Back to Jobs
Adani Group

Chief Information Security Officer - Cyber Security

Adani Group
Ahmedabad, Gujarat, IndiaFull TimeExecutivePosted Today

About Business:

Adani Group: In recent years, we have evolved from a new player in power generation to India’s largest private thermal power producer, with a capacity of 15,250 MW and a 40 MW solar project in Gujarat. It has created a world-class logistics and utility infrastructure portfolio that has a pan-India presence. Adani Group is headquartered in Ahmedabad, in the state of Gujarat, India. Over the years, Adani Group has positioned itself to be the market leader in its logistics and energy businesses focusing on large-scale infrastructure development in India with O & M practices benchmarked to global standards. With four IG-rated businesses, it is the only Infrastructure Investment Grade issuer in India.

Job Purpose: The BU CISO is a senior leadership role responsible for overseeing the cybersecurity posture, strategy, and risk management within a specific business unit (BU) of the organization. This role will ensure that cybersecurity initiatives are aligned with the strategic goals of the business unit, while maintaining overall compliance with corporate security standards, policies, and regulatory requirements. The BU CISO will work closely with business unit leaders, IT, legal, and compliance teams to create and implement robust cybersecurity frameworks, address emerging risks, and safeguard the organization’s critical assets.

BU CISO

Cybersecurity Strategy and Governance:

Develop, implement, and lead the cybersecurity strategy for the assigned business unit, ensuring alignment with organizational goals group cyber security strategy and industry best practices.

Establish and enforce cybersecurity policies, procedures, and governance frameworks specific to the business unit.

Ensure cybersecurity initiatives are in compliance with applicable regulatory frameworks and internal standards (e.g., GDPR, ISO 27001, NIST, etc.).

Ensure business level cyber security KPIs are achieved and maintained.

Risk Management and Threat Assessment:

Lead the identification, assessment, and management of cybersecurity risks within the business unit, prioritizing mitigation strategies based on business impact.

Conduct regular risk assessments and threat modeling exercises to identify vulnerabilities and threats relevant to the business unit.

Collaborate with other business units and teams to ensure a holistic approach to risk management across the organization.

Minimize the cybersecurity exceptions at business level.

Cybersecurity Operations:

Oversee the day-to-day cybersecurity operations within the business unit, ensuring that security controls are effectively implemented and maintained.

Ensure timely detection, response, and resolution of security incidents, working closely with the SOC (Security Operations Center) and incident response teams.

Manage the security incident management lifecycle, including investigation, root cause analysis, and remediation efforts.

Collaboration with Business Leaders:

Collaborate with senior leadership and business unit managers to understand business goals and ensure that cybersecurity investments and strategies support those objectives.

Act as the primary point of contact for cybersecurity matters within the business unit, providing expert advice and guidance to business unit stakeholders.

Ensure cybersecurity risks and priorities are effectively communicated and understood at the business unit leadership level.

Cybersecurity Awareness and Training:

Lead initiatives to enhance cybersecurity awareness and build a culture of security within the business unit, including organizing training and awareness programs.

Work with Group Awareness and BU HR teams to develop cybersecurity training programs tailored to the specific needs of the business unit.

Promote secure behavior across teams by fostering good security hygiene practices and continuous education.

Security Architecture and Design:

Collaborate with the architecture and engineering teams to ensure that cybersecurity is integrated into the design and architecture of business unit systems, applications, and infrastructure.

Review and approve security architecture for projects, ensuring that secure coding, encryption, and other security best practices are followed.

Incident Response and Crisis Management:

Lead the business unit’s response to cybersecurity incidents, ensuring timely coordination and escalation to executive leadership when necessary.

Develop and maintain incident response plans and disaster recovery protocols specific to the business unit, ensuring they align with the organization’s overall plans.

Conduct tabletop exercises and incident simulations to improve readiness and response capabilities.

Metrics and Reporting:

Develop and track key performance indicators (KPIs) to measure the effectiveness of the business unit's cybersecurity efforts.

Provide regular reports to senior leadership on the status of cybersecurity activities, risks, and incidents within the business unit.

Utilize data and metrics to continuously improve security processes and identify areas for improvement.

Third-Party Risk Management:

Oversee the security posture of third-party vendors and partners that interact with the business unit, ensuring that they comply with organizational security standards.

Conduct regular assessments of third-party risks, including vendor assessments, contract negotiations, and due diligence processes.

Budgeting and Resource Management:

Manage the cybersecurity budget for the business unit, ensuring that investments are aligned with priority risks and initiatives.

Identify resource needs and lead recruitment and retention efforts to build and maintain a high-performing cybersecurity team within the business unit.

Key Stakeholders - Internal

Executive Leadership

Department Heads

Legal and Compliance

IT Team

Risk Management Team

Security Awareness and Training Teams

Incident Response Team

Procurement and Vendor Management Teams

Internal Security and Penetration Testing Teams

Engineering and Development Teams

Key Stakeholders - External

Cloud Service Providers

Consultants and Industry Experts

Regulatory Bodies and Compliance Authorities

External Auditors

Managed Security Service Providers (MSSPs)

Industry Associations and Cybersecurity Forums

 

Educational Qualification:

Minimum Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.

Advanced degree (e.g., Master's, MBA) in Cybersecurity, Information Assurance, or a relevant discipline is highly desirable..

Certification:

Relevant certifications such as CISSP, CISM, CISA, CISA, or ISO 27001 Lead Implementer are highly desirable.

Work Experience (Range of years):

Minimum 10 years of experience in cybersecurity.

Ready to apply? You'll be taken to Adani Group's application page.