- Location
- Pune
- Type
- Full-time
- Department
- Security
- Source
- Pinpoint
Description
Group Head of Information Security
Department: Risk and Compliance
Employment Type: Permanent - Full Time
Location: Pune
Description
Key Responsibilities
- Define and operate Group-wide information security governance, including risk appetite translation, risk acceptance/exception processes, and escalation through Group risk and governance forums with measurable outcomes.
- Own the Group assurance model (control assurance, audit readiness, continuous monitoring) to provide risk owners with objective, decision-grade evidence of security posture.
- Deliver monthly Board reporting on security risk posture, control effectiveness, and emerging threats, translating technical risk into clear business options and trade-offs.
- Maintain and continuously improve the Group risk register, ensuring alignment with enterprise risk management frameworks and regulatory expectations.
- Own and continuously improve the Group ISMS (aligned to ISO 27001), ensuring it remains fit for business purpose and scaled appropriately across all Davies entities globally.
- Drive the annual ISO 27001 surveillance/recertification cycle, coordinating internal audits, management reviews, and external audit engagements.
- Ensure the Group policy framework is current, proportionate, and effectively communicated, with demonstrable compliance monitoring and exception management.
- Maintain alignment with relevant regulatory and contractual obligations (including data protection regulations, client contractual security requirements, and sector-specific standards).
- Chair or set direction for security-by-design governance across architecture and change delivery, including control patterns/standards, design assurance, and pragmatic exception handling.
- Establish a Group identity security strategy covering workforce, privileged access, third parties, and service/bot identities, including defences against deepfake/impersonation attacks and insider/fake employee scenarios.
- Ensure security requirements are embedded in enterprise and solution architecture decisions, balancing risk, policy, and cost of controls.
- Govern cloud security posture including consumption/cost-abuse controls, resource guardrails, anomaly detection, and FinOps+SecOps integration.
- Define and oversee security controls for AI-enabled tooling and automation across the Group, including acceptable use policies, data handling requirements, and monitoring/assurance.
- Reduce exposure to AI-assisted social engineering through modern security awareness programmes that explicitly address AI-crafted persuasion and impersonation techniques.
- Govern shadow AI risk through discovery, policy enforcement, and pragmatic onboarding pathways that balance productivity with control.
- Contribute to enterprise AI/algorithm governance, ensuring controls, monitoring, auditability, and risk management for third-party models and automated decisioning.
- Strengthen third-party and supply chain assurance beyond initial assessment, including contractual security controls, ongoing assurance cadence, concentration risk analysis, and cascading supply-chain compromise readiness.
- Ensure supplier risk is integrated into Group risk reporting and that material third-party security risks are escalated to appropriate risk owners.
- Oversee threat-led security planning and incident response maturity across the Group, working closely with the Cyber team.
- Ensure robust incident reporting, classification, root cause analysis, and lessons-learned processes are embedded and continuously improved.
- Maintain deepfake/impersonation preparedness for executives and high-risk business processes.
- Lead security due diligence and risk assessment for mergers, acquisitions, and divestitures.
- Design and deliver security integration plans for newly acquired businesses, ensuring alignment with Group ISMS standards within defined timescales.
- Identify and manage inherited security risks from acquisitions, including legacy technology, unmanaged identities, and contractual obligations.
- Lead, develop and mentor the four Divisional Information Security Officers, creating consistent standards, clear accountability and a high-performing federated security leadership community across the Group
- Build team capability in emerging disciplines (identity security, AI governance, resilience engineering, PQC readiness) through targeted development and recruitment.
- Promote security culture across the wider organisation through engagement, awareness, and collaboration with business stakeholders.
Skills, Knowledge and Expertise
- Significant experience in a senior information security leadership role, with demonstrable ability to influence senior risk owners and embed security decision-making across multiple business units and geographies.
- Expert capability in enterprise security risk management, including risk appetite translation, risk acceptance pathways, measurable risk treatment plans and independent assurance reporting.
- Proven track record of maintaining ISO 27001 certification and managing external audit cycles in a complex, multi-entity organisation.
- Strong experience implementing security-by-design governance across architecture and change delivery, including control patterns, design assurance and pragmatic exception handling.
- Strong understanding of identity-led security, including privileged access, third-party identity and anti-impersonation controls.
- Excellent communication skills, with the ability to tailor messages for Board, CISO, technical and business audiences, including concise risk narratives and clear escalation.
- Experience governing cloud security and modern attack surfaces, including vulnerability and exploit response expectations and secure operational patterns.
- Strong supplier assurance experience beyond initial assessment, including contractual controls, ongoing assurance programmes and supply-chain compromise readiness.
- Demonstrated success leading through federated and matrix structures, including directing divisional security leaders and aligning stakeholders without relying solely on line authority.
- Demonstrated ability to lead and influence senior stakeholders across multiple cultures and geographies through clear governance, strong written communication and disciplined decision-making.