Lead - Cybersecurity
Cybersecurity Strategy, Governance & Compliance
- Develop, implement, and continuously enhance cybersecurity policies, standards, frameworks, and operational procedures across the business.
- Establish cybersecurity governance mechanisms and drive periodic cybersecurity performance reviews with business leadership.
- Define cyber KPIs, KRIs, scorecards, and reporting frameworks.
- Ensure compliance with cybersecurity regulations, customer requirements, contractual obligations, and industry standards.
- Maintain cyber risk registers and monitor closure of identified risks and audit observations.
Cyber Hygiene & Technology Controls
- Govern and continuously improve cyber hygiene controls across all operational sites.
- Ensure effective Identity & Access Management (IAM), Privileged Access Management (PAM), Multi-Factor Authentication (MFA), and user access governance.
- Drive endpoint security, anti-virus management, security patch deployment, and operating system/application security updates.
- Manage backup infrastructure, restoration testing, and cyber recovery controls.
- Ensure OEM-supported security configurations and technology lifecycle compliance across critical systems.
Operational Technology (OT) Security
- Develop and implement cybersecurity controls for Operational Technology environments including BMS, DCIM, IBMS, EPMS, CCTV, Access Control Systems, PLCs, and Building Automation Systems.
- Ensure secure integration and segregation of IT and OT networks.
- Lead OT vulnerability assessments, security audits, and remediation programs.
- Collaborate with Operations, Engineering, and OEM partners to strengthen resilience of mission-critical operational systems.
Network & Endpoint Security
- Manage enterprise and data center network security architecture.
- Govern firewalls, IDS/IPS, NAC, VPNs, secure remote access, network segmentation, and threat detection controls.
- Implement and manage Endpoint Detection & Response (EDR/XDR) solutions.
- Continuously monitor network and endpoint security posture and drive corrective actions.
Cybersecurity Incident Response & Crisis Management
- Lead cybersecurity incident detection, investigation, containment, eradication, and recovery activities.
- Develop and maintain incident response plans, cyber playbooks, escalation matrices, and response procedures.
- Conduct root cause analysis and implement preventive and corrective actions.
- Coordinate with leadership, OEMs, customers, service providers, and regulatory agencies during cybersecurity incidents.
- Conduct cyber crisis simulations, tabletop exercises, and business continuity testing.
Cyber Risk Management & Vulnerability Management
- Conduct periodic cyber risk assessments for infrastructure, applications, networks, OT systems, and critical business processes.
- Lead vulnerability assessments, penetration testing, security reviews, and threat exposure assessments.
- Prioritize and drive remediation of identified vulnerabilities within defined timelines.
- Monitor emerging cyber threats and ensure timely mitigation of associated risks.
Cybersecurity Solutions & Technology Deployment
- Evaluate, recommend, and implement cybersecurity technologies aligned with business and operational requirements.
- Drive deployment and lifecycle management of SIEM, SOAR, PAM, EDR/XDR, threat intelligence, vulnerability management, and other cybersecurity platforms.
- Collaborate with digital, automation, infrastructure, and project teams for integration of secure technologies.
Cybersecurity Audits & Assurance
- Lead internal and external cybersecurity audits, assessments, certifications, and customer security reviews.
- Ensure readiness and compliance with standards such as ISO 27001, NIST Cybersecurity Framework, CIS Controls, and other relevant industry practices.
- Maintain cybersecurity documentation, evidence repositories, and compliance records.
Vendor & Third-Party Cyber Risk Management
- Conduct cybersecurity assessments of OEMs, contractors, managed service providers, consultants, and third-party vendors.
- Review cybersecurity controls and contractual compliance of suppliers and service providers.
- Ensure remediation and mitigation of identified third-party cyber risks.
- Embed cybersecurity requirements into procurement, contracting, and vendor management processes.
Cybersecurity Awareness & Capability Building
- Develop and implement cybersecurity awareness programs across operational data centers.
- Conduct periodic employee awareness campaigns, phishing simulations, training sessions, and security workshops.
- Build cybersecurity competency within operations, engineering, facility management, and support functions.
- Promote a strong cyber-aware culture across the organization.
ESG, Sustainability & Workplace Safety
- Demonstrate active commitment to AdaniConneX's Environmental, Social & Governance (ESG) objectives and sustainability agenda.
- Promote environmentally responsible management of IT and electronic assets, including e-waste disposal and sustainable technology practices.
- Comply with all applicable Environment, Health & Safety (EHS) policies, procedures, and statutory requirements.
- Participate in safety audits, emergency response drills, incident investigations, and risk mitigation initiatives.
- Ensure safe working practices while executing cybersecurity projects and operational activities at data center facilities.
- Ensure vendors, contractors, and OEM representatives comply with site safety, environmental, security, and governance requirements.
Key Internal Stakeholders
- Group Chief Information Security Officer
- Head – Operations
- Information Technology team
- Engineering & Projects Teams
- Digital & Automation Teams
- Facility Management Teams
- Risk & Compliance Teams
- Procurement Teams
- Physical Security Teams
- Business Leadership Team
Key External Stakeholders
- OEM & technology Partners and cybersecurity consultants
- Clients
- Managed Security Service Providers
- Audit Agencies
- Regulatory Authorities
Educational Qualification
- Bachelor or master’s degree in computer science, Information Technology, Electronics, Cybersecurity, Engineering, or related discipline.
Professional Certifications (Preferred)
- CISSP
- CISM
- CISA
- CEH
- CCSP
- ISO 27001 Lead Implementer / Lead Auditor
- GIAC Certifications
- GICSP (OT Security)
- Microsoft Security Certifications
- Cisco / Palo Alto Security Certifications
Key Competencies Functional Competencies
- Cybersecurity Governance
- OT Security
- Network Security Architecture
- Endpoint Security
- Incident Response & Crisis Management
- Cyber Risk Management
- Vulnerability Management
- Security Operations
- Third-Party Risk Management
- Regulatory Compliance & Audits
- Business Continuity & Cyber Resilience
Behavioral Competencies
- Strategic Thinking
- Leadership & Team Development
- Stakeholder Management
- Analytical Problem Solving
- Risk-Based Decision Making
- Communication & Influencing Skills
- Customer Orientation
- Continuous Improvement Mindset