Cybersecurity Risk and Compliance Manager

1 week ago


Noida Berger Tower India Thales Full time ₹ 5,00,000 - ₹ 12,00,000 per year

Cybersecurity Risk and Compliance Manager

Location: Noida, IndiaThales people architect identity management and data protection solutions at the heart of digital security. Business and governments rely on us to bring trust to the billons of digital interactions they have with people. Our technologies and services help banks exchange funds, people cross borders, energy become smarter and much more. More than 30,000 organizations already rely on us to verify the identities of people and things, grant access to digital services, analyze vast quantities of information and encrypt data to make the connected world more secure.Present in India since 1953, Thales is headquartered in Noida, Uttar Pradesh, and has operational offices and sites spread across Bengaluru, Delhi, Gurugram, Hyderabad, Mumbai, Pune among others. Over 1800 employees are working with Thales and its joint ventures in India. Since the beginning, Thales has been playing an essential role in India's growth story by sharing its technologies and expertise in Defence, Transport, Aerospace and Digital Identity and Security markets.

The Security Governance & Compliance Specialist is responsible for ensuring the security of all aspects of personnel, physical and IT security at all DIS Makati R&D and Business activities as well as related topics in the region as needed. This position is also required to provide technical consultation, guidance, training and assistance to users with reference to security policy clarification and remediation, as required.

  • DIS Makati Security Governance & Compliance Specialist (R&D/BU) needs to coordinate closely with Asia
  • Business Security & Compliance Manager to ensure actions/plans align with Thales DIS security roadmap and participate in security audits both internally and externally.

The role will interface with peers in Asia Security team, Asia IT Security team and with business users (R&D, GGS, Sales, Technical Consultant, etc), to share the DIS Central security vision and to solicit their involvement in achieving high levels of enterprise security through information sharing and co-operation, manage DIS R&D / Business security risks through explicit management control and meet customers' expectations for Information Security.

Missions and Responsibilities :

At DIS Makati R&D and Business activities as well as related business security and compliance at all regional sites as needed.

  • Acting in accordance with the DIS Central Security Management System and DIS Central Security Policy to manage all aspects of R&D SW Development Security, IT Security, Personnel Security and Physical Security
  • Develop and maintain the Site Security Management System (SMS) to fulfill the regulatory requirements and ensure that an adequate level of security is enforced in all software development and new business activities.
  • Provide vision to management and take necessary steps to measure propose thesecurity controls needed to protect information and assets as well as information that has been entrusted to Thales DIS by third parties and customers.
  • Enforce implementation of Thales DIS security policies effectively identify, evaluate, monitor, report and mitigate security risks
  • Enforce R&D security compliance in the area of source code management, change management and configuration management with Asia IT Security team.
  • Proactively monitoring and manage physical security management system, such as Access Control System, Alarm System and CCTV system on daily basis.
  • Conduct Physical & Logical security audit internally and complete corrective actions within stipulated timeline.
  • Initiates, facilitates and promotes activities to raise security awareness for employees, vendors and other stakeholders as required.
  • Conduct physical and logical security assessments and evaluate new security threats and assess their impacts to Thales DIS information assets.
  • Ensure R&D center security level compliance with security standards from both DIS Central internal audit and external audit.
  • Coordinate with Asia IT Security team and ensure that firewall rule reviews, antivirus management, vulnerability management and patch management are timely performed with systems free of "Critical" issues.
  • Coordinate with Asia IT Security team and perform regular checks on R&D systems to eliminate blacklisted software and ensure compliance with Thales DIS Software Policy.
  • To formulate security audit plan with Asia Regional Security Manager and perform internal audits of all Makati DIS R&D & Business activities as needed.
  • Manage and coordinate with Security supplier, supervise service level and ensure the compliance with service contract.
  • Liaise with contractor(s) working on security equipment and ensure the contractual conformity of their performances.

Required Education/Certificate:

  • Bachelor's Degree (IT / Security / Computer Science) or equivalent.
  • Appropriate Security Qualifications or Certifications such as CISSP, CISM, CISA and/or other IT security related certification is a plus

Working Experience:

  • 3-5 Years of IT / Security Operations Experience with Physical security operations in managing access controls systems, CCTVs, alarms etc.
  • Broad experience of IT going beyond individual components (hardware, software, network, etc.)
  • Hands on experience in security solution implementations

Technical Skills:

  • Knowledge of software development process and related risks
  • Experience in implementation and monitoring security policies
  • Ability to investigate and identify root cause of security incidents.
  • Trainer experience is a plus.

