Group Chief Information Security Officer

4 days ago


maharashtra, India Aditya Birla Group Full time

ABG Group Chief Information Security Officer (GCISO) will be based out of the Group Corporate Office i.e ABMCPL (Aditya Birla Management Corporation Limited) and will lead and oversee the information security strategy and operations of our diversified conglomerate across 36 countries. The GCISO is responsible for ensuring the confidentiality, integrity and availability of our data, systems and assets, as well as managing the security risks and compliance requirements of our diverse businesses.

The GCISO reports directly to the Group CIO and is a key member of IT and Digital leadership team of ABG. The GCISO works closely with the business unit leaders, IT heads, legal and regulatory teams, and external stakeholders to align the information security vision and objectives with the group's overall strategy and goals.



Responsibilities:



  • Define and implement the group-wide information security framework, policies, standards, guidelines and best practices, in alignment with the industry benchmarks and regulatory requirements.
  • Establish and maintain the information security governance structure, including the roles, responsibilities, committees, processes and metrics to measure and monitor the effectiveness and performance of the information security program.
  • Develop and execute the information security roadmap, budget and resource allocation, and prioritize the initiatives and projects based on the risk assessment and business impact analysis.
  • Lead and manage the information security team, including hiring, training, mentoring and evaluating the staff, and ensuring their professional development and career growth. The current team size is 10 FTEs.
  • Oversee the information security operations, including the identification, prevention, detection, response and recovery from cyber threats and incidents, and the implementation and maintenance of the security tools and technologies: Endpoints, Perimeter, Monitoring, Attack Surface Monitoring, Brand protection, Security Orchestration system, Threat Intelligence, etc.
  • Coordinate and collaborate with the business units, IT teams, internal audit, legal and compliance, and external partners and vendors to ensure the integration and alignment of the information security policies and controls across the group. Group CISO also chairs the group CISO council and directs all the business CISOs.
  • Promote and foster the information security awareness and culture among the employees, customers, suppliers and other stakeholders, and provide regular communication and reporting on the information security status, issues and trends.
  • Stay abreast of the latest information security developments, trends, threats, vulnerabilities, best practices and standards, and provide strategic guidance and recommendations to the senior management and the board.



Qualifications: A bachelor's degree or higher in computer science, information technology, information security, or related field, and relevant professional certifications such as CISSP, CISM, CISA, CRISC, etc



Required Skills:



  • At least 20 years of progressive experience in information security, risk management, IT governance, or related domains, preferably in a diversified conglomerate or a large multinational organization
  • Proven track record of designing, implementing and managing a comprehensive and effective information security program, and delivering successful outcomes and value to the business
  • Strong leadership, communication, presentation and interpersonal skills, and the ability to influence and collaborate with senior executives, peers, staff and external parties
  • Strategic, visionary> and innovative mindset, and the ability to balance the big picture and the details, and the risks and the opportunities
  • Sound knowledge and understanding of the information security principles, practices, standards, frameworks, regulations and laws, and their applicability and implications to different business sectors and geographies



  • Mumbai, Maharashtra, India Hyrmus Full time

    **Job Title**: Information Security & Compliance Officer (Alternate Title: Infosec Auditor & Governance Manager) **Location**: Mumbai (or Hybrid as per business need) **Reporting To**: Chief Information Security Officer (CISO) / Head of Technology **Purpose of the Role**: To manage and coordinate all Information Security audits, respond to auditor/banker...


  • Mumbai, Maharashtra, India Barclays Full time

    Job Title: Business Information Security Officer Location: Mumbai About Barclays Barclays is a British universal bank. We are diversified by business, by different types of customers and clients, and by geography. Our businesses include consumer banking and payments operations around the world, as well as a top-tier, full service, global corporate and...


  • Pune, Maharashtra, India Gentrack Full time

    **The Company** Gentrack provides leading utilities across the world with innovative cleantech solutions. The global pace of change is accelerating, and utilities need to rebuild for a more sustainable future. Working with some of the world’s biggest energy and water companies, as well as innovative challenger brands, we are helping companies reshape what...


  • Lower Parel, Mumbai, Maharashtra, India Morpheus Human Consulting Full time

    Job Title: Chief Information Security Officer - Financial Services - Mumbai Job Description: Our client is a non-banking finance company "NBFC" registered with the Reserve Bank of India as a systemically important non-deposit taking company. They are a professionally managed and institutionally owned organization engaged in providing structured term...


  • Mumbai, Maharashtra, India PaywithRing Full time

    As the Chief Information Security Officer (CISO) at Ring, you will be responsible for overseeing and implementing comprehensive security strategies to safeguard our organization's information assets and ensure compliance with industry regulations. You will play a critical role in maintaining the confidentiality, integrity, and availability of our data,...


  • Mumbai, Maharashtra, India Kuber and Company Full time

    **Job Title: Information Security & Compliance Officer** **(Alternate Title: Infosec Auditor & Governance Manager)** **Location**:Mumbai (or Hybrid as per business need) Reporting To: Chief Information Security Officer (CISO) / Head of Technology **Purpose of the Role**: To manage and coordinate all Information Security audits, respond to auditor/banker...


  • Pune, Maharashtra, India Davies Full time

    **Description**: - We are seeking a proactive and knowledgeable Information Security Officer to support the business across all aspects of information security. This role is essential in maintaining and strengthening our security posture, ensuring compliance with our regulatory and legal requirements, including maintaining our ISO/IEC 27001 certification. -...


  • Mumbai, Maharashtra, India BNP Paribas Full time

    **Job Description - APAC** **Note to Hiring Manager**: Job Title: Chief Information Security Officer Date: August 2024 Department: IT **Location**: Mumbai, India Business Line / Function: ITO CCCO Reports to: (Direct) SIPL COO Grade: (if applicable) (Functional) APAC Head -Business and Information Security Number of Direct...


  • Mumbai, Maharashtra, India Société Générale Full time

    **Responsibilities**: **Department Description**: Reporting to the Group Chief Operating Office Unit (GCOO), the Information Security and Risk (ISR) department in Asia is responsible for securing and steering Information Security and Cybersecurity related risks falling under Global Banking & Investor Solutions' (GBIS) remit. **Main Responsibilities** - Lead...


  • Powai, Mumbai, Maharashtra, India CRISIL Full time

    **Role / Designation**: Manager - Information Security Governance, Risk & Compliance Job Level: 12A/13A Job location: Mumbai Employment type: On-Roll Reporting Manager: Chief Information Security Officer Accountabilities: 1. Establishing and maintaining Information security program conforming to ISO/IEC 27001:2015 for uplifting the cyber resilience and...