PURPOSE OF THE POSITION
(The main reason for the position, in what context and what is the expected overall end result)
Chief Information Security officer ( CISO)
Logical security management for entire IT set up of CCIL.
ISO-27001 certificate maintenance
Maintaining robust IS security posture of the organization
Audit & Compliance for IT department
Operational Audits
Other compliances aligned to IT act 2008
SCOPE
(The way that the position contributes to and impacts on the organization)
As Chief Information Security officer ( CISO)
Maintain and enhance Information security posture of the organization
Maintain ISO 27001 certification through standard process certification process
Maintain and enhance security architecture, design and the solutions implemented so far in the IT set up of CCIL.
Assess and introduce additional security measures in the current set up
Infrastructure as well as applications
Manage day to security operations through coordination with third party Security operations center (SOC).
Develop / manage/enhance security policies and procedures.
Monitor, manage and maintain all network security devices.
Identify new/additional security threats and develop appropriate mitigation strategy/solution for the same and implement.
Audit & Compliance for IT department
End to end coordination of operational audits covering
Meet compliance requirements as per prevailing regulatory stipulations like IT act 2008 ( eg S/w license management)
RESPONSIBILITIES
(Major responsibilities and target accomplishments expected of the position including the typical problems encountered in carrying out the responsibilities.)
As Chief Information Security officer ( CISO) the position is responsible for
Maintain and enhance Information security posture of the organization
Conduct Information security Management Forum meetings
Development/ maintenance/enhancement of all policies and procedures related to IS security
Coordinate Risk Assessment (RA) and Risk Treatment Plan (RTP) across organization and maintain RA/RTP
Conduct awareness / trainings related to IS security
Maintain ISO 27001 certification
End to end coordination of all security audits
To understand logical security requirements of the organization and makes sure that appropriate strategies and solutions are implemented.
Manage and maintain highest security standards through appropriate policies/ procedures/ solutions.
Set up / enhance appropriate application security practices
Evaluation, Procurement and Implementation of suitable new security tools/products
Manage day to day operations of security devices/appliances
Coordinate with SOC service provider and initiate necessary actions for preventive and corrective measures
Ensure on-going compliance to ISO 27001
Audit & Compliance for IT department
End to end coordination of operational audits covering
Meet compliance requirements as per prevailing regulatory stipulations like IT act 2008 ( eg S/w license management)
QUALIFICATIONS, KNOWLEDGE, SKILLS AND ABILITIES
(The knowledge, skills and attitudes required for satisfactory job performance)
Qualification
Minimum acceptable qualification
BE (Comp Science , IT or Electronics of equivalent)
Job Experience
Minimum job experience in related field
6 to 8 Years
Must have gone through the experience of implementation of ISO 27001 and other security related implementation(s)
Knowledge
The incumbent must have proficient knowledge in the following areas:
IS security : Process, tools
ISO 27001
Audit and compliance
Skills
The incumbent must demonstrate the following skills:
Ability to assess and evaluate IS security risks and manage them
Understanding of various technologies / tools relevant to Logical security management
Strong interpersonal skills
Good team player
Training
The incumbent must have undergone these trainings in his/her previous job
CISA
IS security, Network security
ISO 27000 LA or implementation
Certifications CISSP, CISM, CEH etc
Technology Knowledge/awareness
The incumbent must have these technology awareness/knowledge
Overall understanding of security related to IT infrastructure and application
Operations of SOC
Preventive/corrective measures for security threats/ attacks
Personal Attributes
The incumbent must demonstrate the following personal attributes:
The incumbent must demonstrate the following personal attributes:
Good communication skills ( written and verbal)
Good analytical skills
WORKING CONDITIONS
(The unavoidable, externally imposed conditions under which the work must be performed and which createhardship for the incumbent including the frequency and duration of occurrence of physical demands, environmentalconditions, demands on one’s senses and metal demands. – late hours/shift duty/staggered shift/outside office working/visiting customers/clients)
In general, working hours will be as per normal work hours of CCIL however the candidate must be prepared to adjust to demands of the work assignment
Physical Demands
(The nature of physical effort leading to physical fatigue)
Not applicable
Environmental Conditions
(The nature of adverse environmental conditions affecting the incumbent)
Corporate office environment
Sensory Demands
(The nature of demands on the incumbent’s senses)
Not applicable
Mental Demands
(Conditions that may lead to mental or emotional fatigue)
Not applicable