Deputy Manager-IT Security

Tata AutoComp
Posted on
Tata AutoComp logo

Experience
6 - 11 yrs
Job Location
Pune, India
Vacancy
1
Designation
Deputy Manager - Security
Job Type
Not specified

Job Description

Key Responsibilities1. Security Strategy & Governance

  • Define and execute enterprise IT security strategy aligned with business goals.
  • Establish and maintain security governance frameworks, policies, and standards.
  • Ensure alignment with global standards such as ISO 27001, NIST, CIS Controls.
  • Drive continuous improvement of the organizations security posture.

2. Risk Management & Compliance (across the Business Units of Tata AutoComp)

  • Lead enterprise-wide risk assessments and mitigation planning
  • Manage vulnerability assessment and penetration testing (VAPT) programs.
  • Ensure compliance with regulatory and legal requirements (e.g., DPDP Act).
  • Manage internal and external security audits and ensure closure of findings.

3. Security Operations

  • Oversee Security Operations Center (SOC) functions including monitoring, detection, and response.
  • Define and track KPIs such as MTTD, MTTR, and incident severity.
  • Enhance threat intelligence capabilities and proactive defense mechanisms.
  • Ensure 24x7 monitoring of security events and incidents.

4. Incident Response & Crisis Management

  • Lead cyber incident response planning and execution.
  • Coordinate with internal teams and external agencies during major incidents.
  • Conduct root cause analysis (RCA) and implement corrective measures.
  • Develop and test cyber crisis and business continuity plans.

5. Security Architecture & Engineering

  • Define secure architecture for enterprise IT systems (on-premise and cloud).
  • Implement / Manage controls across: 
  • Network security (firewalls, IDS/IPS)
  • Endpoint security (EDR/XDR)
  • Identity & Access Management (IAM, PAM)
  • Data security (DLP, encryption)
  • Drive Zero Trust architecture adoption.

6. Cloud & Digital Security

  • Ensure secure adoption of cloud platforms (Azure, AWS).
  • Oversee cloud security posture management (CSPM) and workload protection.
  • Ensure secure APIs, applications, and DevSecOps pipelines.

7. Third-Party & Vendor Risk Management

  • Assess and manage risks from third-party vendors and partners.
  • Implement vendor security assessment frameworks.
  • Ensure contractual security requirements are enforced.

8. Leadership & Stakeholder Management

  • Lead and mentor cybersecurity teams.
  • Collaborate with IT, business units, HR, Admin, legal, and compliance teams.
  • Present security posture and risk insights to senior leadership.
  • Manage budgets and strategic security investments.

9. Awareness & Training

  • Drive organization-wide security awareness programs.
  • Conduct phishing simulations and user training.
  • Promote a security-first culture across the enterprise.

Required Skills & CompetenciesTechnical Skills

  • Deep understanding of: 
  • Network and infrastructure security
  • Cloud security and architecture
  • Endpoint and identity security
  • Application security (OWASP Top 10)
  • Hands-on experience with SIEM, SOAR, EDR, DLP, IAM tools.
  • Knowledge of threat landscapes, attack vectors, and mitigation strategies.

Cybersecurity Frameworks

  • ISO 27001, NIST CSF, CIS Controls
  • MITRE ATT&CK framework
  • Risk management frameworks

Leadership Skills

  • Strategic thinking and decision-making
  • Strong communication and stakeholder management
  • Crisis handling and problem-solving abilities
  • Capability to lead cross-functional teams

Qualifications

  • Education: Bachelors/Masters in Computer Science, IT, Cybersecurity, or related field
  • Experience: 6-11 years of experience in IT security, with:
  • Experience managing enterprise-scale environments

Certifications (Preferred)

  • CISSP (Highly preferred)
  • CISM / CISA
  • CCSP / CCSK
  • CEH / OSCP
  • ISO 27001 Lead Implementer / Auditor

Key Performance Indicators (KPIs)

  • Reduction in security incidents and risk exposure
  • Incident response effectiveness (MTTD / MTTR)
  • Compliance audit success rate
  • Vulnerability remediation timelines
  • Security awareness maturity level

Nice to Have

  • Experience with Zero Trust implementation
  • Knowledge of AI/ML in cybersecurity
  • Exposure to DevSecOps and automation
  • Experience in regulated industries (BFSI, Manufacturing, Pharma)

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.