Job Role: Security Lead
Job Summary:
A Security Lead is responsible for overseeing the development and implementation of security measures to protect an organization’s digitalassets, infrastructure, data, and systems from cyber threats. They lead security strategy, manage risk, respond to incidents, and ensure regulatorycompliance across IT operations.
Experience:
1. Minimum 5 years of relevant experience in cybersecurity, with at least 2–3 years in a leadershiprole
2. Proven experience in managing enterprise security for networks, applications, and cloud infrastructure
3. Domain experience in regulated industries (e.g., education, skilling, finance, healthcare, government) is a plus
Main responsibilities inter-alia include
1. Security Strategy & Governance: Define, implement, and maintain the organization’s cybersecurity policies, standards, andprocedures; Develop and manage the organization’s overall security roadmap aligned with business goals; Lead risk assessments andsecurity audits across systems and infrastructure
2. Threat Detection & Response: Monitor for threats, vulnerabilities, and incidents using SIEM and security tools; Lead investigation andresponse to security incidents and breaches; Coordinate incident response plans and disaster recovery exercises
3. Compliance & Risk Management: Ensure adherence to relevant security standards and regulations (e.g., ISO 27001, NIST, DPDP Act,GDPR); Identify security risks and define mitigation strategies; Work with auditors and regulatory bodies during security assessments
4. Technical Oversight: Manage firewall rules, IDS/IPS systems, endpoint protection, VPNs, and IAM solutions; Oversee secureconfiguration of cloud platforms (AWS, Azure, GCP); Review and approve architecture changes from a security standpoint
5. Collaboration & Leadership: Work closely with IT, DevOps, legal, and compliance teams; Lead and mentor a team of security analystsor engineers; Conduct training and awareness programs for employees on cybersecurity best practices
Required Skills:
1. Strong knowledge of network security, application security, cloud security, and identity management
2. Hands-on experience with security tools like SIEM (e.g., Splunk, QRadar), firewalls, endpoint protection, vulnerability scanners,etc.
3. Understanding of encryption, threat modeling, penetration testing, and incident response
4. Familiarity with cloud security frameworks and DevSecOps practices
5. Excellent analytical, problem-solving, and communication skills
Educational Qualification:
1. Bachelor’s or Master’s degree in Computer Science, Information Security, Cybersecurity, or related field
2. Certifications such as CISSP, CISM, CEH, CompTIA Security+, or AWS/Azure Security are highly desirable