Salary
≈ $17k – $37k per year (Estimated)
Location
In office (Mumbai)
Experience
8+ years exp
First seen by Alion on Sep 30, 2026.
Overview
Company
Impact
Profile match
Purpose :
Lead and continuously improve SPNI's information security program across governance, risk, compliance, architecture, cloud, identity, vulnerability management and incident response.
Align business needs with Sony Global policies, ISO/IEC 27001:2022, SOX/ITGC and applicable legal, regulatory and contractual requirements, including India's DPDP Act readiness, while translating security requirements into practical controls across on-premises, AWS, Azure, Microsoft 365 and hybrid environments.
Key Responsibilities :
- Own and continually improve the ISO/IEC 27001:2022-aligned ISMS; maintain scope, risk methodology, Statement of Applicability, treatment plans and evidence; manage certification/surveillance audits, management reviews and governance forums.
- Develop and periodically review security policies, standards, procedures and frameworks; establish control ownership, review cycles, exception handling, escalation, audit readiness and remediation assurance for Sony Global requirements, SOX/ITGC and applicable obligations.
- Define executive KPIs/KRAs and dashboards covering material risks, control gaps, compliance status, remediation priorities, critical exposure, aging, recurrence, vendor risk and operational performance.
Enterprise & Third-Party Risk Management :
- Lead periodic and change-triggered risk assessments across business processes, technology, projects and suppliers; maintain a consolidated register with owners, ratings, actions, target dates, residual risk and formal acceptance; escalate overdue or material exposures.
- Assess emerging threats, technology and regulatory developments; agree proportionate mitigation with business and technology stakeholders and communicate significant weaknesses to leadership.
- Own the third-party risk framework: classify vendors by criticality, data, privilege and dependency; perform security/privacy due diligence; evaluate responses and assurance reports; track gaps and residual risk; periodically reassess and monitor critical/high-risk vendors.
- Partner with Procurement and Legal to embed security, confidentiality, personal-data protection, incident reporting, subcontracting and exit clauses, and report unresolved material vendor risk.
Security Architecture, Network, Cloud & Platform Security :
- Review on-premises, cloud and hybrid designs, including firewalls, VPN, proxy/SWG, IDS/IPS, DNS, TLS, load balancers, WAF, DDoS controls, AWS Direct Connect, Azure ExpressRoute and site-to-site VPN; apply Zero Trust and least privilege, validate implementation, and document exceptions/residual risk.
- Oversee hardening procedures for servers, databases, workstations, laptops and mobile devices; assess backup protection, recovery access and resilience controls.
- Assess AWS accounts and Azure subscriptions across IAM/Entra ID, privileged/service/workload identities, networking, compute, storage, management plane, KMS/Secrets Manager/Key Vault, CloudTrail, GuardDuty, Security Hub, Azure Activity Logs and Defender for Cloud; prioritize posture findings and support secure baselines, IaC reviews and automated checks.
- Assess Microsoft 365, including Exchange Online, SharePoint, OneDrive and Teams; review MFA, Conditional Access, PIM, authentication methods, legacy authentication, guest/external access, application consent, enterprise apps and service principals.
- Review phishing, malicious attachment, impersonation and BEC protection; evaluate Defender for Office 365/XDR; validate audit logging and centralized monitoring; review sensitivity labels, DLP and external sharing with data owners/compliance teams.
Vulnerability, Monitoring & Incident Response :
- Continuously improve vulnerability platforms, processes and coverage across servers, endpoints, network devices, cloud workloads, web applications and internet-facing assets; perform authenticated scans, configuration reviews and authorized validation using Qualys, Nessus and Burp Suite.
- Validate findings and false positives; prioritize by exploitability, criticality, exposure and business impact; agree SLAs, compensating controls and risk acceptance; retest fixes, preserve closure evidence and coordinate with Global Vulnerability Management/regional teams.
- Monitor and investigate SIEM, endpoint, network, cloud, identity and Microsoft 365 alerts; correlate telemetry, distinguish false positives/configuration issues/incidents, determine scope and attack paths, and execute authorized containment and remediation.
