Senior Manager Information Security
InterGlobe Enterprises · Gurugram, Haryana, India
Apply & track with Apply EdgeJob role:The Information Security Manager will serve as the organization's subject-matter expert for cybersecurity protection, detection, response, and recovery. This role is accountable for guiding the design, implementation, and continuous improvement of an enterprise-wide security framework, and for acting as the primary point of contact for information security matters across internal teams, external partners, and customers.Key responsibilities:Stakeholder & Team LeadershipServe as the primary point of contact between the internal information security team, external security partners, and customers/business stakeholders.Manage internal and external security team members, including third-party security service providers.Communicate information security goals, initiatives, and new programs clearly and effectively to department managers and other stakeholders across the organization.Security Strategy & ArchitectureGuide the IT function and other business units in developing, evolving, and maintaining a comprehensive enterprise security framework.Lead the development of baseline infrastructure and application hardening guides based on industry best practices, providing leadership and expertise on current security solutions and configurations.Assess business processes, technology, and IT architecture at the logical, system, and component levels to evaluate risk posture and determine appropriate security models and controls.Evaluate vendor and internal products for security capabilities and integration into the organization's computing environment, ensuring alignment with business objectives and responsiveness to evolving trends.Evaluate new and emerging security technologies and stay current with industry trends and developments.Governance, Risk & ComplianceLead the design, implementation, and maintenance of an ISO 27001, PCI-DSS, DPDP, and GDPR compliant security framework.Conduct periodic internal assessments against ISO 27001 and PCI-DSS requirements, and guide the team in addressing and closing identified gaps.Oversee information security audits, whether performed internally or by third-party assessors.Continuously audit policies and controls to ensure ongoing compliance and operational effectiveness.Security OperationsOwn and maintain security systems and controls, including firewalls, data protection (DLP), patch management, encryption, vulnerability scanning, and penetration testing.Ensure round-the-clock (24x7) monitoring of all security operations and infrastructure.Maintain all security tools and technologies with support from internal teams and external partners.Implement and oversee technology upgrades, improvements, and major changes to the information security environment.Incident Response & Risk ManagementDevelop and maintain a detailed Security Incident Response Program, including playbooks covering detection, containment, eradication, and recovery.Partner with departments across the organization to identify, assess, and reduce information security risk.Awareness & TrainingDesign and deliver information security awareness training programs for organizational personnel.Qualifications & SkillsEducationBachelor's degree in Information Technology, Computer Science, or an equivalent discipline.Experience12 to 14 years of relevant experience in information security / cybersecurity roles.Technical ExpertiseStrong technical knowledge of the organization's applications, systems, network, and infrastructure.Working knowledge of cloud security across AWS, GCP, and/or Azure, along with application and network security.Deep understanding of technologies and architecture within highly scalable enterprise networks.Strong understanding of logging mechanisms across Windows, Linux, and macOS platforms, along with core networking concepts.Hands-on proficiency with EDR, DLP, Anti-Virus, Vulnerability Management, HIPS, NIDS/NIPS, full packet capture, host-based and network-based forensics, and encryption technologies.In-depth knowledge of the architecture, engineering, and operations of at least one enterprise SIEM platform (e.g., ArcSight, QRadar, LogLogic, Splunk).Demonstrated expertise in developing and executing Incident Response Playbooks (IRPs).Certifications & FrameworksAdvanced certifications such as CISSP or CISM are an added advantage.Hands-on exposure to Information Security Management Systems such as ISO 27001, NIST CSF, and NCIIPC guidelines is mandatory.Soft SkillsExcellent communication skills, with the ability to coordinate effectively across diverse stakeholders within the organization.