Zensar Technologies logo

Virtual Chief Information Security Officer (Vciso) - OT & Cybersecurity Governance

Zensar Technologies
  • India, TN
    6 days ago

    Job Description

    Job Description

    Position Title: Virtual Chief Information Security Officer (vCISO) - OT & Cybersecurity Governance

    Location

    Hybrid (Remote with Scheduled Onsite Visits to Nchanga)

    Reporting To

    Service Delivery Director

    Job Purpose

    The Virtual Chief Information Security Officer (vCISO) will provide strategic leadership and governance for Cybersecurity and Operational Technology (OT) security program. The role is responsible for establishing and executing the cybersecurity strategy, developing governance frameworks, managing cyber risk, ensuring regulatory and audit compliance, overseeing security policies and controls, driving security awareness, coordinating incident response activities, and providing executive-level reporting to management and Board stakeholders.

    The vCISO will act as trusted cybersecurity advisor, ensuring that IT and OT environments remain secure, resilient, compliant, and aligned with business objectives. The role will be particularly focused on securing mining operations, industrial control systems, SCADA environments, critical infrastructure, and enterprise technology platforms.

    Key Responsibilities

    Security Strategy & Leadership

    • Develop and maintain Cybersecurity and OT Security Strategy.
    • Define short-term, medium-term, and long-term security roadmaps.
    • Align cybersecurity initiatives with business objectives and operational risks.
    • Advise executive leadership on security priorities, investments, and emerging threats.
    • Establish cybersecurity governance structures and steering committees.

    OT Security Governance

    • Develop security controls and governance frameworks for Operational Technology (OT) environments.
    • Assess and improve security posture across mining operations, industrial networks, SCADA systems, and production environments.
    • Define network segmentation and security architecture standards between IT and OT environments.
    • Oversee OT cybersecurity risk management and mitigation programs.
    • Recommend security controls for critical industrial infrastructure.

    Cyber Risk Management

    • Establish enterprise cybersecurity risk management frameworks.
    • Conduct cyber risk assessments and maturity assessments.
    • Maintain Cyber Risk Registers and remediation roadmaps.
    • Identify vulnerabilities, threats, and potential business impacts.
    • Present risk findings and mitigation plans to executive leadership and governance boards.

    Security Governance & Compliance

    • Establish cybersecurity policies, standards, procedures, and security baselines.
    • Define governance controls for identity management, privileged access, endpoint security, network security, cloud security, and OT environments.
    • Ensure compliance with industry standards and internal security requirements.
    • Support internal audits, external audits, and regulatory assessments.
    • Drive closure of audit observations and security findings.

    Security Architecture & Control Oversight

    • Review and approve security designs for infrastructure and transformation initiatives.
    • Provide governance over firewalls, VPNs, endpoint protection, identity services, network security, cloud security, and monitoring platforms.
    • Ensure security-by-design principles are adopted across projects.
    • Review security exceptions and compensating controls.
    • Advise on technology investments and cybersecurity improvements.

    Incident Response & Cyber Resilience

    • Establish and maintain Cyber Incident Response and Escalation Procedures.
    • Provide executive oversight during cybersecurity incidents.
    • Coordinate investigation, containment, recovery, and post-incident reviews.
    • Ensure lessons learned and corrective actions are implemented.
    • Develop cybersecurity resilience, business continuity, and disaster recovery governance programs.

    Security Awareness & Culture

    • Develop and lead enterprise-wide cybersecurity awareness programs.
    • Conduct executive security awareness sessions and phishing simulations.
    • Promote cybersecurity best practices across business and operational teams.
    • Develop security communications, advisories, and awareness campaigns.
    • Improve overall security maturity and culture.

    Executive & Board Reporting

    • Prepare cybersecurity dashboards and executive reports.
    • Present cybersecurity risks, compliance status, incidents, and strategic initiatives to management and board members.
    • Define and report cybersecurity KPIs, KRIs, and maturity metrics.
    • Provide recommendations on risk acceptance, mitigation priorities, and investment planning.
    • Facilitate periodic Cybersecurity Governance Review meetings.