- Support recovery, evidence preservation, root-cause analysis and accurate timelines; improve detections, queries, playbooks, alert tuning and log onboarding; conduct threat hunting, simulations/tabletops, document lessons and track corrective actions.
- Escalate personal-data or regulatory matters to Legal, Privacy and GRC.
- Investigate identity compromise, suspicious sign-ins, malicious inbox rules, risky OAuth apps and unauthorized sharing.
AI Security, Awareness, Reporting & Collaboration :
- Assess AI-enabled services for sensitive-data exposure, permissions, third-party processing, insecure connectivity, prompt injection, unsafe tool access and unintended disclosure; review approved use, access restrictions, logging and protection settings with Architecture, Legal, Privacy and GRC.
- Run a risk-based security/privacy awareness program using LMS training, phishing simulations and targeted education; measure completion, reporting behavior and repeat susceptibility, and promote good practice among employees, vendors and stakeholders.
- Maintain architecture reviews, assessment reports, incident records, technical procedures and remediation evidence; support audits with technical evidence and control validation; communicate clearly to technical and non-technical audiences.
- Collaborate with Global Information Security Operations, Global Vulnerability Management, Infrastructure, Cloud, Network, Applications and local teams; automate assessments, alert enrichment and reporting through scripting/APIs; stay current on threats, attack techniques and security technologies.
Experience, Qualifications & Success Measures :
- Hands-on ownership of an ISO/IEC 27001-aligned ISMS, audits, security risk/control assurance, policy governance, audit remediation, third-party risk and executive reporting.
- Hands-on security across AWS, Azure and Microsoft 365, with depth in at least one cloud; cloud IAM/Entra ID, PIM, MFA and Conditional Access; infrastructure, application, identity and data-protection controls.
Skills
Security, Information Security, GRC, Security Operations Center, ISMS, TPRM, Cloud Security, Vulnerability Management, Security Risk Management
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,053,222 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Free forever. No card. Under a minute.
Your match
How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.
Recommended for you based on this role
Security
Similar stack
Same company
Mumbai
Senior Information Security Engineer
1 day ago
≈ $99k – $194k per year (Estimated) • Hybrid • Contractor • 5+ years exp • Columbus
Python
JavaScript
PowerShell
Bash
DevOps
Ansible
Windows Server
Incident Management
Amazon S3
Windows
Management
Agile
Scrum
Kanban
Apply
Junior Security Engineer
1 day ago
≈ $19k – $54k per year (Estimated) • In office • Sofia
Python
PowerShell
DevOps
Splunk
Windows
TCP/IP
DNS
Cybersecurity
Crowdstrike
Nessus
Qualys Cloud Platform
OpenVAS
SIEM
Apply
DevSecOps Engineer
27 min ago
$80k – $175k per year • In office • 5+ years exp • Master's Degree • McLean
Python
Ruby
PowerShell
Groovy
DevOps
Terraform
Ansible
GCP
OpenShift
Helm
GitHub Actions
Podman
Chef
CircleCI
CloudFormation
GitLab CI
Azure
CI/CD
Jenkins
Git
AWS
Docker
Kubernetes
Concourse
Bitbucket
GitHub
GitLab
Management
Agile
QA
Selenium
Apply
