Bangalore International Airport Ltd
Website:
bengaluruairport.com
Job details:
About the Company: Kempegowda International Airport, Bengaluru (KIAB/ BLR Airport), named after founder of the City – Hiriya Kempegowda – has the unique distinction of being the first Greenfield Airport in India, established on a Public-Private Partnership (PPP) model. This heralded a revolution in Indian aviation, as more airports in the Country were privatised, thereafter.
Job Purpose:
As Senior Manager – Security Architecture & Transformation, the individual will build and run a robust security architecture practice that drives architectural quality, security transformation and security automation across BIAL’s ICT ecosystem – spanning enterprise IT, Operational Technology (OT), IoT and airport operational systems.
BIAL operates a highly diverse and interconnected technology environment with extensive dependencies on partners, vendors, OEMs, service providers and concessionaires. Security architecture must therefore balance cyber risk with safety, availability, reliability, regulatory compliance and continuity of airport operations.
The role acts as the design authority for information security transformation initiatives and as an integration point with Enterprise Architecture, Infrastructure Operations, Cyber Security Operations and Data Privacy & Regulatory Compliance functions, providing consulting on upcoming technologies and threats. The individual is expected to stay current with security standards, authentication protocols and best-practice security products, and where required to transform the security architecture of the technology landscape to bring in the latest innovation in information security safeguards.
Principal Accountabilities & Major Activities:
Security Architecture Governance
- Design and maintain target-state, transition-state and solution security architectures that are scalable, reliable and aligned with business objectives, cybersecurity strategy and regulatory obligations.
- Conduct security architecture reviews and design reviews; review and approve high-level and low-level designs, integration designs and security requirements for ICT initiatives.
- Identify and evaluate potential security risks through risk assessments of current measures and controls, recommending enhancements, countermeasures and security plans.
- Maintain security standards, reference architectures, architecture decision records and exception registers.
- Ensure the security architecture of organisational systems complies with relevant regulatory and compliance requirements (including CERT-In, NCIIPC and sector-specific directives).
Architecture Review Board (ARB)
- Represent the security function on the Architecture Review Board, ensuring appropriate security requirements are vetted in every solution architecture presented for review.
- Ensure the necessary cybersecurity non-functional requirements (NFRs) are defined and kept updated in RFP templates and solution evaluation criteria.
- Participate in bidder proposal meetings to ensure the right questions on cybersecurity architecture and design are asked and satisfactorily answered before technology selection.
- Take ownership of the final approved architecture from a security perspective, including sign-off on security design and recording of any accepted risks or exceptions.
- Ensure innovative cybersecurity mechanisms are evaluated and incorporated into the broader BIAL ecosystem through the ARB process.
- Periodically review the overall cybersecurity posture with the reporting manager to ensure the security landscape is continuously upgraded.
- Attend and support internal, external and regulatory audits, providing architecture evidence and remediating findings relevant to security architecture.
Security Transformation & Projects
- Provide architecture leadership for cybersecurity transformation programmes (e.g. SIEM modernisation, Zero Trust Architecture, identity governance, data security, API/WAF protection, cyber resilience).
- Lead technical evaluations, proof-of-concepts, design workshops and technology selection; develop project timelines and prepare cost estimates for system upgrades.
- Work with project teams, OEMs, system integrators and service providers to resolve design, technical and delivery challenges, and take vendor support in testing, updating and upgrading security systems.
IT / OT & Critical Infrastructure Security
- Design and govern secure architectures spanning enterprise IT, OT environments, airport operational systems and third-party connectivity.
- Specify intrusion detection and prevention methodologies; advise on preventive and reactive measures for critical infrastructure.
Operations Integration & Continuous Improvement
- Maintain accountability for security solutions beyond deployment – ensuring operationalisation, adoption, handover to operations and continual improvement.
- Help teams establish disaster recovery procedures and conduct security breach drills.
- Identify areas of improvement in responding to security incidents and provide post-event analyses.
