Source description
About the role
About the Company Tata Communications Redefines Connectivity with Innovation and Intelligence. Driving the next level of intelligence powered by Cloud, Mobility, Internet of Things, Collaboration, Security, Media services and Network services, we at Tata Communications are envisaging a New World of Communications. Accountable for managing the secured development, deployment, operations and lifecycle management for internal and external applications, AI platforms and projects as well as public and private cloud infrastructure across the organisation and its subsidiaries. Securebydesign, DevSecOps transformation, AI model governance, and cloud security architecture across hybrid and multicloud environments. Key Responsibilities Build security domain capability. Influence CoE, product and engineering functional leadership. Drive security culture in development teams. Define and implement enterprise application security strategy across all digital products and services. Collaborate with business and technology stakeholders to maintain ongoing security governance and address security risks associated with applications and digital platforms to provide security assurance for customerfacing application platforms/services. Embed secure SDLC (SSDLC) practices across engineering teams. Establish DevSecOps frameworks integrated with CI/CD pipelines. Security Domains Oversight SAST DAST SCA API security Mobile application security Container and microservices security Cloud Security Lead security for multicloud and hybrid cloud environments including AWS, GCP, Azure as well as private cloud services Define and implement enterprise cloud security strategy across all digital products and platforms. Collaborate with business and technology stakeholders to maintain ongoing security governance and address security risks associated with cloud infrastructure and automation. Cloud security architecture and guardrails CSPM and CNAPP governance Identity and access security for cloud workloads Cloudnative security monitoring Container and Kubernetes security Serverless security Data security in cloud environments AI Security and Governance AI Security and Governance Develop enterprise framework for AI and ML security and risk management including AI model security, protection against model theft and poisoning, secure training data pipelines, responsible AI governance, adversarial AI threat mitigation, AI risk assessment and regulatory compliance. Establish AI security standards aligned with emerging frameworks such as NIST AI RMF, ISO 42001, Responsible AI guidelines. Lead Implementation Of DevSecOps At Scale Including Security testing automation in CI/CD pipelines Container image security Software integrity and artifact signing Opensource software dependencies Threat modellingSecurity architecture reviews API Security Governance API discovery and inventory API gateway security Strong Knowledge Of Application Security: OWASP Top 10, secure coding practices, application threat modelling, API security Cloud Security: AWS / Azure / GCP security architectures, Kubernetes security, CNAPP / CSPM platforms, Zero Trust architecture AI Security: AI model lifecycle security, ML pipeline security, AI governance frameworks Engineering Practices: DevSecOps pipeline security, Infrastructure as Code security, Software supply chain security About the Company Tata Communications Redefines Connectivity with Innovation and Intelligence. Driving the next level of intelligence powered by Cloud, Mobility, Internet of Things, Collaboration, Security, Media services and Network services, we at Tata Communications are envisaging a New World of Communications. Accountable for managing the secured development, deployment, operations and lifecycle management for internal and external applications, AI platforms and projects as well as public and private cloud infrastructure across the organisation and its subsidiaries. Securebydesign, DevSecOps transformation, AI model governance, and cloud security architecture across hybrid and multicloud environments. Key Responsibilities Build security domain capability. Influence CoE, product and engineering functional leadership. Drive security culture in development teams. Define and implement enterprise application security strategy across all digital products and services. Collaborate with business and technology stakeholders to maintain ongoing security governance and address security risks associated with applications and digital platforms to provide security assurance for customerfacing application platforms/services. Embed secure SDLC (SSDLC) practices across engineering teams. Establish DevSecOps frameworks integrated with CI/CD pipelines. Security Domains Oversight SAST DAST SCA API security Mobile application security Container and microservices security Cloud Security Lead security for multicloud and hybrid cloud environments including AWS, GCP, Azure as well as private cloud se
More at Tata Communications
Related open roles
Sr Manager - Service Delivery & Management
Delhi NCR
Assistant Manager - Cloud & Security Network Operations & Support
Mumbai
Senior Manager - Global Solutions Engineering
Mumbai
General Manager - Global Information Security
Chennai
Deputy General Manager - Network Operations & Support
Mumbai
Asst. Manager - Cloud & Security Network Operations & Support
Mumbai