Job Title: Head of Information Security
Location: Pune
Department: Information Security
Job Summary: The Head of Information Security will be responsible for establishing and maintaining the companys information security strategy and programs. This role involves identifying evaluating and reporting on information security risks in a manner that meets compliance and regulatory requirements. The Head of Information Security will also work closely with various departments to implement and manage security measures to protect sensitive data and ensure the integrity confidentiality and availability of information.
Key Responsibilities:
- Strategic Leadership:
- Develop and implement a comprehensive information security strategy and program.
- Align the security strategy with business goals and objectives.
- Advise senior management on information security risks and mitigation strategies.
- Risk Management:
- Identify assess and prioritize information security risks.
- Develop and maintain risk management frameworks and processes.
- Conduct regular security risk assessments and audits.
- Policy and Compliance:
- Develop implement and maintain security policies standards and procedures.
- Ensure compliance with relevant laws regulations and industry standards (e.g. GDPR CCPA ISO/IEC 27001SOC 2.
- Coordinate securityrelated audits and assessments.
- Incident Management:
- Develop and implement an incident response plan.
- Lead the response to security incidents and breaches.
- Conduct postincident analysis and reporting.
- Security Operations:
- Oversee the implementation and management of security technologies (e.g. firewalls IDS/IPS SIEM).
- Monitor security events and respond to alerts.
- Conduct vulnerability assessments and penetration testing.
- Training and Awareness:
- Develop and deliver security training programs for employees.
- Promote security awareness across the organization.
- Ensure employees understand and adhere to security policies and procedures.
- Collaboration and Communication:
- Work closely with IT Legal HR and other departments to ensure integrated security efforts.
- Communicate security risks and strategies to stakeholders.
- Represent the company in securityrelated forums and committees.
Qualifications:
- Bachelors degree in Computer Science Information Security or a related field. Masters degree preferred.
- Professional certifications such as CISSP CISM or CISA.
- Minimum of 10 years of experience in information security with at least 5 years in a leadership role.
- Strong knowledge of information security management frameworks (e.g. ISO/IEC 27001 NIST SOC2.
- Experience with security technologies and tools.
- Excellent leadership communication and interpersonal skills.
- Ability to think strategically and manage multiple projects simultaneously.
- Strong analytical and problemsolving skills