Head- Cybersecurity
Deepak Nitrite · Vadodara, Gujarat, India
Deepak Nitrite · Vadodara, Gujarat, India
**Role Title**: Head- Cybersecurity **Reporting To:** Chief Information Officer **Location of Posting**: Vadodara-Corporate Office **Position Overview** This role is to lead the Cyber Security & Compliance product group. This includes the Application Security team, responsible for security assurance of applications (Design and architecture review, SAST, and DAST); Infrastructure Security team, responsible for security assurance of all Infrastructure components (such as patch and configuration compliance scanning and reporting); and Vulnerability Management, responsible for the identification, triage, scanning, and reporting against all vulnerabilities in the environment. The lead includes overall leadership of these Application Security, Infrastructure Security, and Vulnerability Management teams; ownership of multiple relevant security controls and all the associated assurance and compliance activities; definition, collection, and reporting of relevant data points to support this activity; maintenance and configuration of associated technology capabilities; and strategy and roadmap development for the product group **Key Responsibilities:** 1. Strategic Leadership - Define and implement the organizations cybersecurity vision, strategy, and roadmap aligned with business objectives. - Establish governance frameworks, policies, and standards for information security. 2. Risk Management - Identify, assess, and mitigate cybersecurity risks across all business units. - Oversee risk assessments, vulnerability management, and penetration testing programs. 3. Security Architecture & Operations - Design and maintain secure IT infrastructure, networks, and applications. - Ensure robust incident detection, response, and recovery mechanisms. - Lead implementation of advanced security technologies (e.g., SIEM, EDR, IAM). 4. Compliance & Regulatory Adherence - Ensure compliance with relevant laws, regulations, and industry standards (ISO 27001, NIST, GDPR, etc.). - Manage audits and certifications related to cybersecurity. 5. Incident Response & Crisis Management - Develop and maintain incident response plans. Lead investigations and remediation of security breaches or cyberattacks. 6. Stakeholder Engagement - Collaborate with executive leadership, IT teams, and business units to integrate security into processes. - Act as the primary liaison for external regulators, auditors, and cybersecurity partners. 7. Team Development - Build and lead a high-performing cybersecurity team. - Provide training and awareness programs for employees to foster a security-first culture. 8. Continuous Improvement Monitor emerging threats, trends, and technologies. Drive innovation in cybersecurity practices and tools. Note: The Description hereinabove is indicative of the Duties and Responsibilities and is subject to change in view of the dynamic nature and requirements of the business. **Education Qualification:** Bachelors degree in computer science, Information Technology, Cybersecurity, or related field. Masters degree (preferred) in Cybersecurity, Information Assurance, or Business Administration (MBA with IT focus). CISSP - Certified Information Systems Security Professional (Preferred) CISM - Certified Information Security Manager (Preferred) CISA - Certified Information Systems Auditor CEH - Certified Ethical Hacker (Preferred) ISO 27001 Lead Implementer / Lead Auditor (Good to have) Cloud Security Certifications (e.g., CCSK, AWS Certified Security Specialty) Risk & Compliance Certifications (e.g., CRISC) (Preferred) **Experience:** 15+ years in IT and cybersecurity roles. 10 years in leadership positions managing cybersecurity programs. **Proven experience in:** - Designing and implementing enterprise-wide security strategies. - Managing large teams and budgets. - Handling regulatory compliance and audits. - Incident response and crisis management. **Technical Competencies/Skills:** 1. Deep knowledge of ISO 27001, NIST CSF, CIS Controls, and other security frameworks. 2. Familiarity with GDPR, PCI-DSS, and regional compliance requirements. 3. Expertise in firewalls, IDS/IPS, VPNs, and secure network architecture. 4. Strong understanding of cloud security (AWS, Azure, GCP). 5. Implementation of Single Sign-On (SSO), Multi-Factor Authentication (MFA). 6. Role-based access control and privileged access management. 7. Advanced skills in SIEM tools (Splunk, QRadar, etc.). 8. Proficiency in threat hunting, forensics, and malware analysis. **Behavioural Competencies:** 1. Proactive, motivated, and driven, Ethical team player, Strong interpersonal skills, Emotional maturity, 2. Multitasking, Self-motivated with the ability to work in a fast-moving environment, Strong verbal and written communication skills, highly organized and able to prioritize under pressure, Detail- oriented, 3. Proven ability to deal with highly confidential and sensitive information.