Source description
About the role
Role Overview: As the Head Information Security, your main responsibility will be to devise and implement information security practices, initiatives, governance, and compliances including data privacy. You will play a pivotal role in continuously maturing a resilient Information Security Management System (ISMS) aligned to ISO/IEC 27001, applicable Indian regulations, and data protection frameworks. Your role will report to the Group CITO and you will be responsible for owning the cybersecurity posture across all manufacturing plants, corporate office, warehouses, retail stores, digital infrastructure, and supply chain partner interfaces to ensure business continuity and regulatory trust. Key Responsibilities: - Define and own the enterprise-wide Information Security Goals, roadmap, and budget aligned with business objectives and risk appetite. - Establish and lead the Information Security Steering Committee and present security posture updates to the management on a quarterly basis. - Develop, publish, and enforce the organizations suite of Information Security policies, standards, and procedures. - Lead the design and certification of the ISMS in accordance with ISO/IEC 27001:2022. - Devise and implement Data Privacy program in the company. - Drive enterprise-level Information Security Risk Assessment (ISRA) and maintain a living risk register with defined treatment plans. - Ensure compliance with applicable Indian regulations including IT Act 2000, DPDP Act 2023, RBI cybersecurity guidelines, and sector-specific directives from MeitY. - Oversee third-party and supply chain security risk assessments and enforce contractual data security obligations with vendors and logistics partners. - Serve as the functional lead and implement Digital Personal Data Protection (DPDP) Act 2023 compliance program. - Build and operationalize a Data Governance Framework including data classification, data lineage, consent management, and retention/deletion controls. - Oversee privacy impact assessments (PIAs / DPIAs) for all new digital initiatives, product launches, and cross-border data transfers. - Manage data breach notification obligations, including regulatory reporting timelines under DPDP and buyer data security agreements. - Architect and oversee the organizations cybersecurity technology stack including SIEM, SOC, endpoint protection, email security, DLP, and identity/access management. - Lead vulnerability management, penetration testing programs, and patch management lifecycle across IT and OT environments. - Manage Security Operations Centre (SOC) activities, incident detection, response playbooks, and post-incident reviews. - Oversee cloud security posture management for various workloads covering ERP, e-commerce, and software platforms. - Own the organizations Business Continuity Plan (BCP) and IT Disaster Recovery Plan (DRP) and lead annual DR drills and tabletop exercises. - Define and enforce RTO / RPO targets for all critical business systems and ensure tested backup and failover capabilities. - Act as the Incident Commander for high-severity cybersecurity incidents and coordinate legal, communications, and any other necessary actions. Role Overview: As the Head Information Security, your main responsibility will be to devise and implement information security practices, initiatives, governance, and compliances including data privacy. You will play a pivotal role in continuously maturing a resilient Information Security Management System (ISMS) aligned to ISO/IEC 27001, applicable Indian regulations, and data protection frameworks. Your role will report to the Group CITO and you will be responsible for owning the cybersecurity posture across all manufacturing plants, corporate office, warehouses, retail stores, digital infrastructure, and supply chain partner interfaces to ensure business continuity and regulatory trust. Key Responsibilities: - Define and own the enterprise-wide Information Security Goals, roadmap, and budget aligned with business objectives and risk appetite. - Establish and lead the Information Security Steering Committee and present security posture updates to the management on a quarterly basis. - Develop, publish, and enforce the organizations suite of Information Security policies, standards, and procedures. - Lead the design and certification of the ISMS in accordance with ISO/IEC 27001:2022. - Devise and implement Data Privacy program in the company. - Drive enterprise-level Information Security Risk Assessment (ISRA) and maintain a living risk register with defined treatment plans. - Ensure compliance with applicable Indian regulations including IT Act 2000, DPDP Act 2023, RBI cybersecurity guidelines, and sector-specific directives from MeitY. - Oversee third-party and supply chain security risk assessments and enforce contractual data security obligations with vendors and logistics partners. - Serve as the functional lead and implement Digital Personal Data Prot