VP - Internal Cyber Security Defence
Job Description
Job Description: Head - Internal Corporate Cyber Secuirty
\nLocation: Bengaluru, India
\nFunction: Cybersecurity Services, MCDC, DFIR, GRC & AI Security Platforms
\nRole Summary
\nWe are seeking a senior cybersecurity leader to head internal corporate cybersecurity, including our MCDC (Managed Cyber Defense Center) operating as an internal enterprise security function. The role is responsible for protecting our people, data, infrastructure, applications, cloud, and AI ecosystem across global locations. The incumbent will lead enterprise security operations, digital forensics & incident response, GRC, security architecture, and AI governance, with accountability for risk reduction, regulatory compliance, and resilience of our organization's environment.
\nKey Responsibilities
\n1. Enterprise Cybersecurity Strategy & Governance
\n- \n
- Define and execute the internal cybersecurity strategy and roadmap aligned to business priorities and global regulatory expectations \n
- Establish enterprise security policies, standards, and control frameworks \n
- Drive Zero Trust, secure access, cloud security, identity governance, and AI security strategies for the corporate environment \n
- Act as trusted advisor to CRO/CISO and executive leadership on cyber risk posture, investments, and exceptions \n
3. Digital Forensics & Incident Response
\n- \n
- Define forensic readiness frameworks and chain-of-custody protocols aligned to legal, HR, and regulatory expectations \n
- Build and maintain incident response playbooks for ransomware, APTs, insider threats, data breaches, and cloud-native attacks \n
- Integrate endpoint, network, identity, and cloud telemetry into unified forensic workflows \n
- Drive automation of DFIR tasks using orchestration, LLMs, and agents \n
- Automated evidence collection \n
- Triage and timeline reconstruction \n
- IOC enrichment and correlation \n
- Lead major internal incident investigations, coordinating with Legal, HR, IT, Compliance, regulators, and law enforcement as needed \n
4. Security Architecture & Engineering
\n- \n
- Lead design and implementation of enterprise security architecture, including: \n
- Zero Trust architecture \n
- Cloud & SaaS security (cloud posture management, workload protection, secure access \n
- Endpoint protection and detection \n
- Email and collaboration security \n
- Vulnerability and exposure management \n
- Backup, recovery, and cyber resilience \n
- Identity & Access Management (IAM, PAM) \n
- Data protection and DLP \n
- Ensure secure-by-design principles are embedded across internal IT, engineering, and delivery platforms. \n
5. Enterprise GRC, Risk & Compliance
\n- \n
- Establish and govern internal cyber risk management frameworks aligned to: \n
- ISO 27001 \n
- ISO/IEC 42001 (AI Management Systems) \n
- NIST CSF / NIST AI RMF / NIST SP 800-86 (Forensics) \n
- GDPR, EU AI Act, India DPDP Act \n
- PCI DSS, SOC 2 \n
6. AI Governance & Secure AI Adoption
\n- \n
- Lead secure adoption of enterprise AI platforms and generative AI tools across the organization. \n
- Define controls for: \n
- Data protection (no training on enterprise data, DLP, audit logs) \n
- Access governance and license provisioning \n
- Contractual safeguards and exemption tracking \n
- Embed ISO/IEC 42001 AI governance principles into the internal AI lifecycle. \n
7. Cyber Insurance, Audit & Regulatory Interface
\n- \n
- Own internal cyber insurance readiness and control validation. \n
- Interfacewith: \n
- External auditors \n
- Regulators \n
- Internal audit & compliance \n
- Coordinate with Finance (cyber insurance), Legal (contracts), HR (insider risk), and IT (operations) for cross-functional risk management. \n
8. Network Security & Advanced Threat
\n- \n
- DefenseDrive deep technical capabilities for: \n
- Network detection & response \n
- Packet inspection and protocol analysis \n
- Network forensics and traffic monitoring \n
- Strengthen perimeter, internal segmentation, and east-west traffic visibility. \n
10. Program Governance & Multi-Vendor
\n- \n
- AssuranceLead complex, multi-vendor security programs under stringent timelines and regulatory expectations \n
- Drive:Requirements decomposition \n
- Interface control \n
- V&V strategy \n
- Multi-vendor / third-party risk management \n
11. Team Build-out & Leadership
\n- \n
- Build, lead, and scale a global, multi-disciplinary internal cybersecurity team across: \n
- MCDC / SOC \n
- operationsDFIR and threat hunting \n
- Security engineering & architecture \n
- GRC, compliance & AI governance \n
- Establish a high-performance, risk-aware culture with continuous capability building (certifications, red/blue/purple teaming, SOC & forensic automation). \n
Required
\n- \n
- Experience20+ years of leadership across enterprise cybersecurity operations, risk & compliance, AI-powered security platforms, digital forensics, and critical-infrastructure \n
- protection. Proven experience in building and leading internal Global SOC / Cyber Defense Center capabilities — operating model, tooling, team, and processes. \n
- Strong background in GRC & control \n
- assurance. Demonstrated experience in AI-first security platforms and AI governance (ISO 42001, AI RMF). \n
- Hands-on background in network security, traffic monitoring, and network forensics. \n
- Experience with risk data aggregation and executive reporting infrastructure at large enterprise scale. \n
- Exposure to safety-critical, regulated environments (defense, aerospace, BFSI) with multi-vendor program governance. \n
Preferred Education & Credentials
\n- \n
- M.Tech in Computer Science/ AI or equivalent \n
- Professional development in: \n
- Product Ownership \n
- ISO 27001 — Information Security Management \n
- ISO 42001 — AI Management Systems \n