It Security Officer
Aarti Industries · Navi Mumbai, Maharashtra, India - Vadodara, Gujarat, India
Aarti Industries · Navi Mumbai, Maharashtra, India - Vadodara, Gujarat, India
**Job Responsibilities** - Manage security configurations and policies across Firewalls, Proxy, SIEM, Secure Web Gateway (SWG), Data Loss Prevention (DLP), Zero Trust Network Access (ZTNA), EDR/XDR, IPS, and other cybersecurity solutions. - Conduct security assessments through Vulnerability Assessments, risk analysis, and security reviews. - Perform self-assessments against cybersecurity standards and frameworks such as NIST CSF and ISO 27001. - Support the implementation and sustenance of ISO 27001:2022. Assist IT teams during internal and external audits, risk assessments, and compliance activities. - Maintain and continuously improve the organization's Incident Response Plan (IRP), Disaster Recovery (DR), and Business Continuity (BCP) security requirements. - Ensure compliance with email security standards including SPF, DKIM, and DMARC, and manage anti-spam and anti-phishing controls. - Manage and implement security controls for cloud environments (AWS, GCP, and Google Workspace), including IAM, security monitoring, logging, data protection, and compliance. - Ensure timely closure of SOC incidents, reduce false positives, improve Mean Time to Respond (MTTR), and implement SOAR playbooks for repetitive security use cases. - Possess working knowledge of API Security, Web/Application Security (WAF), and Vulnerability Assessment & Penetration Testing (VAPT). - Have working knowledge of Operational Technology (OT) Security, IEC 62443 standards, Purdue Model, industrial network segmentation, and secure remote access. - Perform third-party/vendor security assessments and ensure compliance with organizational security requirements. - Investigate security incidents and prepare reports detailing root cause, impact, and corrective actions. - Stay updated with the latest cybersecurity threats, vulnerabilities, technologies, and industry best practices. - Develop, review, and maintain cybersecurity policies, standards, procedures, and security documentation. - Recommend security improvements and risk mitigation measures to management and IT leadership. - Provide technical guidance to IT teams and end users on cybersecurity tools, secure practices, and security procedures. - Drive cybersecurity awareness programs, phishing simulation campaigns, and user awareness initiatives independently. **Additional Responsibilities** - Monitor cybersecurity posture through security dashboards, KPIs, and compliance metrics. - Coordinate with SOC, IT Infrastructure, Cloud, and Application teams for timely remediation of security findings. - Manage vulnerability remediation and patch compliance by working closely with infrastructure and application teams. - Review firewall, VPN, privileged access, and security rule change requests from a cybersecurity perspective. - Participate in new IT project reviews and ensure Security by Design principles are incorporated. - Ensure compliance with regulatory requirements such as DPDPA, CERT-In directions, and other applicable cybersecurity regulations. - Evaluate new cybersecurity technologies and recommend security improvements based on business requirements. - Support cyber incident investigations, digital forensics, and evidence collection when required.