Role: Director - Ntwk & Info Sec
Location: Chennai, Hyderabad
Experience: 18 years-22 years
You will lead a team of cybersecurity engineers with both application development and network & infrastructure background, threat intelligence analysts and risk management personnel who work closely with our Chief Information Security Office (CISO), Global Network and Technology (GN&T) teams to align common technologies and practices that fortify our applications, systems, IT network and infrastructure. To be successful in this role, the leader must have a keen understanding of the evolving cyber landscape, inspire creativity and the ability to both encourage and empower teams to excel in this mission.
Network & Infrastructure Security Governance
- Identify, implement and operationalize metrics, dashboards, scorecards, and tracking to consistently measure the current state of cybersecurity across Network & Infrastructure, leveraging industry best practices and standards.
- Ensure effectiveness and coverage of the Security Policies and Controls of Network & Infrastructure, prioritizing risk level.
- Instill ownership and accountability for security-based metrics and drive increased maturity, visibility, and subject-matter expertise for all segments.
- Develop action plans jointly with all stakeholders to remediate deviations, providing necessary support to close on all key items.
- Champion a highly collaborative work model with an aptitude of building and maintaining relationships across different teams at multiple senior levels, internally and externally.
- Develop awareness, training & compliance programs focused on Network & Infrastructure Cyber Security practices, leveraging Security Development program.
- Ensure Security posture of Network & Infrastructure, e.g., access management, vulnerabilities remediation, etc.
- Coordinate necessary activities with our CISO Cyber Security organization: pen testing, incident response, data collection, etc.
Application Security & Risk Management
- Drive automation and orchestration of all security tools for visibility and prevention.
- Interpret the Information Technology threat landscape, security industry best practices, industry threat vectors, new technologies impacting security operations, etc.
- Technical expert in business applications, IT infrastructure and architecture - Defense in Depth Architecture and Practices.
- Experience implementing and monitoring security controls, vulnerability management, penetration testing, and identity/access management best practices.
- Track record with leading high performance operational teams.
- Background with different cloud computing platforms and the cloud security framework.
- Manage the budget for security testing, operational and monitoring tools expenses.
- Recruit, train, and lead security operations team members.
- Create and communicate security operations metrics, incidents, investigations, etc.
- Determine SLAs for detecting issues internally and with our external partners.
- Assist in Crisis Management, Ransomware Recovery and Business Continuity planning.
- Prepare reports and make presentations on internal investigations, losses, or violations of regulations, policies, and procedures.
- In partnership with the CISO team, identify, investigate and resolve global security breaches/incidents.
Security Automation Platforms
- Develop and maintain IT Applications, Network & Infrastructure Security reporting dashboards, scorecards and maturity models used to measure our Cyber practice, with a focus on data integrity, working with the SRE teams.
- Identify, build and maintain the automation platforms supporting Enterprise Network, On-Prem Infrastructure, Datacenters and Cloud organizations in their Cyber practice.
- Drive a culture of Security by Design, automation to scale cyber security practices.
Industry Engagements & Cyber Transformation
- Establish partnerships with industry leaders and forums to constantly assess new trends and solutions.
- Lead transformation towards Security by Design and Zero Trust principles for Network & Infrastructure.
- Operationalize future Cyber Security Architectures and Policies related to Network & Infrastructure, constantly raising our maturity and level of protection.
Leadership
- Lead a team of cybersecurity engineers with both network & infrastructure, security engineers, threat intelligence analysts, security champions and risk management personnel.
- Focus on employee hiring, career development, rotation and succession planning.
- Motivate staff through servant leadership.
- Identify opportunities for automation, partnering with our India team.
- Stakeholdering with multiple external teams, with sometimes competing, organizationally separate groups and goals.
- Effective communication of complex technical subjects to non-expert, cross-functional peers, with effective storytelling and proficiency when presenting to leadership.
- Cross-functional collaboration and relationship building to achieve wider, organizational strategic goals.
You’ll need to have:
- Bachelor’s degree in network engineering, computer science, IT infrastructure or related discipline.
- Ten or more years of relevant work experience in Security, IT, and/or Network.
- Strong knowledge of SDLC and DevSecOps
- One or more of the following certifications - CISSP, CCIE, CCSK, TOGAF, SABSA
- Experience managing a team of experienced, technical professionals.
- Willingness to travel.
Even better if you have one or more of the following:
- Bachelor’s degree in cybersecurity, network, engineering, computer science or related discipline.
- Ability to thrive in a dynamic environment while managing multiple high-priority projects.
- Strong strategic and collaborative skills required to energize and provide direction to teams that are cross organizational(e.g. IT, Cyber and Business).
- Experience in planning large budgets and executing on target.
- Experience with networking concepts and protocols; security and compliance.
- Strong analytical, interpersonal, project management and communication skills.
- Strong troubleshooting and problem solving abilities in order to quickly find solutions to problems where no previous examples or methods may exist.
- Ability to engage people in the vision and demonstrate the meaning of the work for the bigger purpose.