LinkCxO (The CxO's Marketplace)
Website:
linkcxo.com
Company:
https://www.linkedin.com/company/linkcxo-global-private-ltd
Industries: Technology, Information and Internet, Food and Beverage Services, and Consumer Services
Job details:
Director – Cyber Security & Governance
Location: India
Industry: FMCG / Consumer Goods / Beverage
Employment Type: Full-Time
Work Mode: Hybrid
Function: Cyber Security / Information Security / IT Governance
About the Role -
We are seeking a strategic and business-focused Director – Cyber Security & Governance to lead the organization's cyber security, IT governance, risk, and compliance (GRC) function. As a key member of the technology leadership team, this role will be responsible for strengthening the organization's cyber resilience, embedding security into enterprise transformation initiatives, and ensuring a robust IT control environment across business operations.
The successful candidate will serve as the primary cybersecurity leader for the business, partnering with executive leadership, technology teams, internal audit, and global security functions to establish security as a business enabler while ensuring compliance with enterprise standards and regulatory requirements.
Key Responsibilities -
Cyber Security Leadership
- Define and execute the cyber security strategy aligned with business objectives and enterprise security standards.
- Own the organization's cyber risk posture and maintain a comprehensive cyber risk register with clear ownership and remediation plans.
- Establish governance mechanisms to monitor cyber risks, control effectiveness, and security performance.
- Advise executive leadership on cyber threats, emerging risks, and strategic security investments.
IT Governance, Risk & Compliance (GRC)
- Lead the IT Governance, Risk & Compliance (GRC) function across enterprise technology environments.
- Develop, implement, and continuously improve IT governance frameworks, policies, standards, and controls.
- Oversee IT General Controls (ITGCs) across ERP platforms, enterprise applications, cloud environments, and business systems.
- Ensure continuous compliance with corporate policies, regulatory requirements, and industry security standards.
- Lead governance forums, policy exception management, control testing, and compliance reporting.
Audit & Risk Management
- Act as the primary liaison for Internal Audit, External Audit, and Risk Management functions.
- Lead audit planning, audit readiness, control assessments, and remediation of audit observations.
- Ensure timely closure of audit findings and strengthen the overall IT control environment.
- Develop risk mitigation strategies for technology and information security risks.
Security by Design & Digital Transformation
- Embed security and governance throughout the software development lifecycle and enterprise transformation programs.
- Provide security oversight for ERP implementations, cloud migration initiatives, AI solutions, SaaS platforms, and enterprise integrations.
- Ensure security requirements are incorporated into project planning, architecture, implementation, and deployment.
- Collaborate with Product, Technology, Infrastructure, and Data teams to enable secure digital transformation.
Identity & Access Governance
- Establish governance frameworks for Identity and Access Management (IAM).
- Oversee user access controls, privileged access management, and segregation of duties (SoD) across critical business systems.
- Ensure appropriate access governance across ERP, cloud, and enterprise platforms.
Third-Party Risk Management
- Lead security assessments and governance for vendors, managed service providers, cloud providers, SaaS applications, and technology partners.
- Evaluate supplier security posture, contractual security requirements, and ongoing compliance.
- Establish third-party cyber risk assessment and monitoring frameworks.
Incident Management & Cyber Resilience
- Coordinate local cyber incident response and business recovery activities.
- Partner with enterprise security operations teams during cyber incidents and crisis management.
- Strengthen vulnerability management, patch management, and exposure management programs.
- Support business continuity and disaster recovery planning.
Security Culture & Awareness
- Develop and lead enterprise-wide cyber security awareness and education programs.
- Promote a culture of shared responsibility for cyber security across business functions.
- Engage senior leadership through regular risk reporting and executive security briefings.
Leadership & Stakeholder Management
- Partner with CIO, CISO, Executive Leadership, Internal Audit, Risk, Legal, Compliance, and Business Leaders.
- Influence strategic technology decisions through a risk-based approach.
- Build high-performing governance and security teams while fostering collaboration across global and regional stakeholders.
- Translate technical risks into business-focused recommendations for executive decision-making.
Required Qualifications & Experience -
- Bachelor's degree in Information Technology, Computer Science, Cyber Security, Engineering, or a related discipline.
- Master's degree or MBA preferred.
- 15+ years of experience in Cyber Security, Information Security, IT Governance, Risk & Compliance, or Enterprise Technology Leadership.
- Proven experience leading cyber security and GRC functions within large, complex organizations.
- Strong knowledge of IT governance, ITGCs, audit methodologies, enterprise risk management, and regulatory compliance.
- Experience implementing security controls across ERP, Cloud, SaaS, AI, and enterprise technology environments.
- Demonstrated success in managing security transformation and governance initiatives.
- Strong executive communication and stakeholder management skills.
Preferred Qualifications -
- Professional certifications such as CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer/Auditor, CGEIT, or equivalent.
- Experience with SAP S/4HANA, RISE with SAP, cloud security, AI governance, and digital transformation programs.
- Familiarity with enterprise security frameworks including ISO 27001, NIST Cybersecurity Framework (CSF), CIS Controls, COBIT, and ITIL.
- Experience working within global matrix organizations and shared services environments.
Key Competencies -
- Cyber Security Leadership
- IT Governance, Risk & Compliance (GRC)
- Enterprise Risk Management
- IT General Controls (ITGC)
- Cyber Risk Assessment
- Information Security Governance
- Identity & Access Management (IAM)
Click on Apply to know more.