- Supervise vulnerability testing, risk analyses and security assessments.
Stakeholder & Advisory
- Provide guidance and support to business and technology teams on security best practices, policies and procedures, including data privacy and protection, access control and incident management.
- Coordinate cross-functional efforts across ICT, Cyber Security Operations, Engineering & Maintenance, Airport Operations, Legal and Compliance.
- Help create solutions that balance business requirements with information and cybersecurity requirements.
Emerging Technology & AI Security
- Provide security architecture guidance for AI and Generative AI initiatives, establishing guardrails covering data protection, identity, access control, model and third-party integrations, and monitoring.
- Identify and communicate current and emerging security threats; stay up to date with the latest security technologies, standards, authentication protocols and products.
Dimensions:
Financial : Provide relevant inputs from a Security Architecture perspective to help Head – Security and Governance determine the Annual Budget and periodic forecasting.
Non-Financial : 2–3 indirect reports from small vendor resources providing security architecture services.
Operating Network:
Internal: Enterprise Architecture, ICT & Infrastructure Operations, Cyber Security Operations, Airport Operations, Engineering & Maintenance, Digital, Legal, Compliance and Procurement teams.
External: OEMs, system integrators, MSSPs, consultants, service providers, concessionaires and regulatory bodies (e.g. CERT-In, NCIIPC, BCAS) as applicable.
Job Specification:
1. Education qualification and certifications
- Bachelor or master’s degree in computer science, IT Systems, or related domains.
- Any of the following certifications will be nice to have: CISSP, CISM, CISA, CCSP, ISSAP / ISSEP, SABSA, TOGAF.
2. Years of Experience
- 10–15 years of Information Systems experience, including planning, organising and developing Infrastructure and Cyber / Information Security Operations related capabilities.
- Out of this, minimum 5 years of experience as Security Architect for large technology ecosystems, including leading security programmes from architecture through implementation and operationalisation.
- Experience across both IT and OT environments is highly desirable; experience in aviation, transportation, utilities or other critical infrastructure sectors is preferred.
3. Knowledge and work skills
- Knowledge of security and industry frameworks such as ISO 27001/02, NIST Cybersecurity Framework and 800-53, CIS Controls, IEC 62443, PCI-DSS, IT Act 2000, CERT-In guidelines and NCIIPC requirements.
- Experience with enterprise-grade cloud and SaaS security solutions, and knowledge of Zero Trust Architecture principles.
- Solid understanding of security protocols, cryptography, PKI, authentication and authorisation; experience implementing multi-factor authentication, single sign-on, identity governance or related technologies.
- Familiarity with security operations technologies – SIEM and security data pipelines, intrusion detection and prevention, vulnerability management – and threat-informed practices such as MITRE ATT&CK.
- Knowledge of securing development pipelines (automated code scanning, API management) and containers, including container management solutions such as Kubernetes and OpenShift.
- Understanding of cyber resilience, recovery and immutable storage concepts.
- Extensive experience in information security and/or IT risk management with a focus on security, performance and reliability; good working knowledge of current IT risks and experience implementing security solutions.
- Ability to communicate complex security concepts and risks to both technical and non-technical audiences, and to work collaboratively with teams across the organisation, including IT, legal, compliance and business units.
- Ability to interact with a broad cross-section of personnel to explain and enforce security measures.
- Ability to think like a malicious hacker to anticipate and defend the organisation against information security risks.
BEHAVIORAL COMPETENCIES
- Strategic Leadership - Leading self/teams effectively
- Change Influencer - Leading Team/Organization during change
- Innovation Mindset - Innovating to impact Team/Organization performance
- Customer Centricity - Driving competitiveness and innovation
- Execution Excellence - Driving business performance
- Collaboration - Collaborating across businesses
⚠️ Important: Candidates should be comfortable working 5 days a week from the office at Kempegowda International Airport, Bengaluru (KIAB/BLR Airport).
Click on Apply to know more.