Senior Manager Information Security
InterGlobe Enterprises · India
Job Description
Job role:
The Information Security Manager will serve as the organization's subject-matter expert for cybersecurity protection, detection, response, and recovery. This role is accountable for guiding the design, implementation, and continuous improvement of an enterprise-wide security framework, and for acting as the primary point of contact for information security matters across internal teams, external partners, and customers.
Key responsibilities:
Stakeholder & Team Leadership
- Serve as the primary point of contact between the internal information security team, external security partners, and customers/business stakeholders.
- Manage internal and external security team members, including third-party security service providers.
- Communicate information security goals, initiatives, and new programs clearly and effectively to department managers and other stakeholders across the organization.
Security Strategy & Architecture
- Guide the IT function and other business units in developing, evolving, and maintaining a comprehensive enterprise security framework.
- Lead the development of baseline infrastructure and application hardening guides based on industry best practices, providing leadership and expertise on current security solutions and configurations.
- Assess business processes, technology, and IT architecture at the logical, system, and component levels to evaluate risk posture and determine appropriate security models and controls.
- Evaluate vendor and internal products for security capabilities and integration into the organization's computing environment, ensuring alignment with business objectives and responsiveness to evolving trends.
- Evaluate new and emerging security technologies and stay current with industry trends and developments.
Governance, Risk & Compliance
- Lead the design, implementation, and maintenance of an ISO 27001, PCI-DSS, DPDP, and GDPR compliant security framework.
- Conduct periodic internal assessments against ISO 27001 and PCI-DSS requirements, and guide the team in addressing and closing identified gaps.
- Oversee information security audits, whether performed internally or by third-party assessors.
- Continuously audit policies and controls to ensure ongoing compliance and operational effectiveness.
Security Operations
- Own and maintain security systems and controls, including firewalls, data protection (DLP), patch management, encryption, vulnerability scanning, and penetration testing.
- Ensure round-the-clock (24x7) monitoring of all security operations and infrastructure.
- Maintain all security tools and technologies with support from internal teams and external partners.
- Implement and oversee technology upgrades, improvements, and major changes to the information security environment.
Incident Response & Risk Management
- Develop and maintain a detailed Security Incident Response Program, including playbooks covering detection, containment, eradication, and recovery.
- Partner with departments across the organization to identify, assess, and reduce information security risk.
Awareness & Training
- Design and deliver information security awareness training programs for organizational personnel.
Qualifications & Skills
Education
- Bachelor's degree in Information Technology, Computer Science, or an equivalent discipline.
Experience
- 12 to 14 years of relevant experience in information security / cybersecurity roles.
Technical Expertise
- Strong technical knowledge of the organization's applications, systems, network, and infrastructure.
- Working knowledge of cloud security across AWS, GCP, and/or Azure, along with application and network security.
- Deep understanding of technologies and architecture within highly scalable enterprise networks.
- Strong understanding of logging mechanisms across Windows, Linux, and macOS platforms, along with core networking concepts.
- Hands-on proficiency with EDR, DLP, Anti-Virus, Vulnerability Management, HIPS, NIDS/NIPS, full packet capture, host-based and network-based forensics, and encryption technologies.
- In-depth knowledge of the architecture, engineering, and operations of at least one enterprise SIEM platform (e.g., ArcSight, QRadar, LogLogic, Splunk).
- Demonstrated expertise in developing and executing Incident Response Playbooks (IRPs).
Certifications & Frameworks
- Advanced certifications such as CISSP or CISM are an added advantage.
- Hands-on exposure to Information Security Management Systems such as ISO 27001, NIST CSF, and NCIIPC guidelines is mandatory.
Soft Skills
- Excellent communication skills, with the ability to coordinate effectively across diverse stakeholders within the organization.
Details
| Company | InterGlobe Enterprises |
| Location | India |
| Type | FULL TIME |
| Niche | general |