Personnel Skills:

  • Must be a self-starter, with limited supervision and be able to work effectively in a challenging business environment.
  • Good analytical, presentation and reporting skills
  • Possess strong self-responsibility and teamwork skills.
  • Strong interpersonal and communication skills required.
  • Ability to liaison and communicate with all levels of people.
  • Independent, approachable and analytical; and

Language:

  • Fluent in spoken and written English and regional languages if any would be an advantage.
At Thales we provide CAREERS and not only jobs. With Thales employing 80,000 employees in 68 countries our mobility policy enables thousands of employees each year to develop their careers at home and abroad, in their existing areas of expertise or by branching out into new fields. Together we believe that embracing flexibility is a smarter way of working. Great journeys start here, apply now Experience LevelMid Level

  • Noida Berger Tower, India Thales Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Automotive Cybersecurity AnalystLocation: Noida, IndiaThales people architect identity management and data protection solutions at the heart of digital security. Business and governments rely on us to bring trust to the billons of digital interactions they have with people. Our technologies and services help banks exchange funds, people cross borders, energy...


  • India Tekskills Inc. Full time

    Job Role: Cybersecurity Compliance Manager Job Location: Pune Work Mode: (WFO / Hybrid) Skills Required : ISO 27001:2005~Cyber Security Digital: Risk Regulatory Compliance Analytics Cyber Security - Information Security Risk & Compliance Experience : 10 -14 YRS (Rel 9 yrs) Job Description: At least 7 years of experience in either data...


  • Chennai, India Freshworks Full time

    Job Description Organizations everywhere struggle under the crushing costs and complexities of solutions that promise to simplify their lives. To create a better experience for their customers and employees. To help them grow. Software is a choice that can make or break a business. Create better or worse experiences. Propel or throttle growth. Business...


  • India, Cochin / Kochi / Ernakulam Art Technology and Software Full time

    Job Description The GRC Lead will be responsible for overseeing the governance, risk management, and compliance functions within the organization. Responsibilities - Strategic Governance & Leadership - Lead the design, execution, and maturation of the organization's comprehensive GRC strategy, encompassing policy governance, risk management frameworks,...


  • Mumbai, India Baker Hughes Full time

    Job Description Cybersecurity and Compliance Analyst Are you passionate about cybersecurity, risk & compliance Would you like to be a part of successful team Please Join us! A leader in the Energy Technology Industry. Baker Hughes offers opportunities for qualified people who want to grow in our high-performance organization. Our leading technologies...


  • Noida, India Kratikal Full time

    Job Description Roles & Responsibilities: 1. Policy Documentation- Create and maintain compliance policies and procedures; translate complex regulatory requirements into clear, user-friendly documents. 2. Regulatory Compliance- Stay informed about evolving laws, standards (e.g., ISO 27001), and regulations; simplify and communicate legal content effectively....


  • Kochi, Kerala, India, Ernakulam Art Technology and Software Full time

    The GRC Lead will be responsible for overseeing the governance, risk management, and compliance functions within the organization.ResponsibilitiesStrategic Governance & LeadershipLead the design, execution, and maturation of the organization’s comprehensive GRC strategy, encompassing policy governance, risk management frameworks, compliance programs, and...


  • India Technip Energies Full time

    Job Description Job Description Be part of the solution at Technip Energies and embark on a one-of-a-kind journey. You will be helping to develop cutting-edge solutions to solve real-world energy problems. We are currently seeking a Cybersecurity - Third Party Risk Management Specialist, to join our Cybersecurity team based in Noida. About us: Technip...


  • Mumbai, Maharashtra, India, Maharashtra DBS Bank Full time

    Business FunctionTechnology and Operations (T&O) enables and empowers the bank with an efficient, nimble and resilient infrastructure through a strategic focus on productivity, quality & control, technology, people capability and innovation. In Group T&O, we manage the majority of the Bank's operational processes and inspire to delight our business partners...

  • GRC Consultant

    3 weeks ago


    India LanceSoft Middle East Full time

    Title: GRC Consultant - CybersecurityLocation: Remote In IndiaJob Type: 6 MonthsImmediate or 15 Days notice period onlyRequired Skills and Qualifications:Proven experience in D&T governance, cybersecurity, risk management, and compliance.Strong knowledge of UAEIA, ISO standards, and industry best practices.Excellent communication and stakeholder management...