$130k – $180k per year • In office • 7+ years exp • Bachelor's Degree • McLean
Python
Ruby
PowerShell
DevOps
Rest API
Terraform
Ansible
Chef
CloudFormation
Git
AWS
Bitbucket
GitHub
GitLab
Cybersecurity
Zero Trust
Threat Modeling
SIEM
Management
Agile
Apply
Cloud Security Engineer
27 min ago
$110k – $155k per year • In office • 5+ years exp • Bachelor's Degree • McLean
Python
Ruby
PowerShell
DevOps
Rest API
Terraform
Ansible
GCP
Chef
CloudFormation
Azure
Git
AWS
Concourse
Bitbucket
GitHub
GitLab
Cybersecurity
Zero Trust
Threat Modeling
SIEM
Management
Agile
Apply
Solution Architect
2 days ago
$33k – $42k per year (gross) • In office • 12+ years exp • Chennai
Python
Java
C#
C#
.NET
Databases
DynamoDB
DevOps
Rest API
Azure
CI/CD
AWS
Docker
Kubernetes
Amazon EKS
AWS Lambda
Amazon EC2
Amazon S3
IAM
Amazon ECS
Amazon CloudWatch
Amazon EventBridge
API Gateway
Management
Agile
Apply
AI Engineer - NLP/Deep Learning
2 days ago
≈ $33k – $76k per year (Estimated) • Remote (likely India) • 10+ years exp • Bengaluru
Python
SQL
AI/ML
LangChain
MLFlow
Embeddings
Scikit-learn
Computer Vision
NLP
Kubeflow
TensorFlow
Pandas
NumPy
PyTorch
OpenAI
Hugging Face
Recommender Systems
Machine Learning
DevOps
GCP
Azure
CI/CD
Git
AWS
Docker
Apply
AI/ML Engineer
2 days ago
≈ $20k – $51k per year (Estimated) • In office • Full-Time • 5+ years exp • Malaysia
Python
Databases
PostgreSQL
Databricks
AI/ML
OpenCV
Scikit-learn
Computer Vision
TensorFlow
PyTorch
Time Series Forecasting
Recommender Systems
Machine Learning
DevOps
AWS
Analytics
Power BI
Apply
Windows server SCCM/Intune Customer Engineer
2 days ago
≈ $22k – $51k per year (Estimated) • In office • Full-Time • 10+ years exp • Malaysia
SQL
PowerShell
Databases
Snowflake
AI/ML
Edge AI
DevOps
Windows Server
AWS
Windows
DNS
Cybersecurity
Active Directory
Analytics
Power BI
Apply
Software Developer (Support)
2 days ago
In office • Full-Time • Bachelor's Degree • Lahore • Islamabad
C#
C#
.NET
Databases
MS SQL
DevOps
Azure
Apply
Automation & AI Specialist
2 days ago
≈ $11k – $29k per year (Estimated) • In office • 2+ years exp • Mumbai
Python
JavaScript
Node JS
Apex
Apex
Salesforce Industries
Databases
Amazon Redshift
AI/ML
Cursor
AutoGen
LangChain
Claude Code
AI Agents
Semantic Kernel
LLM
OpenAI
Multi-Agent Systems
DevOps
Azure
AWS
Self-Healing
AWS Lambda
Amazon S3
Cybersecurity
DLP
Management
n8n
Power Automate
Apply
IN_Senior Manager_ SAP MM_SAP_Advisory_Mumbai
9 hours ago
≈ $13k – $30k per year (Estimated) • In office • Full-Time • 12+ years exp • Bachelor's Degree • Mumbai
ABAP
ABAP
CDS Views
Databases
SAP HANA
Apply
≈ $14k – $32k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Mumbai
Java
ABAP
DevOps
Rest API
SOAP
Apply
Digital Technology Specialist - Data Science
10 hours ago
≈ $14k – $34k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Mumbai
Python
SQL
Databases
Weaviate
Databricks
Chroma
Pinecone
AI/ML
Spark
MLFlow
XGBoost
Scikit-learn
Prompt Engineering
AI Agents
TensorFlow
PyTorch
RAG
Time Series Forecasting
Machine Learning
DevOps
GCP
Azure
AWS
Docker
Kubernetes
Analytics
ETL/ELT
Apply
In office • Full-Time • Mumbai
Analytics
Master Data Management
Apply
Head of Finance, SH ISC Mumbai
10 hours ago
≈ $23k – $50k per year (Estimated) • In office • Full-Time • 12+ years exp • Master's Degree • Mumbai
Apply
This is one of many
1,053,222 more open roles from verified company boards, updated every day.

