes to the environment
Advise business stakeholders on how to achieve the relevant Information security controls and assist with solutions to support them.
Effectively represent business in front of Government sectoral and nodal cybersecurity and investigative agencies like Bureau of Civil Aviation Security (BCAS), National Critical Information Infrastructure Protection Center (NCIIPC), Cert-IN, CBI etc.
EXTERNAL INTERACTIONS
Internal - Roles you need to interact with inside the organization to enable success in your day to day work
Human Resources (Manager or other applicable roles) To enable processes related to user awareness
Facilities Management (Manager or other applicable roles) To enable processes related to Physical Security.
Legal and Compliance (Manager or other applicable roles) To enable implementation of Legal and Compliance requirements such as IT Act.
Ethics and Integrity (Manager or other applicable roles) To facilitate investigations.
External Corporate Communications (Manager or other applicable roles) To ensure public facing websites are secure.
INTERNAL INTERACTIONS
External - Roles you need to interact with outside the organization to enable success in your day to day work
Consulting partner who manages security solutions and processes of GMR
OEMs whose security solutions are implemented / planned to be implemented
Government agencies such as Cert-IN, NCIIPC etc.
FINANCIAL DIMENSIONS
Ensure Cost within the AOP
OTHER DIMENSIONS
Handling Outsourced local IT Helpdesk & BMC Helpdesk at Bangalore (Total 2 Nos)
Vendors (10 Nos)
EDUCATION QUALIFICATIONS
-
- Graduate with interest in the area of Information Security/ Cyber Security/ Network Security/ Application Security/
-
Mobile Security
-
- Understanding of security frameworks from ISO, OWASP, NIST, Gartner
-
- Analytical and problem solving ability
-
- Graduate (B. E, B Tech) with expertise in areas of IT Security / Cyber Security / Network Security / Information Security
-
- Security certifications such as CEH, CISSP, CISM, ECSA etc.
-
- Understanding of security frameworks from ISO, OWASP, NIST, Gartner
-
- Security experience in areas/tools related to Network, Wireless, Mobile, Cloud or SIEM solutions
-
Excellent analytical and problem solving ability.
RELEVANT EXPERIENCE
-
- Relevant experience 8 10 years in Cybersecurity.
-
- Total experience approx. 15 years
-
- Has worked in capacity of Information Security Manager / Leader for organization of similar complexity. Else worked in the top team of the Cybersecurity organization in an organization of repute.
-
- Must have skills: Information Security, Network & Application Security, CEH, CISSP
-
COMPETENCIES
- Networking
- Personal Effectiveness
- Teamwork & Interpersonal influence
- Stakeholder Focus
- Entrepreneurship
- Capability Building
- Social Awareness
- Planning & Decision Making
- Execution & Results
- Strategic Orientation
- Problem Solving & Analytical Thinking
Role:Head - Information Security
Industry Type:Engineering & Construction
Department:IT & Information Security
Employment Type:Full Time, Permanent
Role Category:IT Security
Education
UG:B.Tech/B.E. in Production/Industrial, Any Graduate
PG:Any Postgraduate
-
Information Security Officer
2 weeks ago
Hyderabad, Telangana, India HRmind Full timeJob Overview : The Information Security Officer (ISO) will be responsible for leading the company's information security program and ensuring the confidentiality, integrity, and availability of the company's information assets. The ISO will report directly to the Head Digital Transformation and work closely with the executive team to develop and implement...
-
Chief Information Security Officer
2 weeks ago
Hyderabad, Telangana, India iBASIS Full timeChief Information Security Officer Location : Hyderabad India. Department : IT/IS.ABOUT iBASIS : iBASIS is the leading communication solutions provider enabling operators and digital players worldwide to perform and transform. iBASIS is the first independent international communications specialist, ranking as the third largest global wholesale voice operator...
-
Safety Officer
2 weeks ago
Hyderabad, Telangana, India SAFETY OFFICER Full time ₹ 1,04,000 - ₹ 1,30,878 per yearCompany DescriptionWe suggest you enter details here.Role DescriptionThis is a full-time on-site role for a Safety Officer, located in Hyderabad. The Safety Officer will be responsible for overseeing day-to-day operations to ensure health and safety compliance. Responsibilities include conducting occupational health assessments, accident investigations, and...
-
Chief Information Security Officer
2 weeks ago
Hyderabad, Telangana, India iBASIS Full timeThe Chief Information Security Officer (CISO) will serve as the executive owner of the companys information and cyber security strategy, overseeing all aspects of security operations, governance, and risk management.The CISO will be responsible for protecting iBASISs critical telecom infrastructure, customer data, intellectual property, and global services...
-
Manager, Information Security
2 weeks ago
Hyderabad, Telangana, India NTT DATA Business Solutions Full time ₹ 15,00,000 - ₹ 20,00,000 per yearAs part of the global NTT DATA Group, one of the most successful IT service providers in the world, we specialize in value-added SAP solutions as NTT DATA Business Solutions. With over 16,000 employees in more than 30 countries, we design, implement, and develop custom-fit SAP solutions for our global customers.Would you like to take the next step in your...
-
Information Security Analyst
2 weeks ago
Hyderabad, Telangana, India NTT DATA Business Solutions Full time ₹ 9,00,000 - ₹ 12,00,000 per yearWe want to shape the future with vision and innovation. Be part of it and develop your full potential NTT DATA Business Solutions is a global leader in transforming SAP solutions into value for clients. With operations in over 30 countries and a team of more than 16,000 experts worldwide, we drive innovation and connect business opportunities with the latest...
-
Chief Information Security Officer
1 week ago
Hyderabad, Telangana, India beBeeInformation Full time ₹ 1,50,00,000 - ₹ 2,00,00,000About Information Security RolesCandidates with a strong background in information security are sought to lead and mentor regional teams. This includes managing daily operations, collaborating with global leadership, and delivering solutions for risk management, data protection, customer assurance, and compliance.Key ResponsibilitiesCollaborate with Global...
-
Chief Information Security Officer
2 weeks ago
Hyderabad, Telangana, India Kshema General Insurance Limited Full time ₹ 15,00,000 - ₹ 20,00,000 per yearAbout UsKshema General Insurance Limited (Kshema) was established in 2018 and is India's only Digital Agri Insurance Company catering to farmers/cultivators in the Agriculture Sectors. Kshema enables cultivators with resilience from financial distress due to extreme climate events and perils through localised insurance products. Kshema is leveraging...
-
Head of Information Security
2 weeks ago
Hyderabad, Telangana, India CUBE CONSULTANCY SERVICES Full timeWith a growing workforce of 170 employees, we are committed to maintaining the highest standards of security and integrity in all our operations. We are seeking a dynamic and experienced Chief Information Security Officer (CISO) to join our team and lead our cybersecurity initiatives.Job Responsibilities :- Develop, implement, and monitor a strategic,...
-
Information Security Executive
2 weeks ago
Hyderabad, Telangana, India Solvitecno LLP Full time US$ 90,000 - US$ 1,20,000 per yearJob Title:Information Security Executive / Senior Executive - SOL00064Job Type:Full TimeLocation:Hyderabad, TelanganaExperience Required:3 – 4 YearsJob Description:Our client, headquartered in the USA with offices globally is looking for a proactive and skilledInformation Security Executive / Senior Executiveto join our team. The ideal candidate should...