Confidential Job Posting
This role is from a verified company that prefers not to disclose its name at this stage. Learn More
Location: Gurgaon
Experience: 10-12 yrs
Qualification: B.E./B.Tech/M.Tech/MCA; security certifications preferred
Key Responsibilities:
- Own the information security and infrastructure strategy, operating model, roadmap, policies, standards and annual budget in alignment with business priorities.
- Lead cybersecurity governance, enterprise risk assessments, security architecture reviews and remediation tracking; present risk posture, key metrics and exceptions to senior management.
- Drive participation in Digital Personal Data Protection Act (DPDPA) readiness, including data discovery, privacy-by-design controls, consent and retention dependencies, incident coordination and evidence support to Legal/Privacy teams.
- Own PCI DSS compliance for cardholder-data environments across cinemas, digital channels and corporate systems; coordinate scoping, control implementation, assessments, evidence, remediation and third-party dependencies.
- Manage endpoint security, EDR/XDR, anti-malware, device hardening, patching, encryption and privileged access controls across corporate and cinema endpoints and servers.
- Establish and mature security monitoring and incident response capabilities, including SIEM/SOC integration, use-case development, threat intelligence, playbooks, investigation, containment, recovery and post-incident reviews.
- Lead vulnerability management, penetration testing, configuration compliance, attack-surface management and timely closure of critical findings through accountable risk owners.
- Oversee identity and access management, MFA, SSO, role-based access, joiner-mover-leaver controls, privileged access management and periodic access reviews.
- Direct enterprise network operations covering LAN, WAN, SD-WAN, MPLS, internet, Wi-Fi, DNS/DHCP, firewalls, VPN, routing and switching across a large multi-location environment.
- Lead cloud and data-centre security and infrastructure across public cloud and on-premises environments, covering secure landing zones, workload protection, backup, capacity, availability and cost optimisation.
- Ensure business continuity and disaster recovery readiness through BIA inputs, resilient architecture, backup assurance, DR drills, recovery testing and closure of observations.
- Define security requirements and conduct due diligence for technology projects, applications, APIs, SaaS platforms, payment integrations, vendors and managed service providers.
- Manage OEMs, system integrators, SOC/MSSP, cloud and telecom partners through clear SLAs, service reviews, escalation governance, licence optimisation and contract performance.
- Lead IT audits and compliance engagements, including internal audit, statutory/third-party reviews and customer or partner assessments; maintain a sustainable evidence and control-testing framework.
- Build a security-aware culture through role-based training, phishing simulations, targeted communication and measurable awareness programmes for corporate and cinema teams.
- Recruit, mentor and manage security, network, cloud and infrastructure teams; establish goals, succession plans, on-call coverage, capability development and performance standards.
- Track and report KPIs/KRIs such as security incidents, MTTD/MTTR, endpoint coverage, vulnerability ageing, patch compliance, availability, capacity, audit observations, PCI status and DR readiness.
- Collaborate with Business, Operations, Finance, Legal, HR, Internal Audit, Digital, Application and Engineering teams to balance risk, customer experience, availability and commercial outcomes.
Job Competence (Skills):
- Cybersecurity governance and frameworks: ISO/IEC 27001, NIST CSF, CIS Controls, risk management and control assurance.
- Privacy and compliance: DPDPA participation, PCI DSS, audit management, policy lifecycle and third-party risk management.
- Security operations: SIEM, SOC, EDR/XDR, vulnerability management, incident response, threat hunting, DLP and email/web security.
- Infrastructure security: multi-vendor firewalls, secure network design, segmentation, NAC, VPN, WAF, IDS/IPS, routing, switching and wireless.
- Cloud and platform security: AWS/Azure/GCP concepts, IAM, CSPM/CNAPP, workload protection, secure configuration, logging and key management.
- Infrastructure operations: Windows/Linux servers, virtualisation, storage, backup, monitoring, databases and data-centre operations.
- Leadership capabilities: strategy execution, stakeholder management, financial planning, vendor negotiation, team development and executive reporting.
- Strong analytical, problem-solving and decision-making skills with the ability to translate technical risk into business impact.
Didn’t find the job appropriate? Report this Job