Search Jobs

Search by job, company or skills

Director, Information Security

Director, Information Security

Toast
10-15 Years
Quick Apply
  • Posted 14 days ago
  • Over 50 applicants have applied

Job Description

  • Leadership and Team Building: Build and lead skilled Information Security, Governance, Risk and Compliance teams in India, fostering collaboration, innovation, and continuous improvement.
  • Strategic Planning and Implementation: Develop and execute a comprehensive information security strategy aligned with Toasts business objectives and global security framework.
  • Security Operations: Manage daily security operations, including incident response, vulnerability management, and threat intelligence. Lead security awareness initiatives to enhance the organizations defense posture.
  • Compliance and Risk Management: Ensure compliance with relevant industry standards / regulatory requirements (e.g. SOX, PCI, SOC, etc) and internal policies. Proactively identify, assess, and mitigate compliance and security risks.
  • Collaboration and Communication: Work closely with cross-functional teams, including Engineering, IT, Operations, Enterprise Risk, and Legal, to integrate security into all aspects of the business. Communicate effectively with senior leadership and stakeholders on security risks and initiatives.
  • Innovation and Adaptation: Stay abreast of emerging security threats and technologies, and adapt security strategies and controls accordingly. Support security as a culture of yes, unblocking engineering and product innovation wherever possible.

Qualifications:

  • Extensive Experience: 10+ years of experience in information security, compliance, and risk management, with demonstrated success in leading security teams and initiatives.
  • Strong Leadership Skills: Ability to inspire and motivate teams, build strong relationships, and influence at all levels of the organization.
  • Technical Expertise: Expertise in cybersecurity technologies, risks and controls processes, best practices, and emerging threats.
  • Strategic Thinking: Ability to develop and implement strategic security initiatives aligned with business goals. Creative and open to interpretation in security architecture and design. Not rigid in implementation of security standards.
  • Problem Solving and Decision Making: Ability to analyze complex security issues, identify root causes, and develop effective solutions.
  • Excellent Communication Skills: Ability to communicate technical concepts clearly and concisely to both technical and non-technical audiences.
  • Industry Knowledge: Strong knowledge of security frameworks and regulations such as: PCI DSS, SOC, SOX, NIST CSF, and ISO 27001.

Additional Considerations:

  • Experience in the technology, payment card or financial services industry is a plus.
  • CISSP, CISM, or other relevant security certifications are highly desirable.
  • Strong understanding of cloud security and data protection principles.
  • Experience with security incident response and forensic investigations.
  • Experience with supporting security in cutting-edge software or hardware development organization

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

About Company

Similar Jobs

12-14 yrs
Bengaluru, India
Skills:
Pci Dss, cloud security, Soc, Cyber Risk Management, Application Security, Iso 27001, DevSecOps, Iam, Siem, RBI regulations, secure-by-design practices, Security Audits
8-10 yrs
Bengaluru, India
Skills:
Network Security, Dlp, Siem, ZTNA, EDR, XDR, SOAR
8-12 yrs
Bengaluru, India
Skills:
Iso 27001, Siem, Penetration Testing, AWS, cloud security, Vulnerability Management, Identity Management, Gcp, Data Loss Prevention, Azure, RBI Master Directions, IRDAI guidelines, cloud-native security tools, incident response planning, risk management principles, data residency, endpoint protection, encryption at rest, zero trust, Security Architecture, least privilege, SOC 2 Type II, DPDP, compliance frameworks
15-17 yrs
Bengaluru, India
Skills:
secure coding , test automation, Shopify, SFCC, Application Security, Gcp, Terraform, React Native, Azure, Kubernetes, AWS, API-first design, CI CD, observability, cloud-native development
15-17 yrs
Bengaluru, India
Skills:
Identity And Access Management, Orchestration layers, End user and host security controls and technologies, Cloud architectures, Multiple operating systems, Enterprise-level Technology, Role-based access control, Enterprise IT Information Security, TCP IP networking architectures and systems, Server virtualization platforms