    Third-Party & Vendor Security Governance

    • Assess third-party cybersecurity risks.
    • Review vendor security controls and compliance requirements.
    • Participate in contract reviews from a security perspective.
    • Ensure suppliers and service providers comply with security expectations.
    • Monitor remediation of third-party security risks.

    Required Skills & Experience

    Core Cybersecurity Competencies

    • Cybersecurity Governance
    • OT/ICS/SCADA Security
    • Enterprise Security Architecture
    • Risk Management
    • Security Compliance & Audits
    • Incident Response Governance
    • Business Continuity & Disaster Recovery
    • Security Awareness & Training
    • Third-Party Risk Management
    • Security Program Development

    Technical Knowledge

    • Industrial Control Systems (ICS)
    • SCADA Security
    • Network Security
    • Identity & Access Management (IAM)
    • Privileged Access Management (PAM)
    • Endpoint Security
    • Cloud Security (M365, Azure, AWS)
    • Vulnerability Management
    • Security Operations & SIEM
    • Data Protection & Information Security

    Experience

    • 15+ years of IT and Cybersecurity experience.
    • 8+ years in Cybersecurity Leadership, Governance, or CISO-level functions.
    • Demonstrated experience securing OT, SCADA, Industrial, Mining, Utilities, Manufacturing, or Critical Infrastructure environments.
    • Experience leading audit readiness, risk management, and enterprise security programs.
    • Experience presenting to Executive Leadership and Board-level stakeholders.

    Educational Qualifications

    • Bachelor's Degree in Information Technology, Cybersecurity, Computer Science, Engineering, or related field.
    • Master's Degree preferred.

    Preferred Certifications

    • CISSP
    • CISM
    • CRISC
    • CGEIT
    • ISO 27001 Lead Implementer / Lead Auditor
    • IEC 62443 (Industrial Cybersecurity)
    • CCSP or equivalent cloud security certification

    Numbers & Facts

    LocationIndia, TN
    IndustryComputer/IT Services
    Company Size5,000 to 9,999 employees
    Year Founded2001
    Websitehttp://www.zensar.com/

    About Company

    Zensar Technologies is a technology partner of choice for global organizations looking to strategically transform, grow, and lead in today’s challenging business environment. Backed by a strong track-record of innovation, over 8000 associates and footprint in 29 global locations, Zensar’s comprehensive range of software services and solutions enable its 400+ forward-looking customers to cross new thresholds of business performance. The Company owing to its growth in recent times has moved up the NASSCOM listing of Software Service Companies in India to #13 this year. This is reiterated in the Porter’s Prize for Best Strategic Management in the Information, Media and Telecom Industries that has been bestowed upon the Company. A noted publication, Dataquest in its Top 200 listing has rated Zensar 20 notches higher this year, given its performance. Zensar operates in the US, Europe, Africa, Middle East, Singapore and Australia regions and has delivery centers in India (Pune, Hyderabad and Bangalore), China,UK, Amsterdam and US (Westborough). Zensar is the world's first enterprise-wide SEI CMM Level 5 Company. The Company has a services portfolio that ranges from the traditional to the transformational - across service lines of Management Consulting, Business Application Services, Enterprise Solutions, Enterprise Collaboration Services, Testing and Assurance Services, BPM and Infrastructure Management Services. Zensar’s experience across industries of Retail, Manufacturing, Insurance, Banking, Healthcare and others translate into a differentiated value proposition and faster time-to-market for clients. Our capability in infrastructure-oriented services ranges from remote infrastructure management to end user computing to data centre services and security and compliance. Zensar is now leading the way in powering next-generation enterprises with its cloud, mobility and social media solutions. The Company has been recognized for its exceptional service capabilities and industry-leading solutions, and has bagged prestigious awards in areas such as R&D, people practices, CSR programs and sustainability initiatives. Zensar's Corporate Social Responsibility programs focus on creating sustainable development and livelihood for local communities. At Zensar, we see Innovation as a clear differentiator. Innovation, along with focus on deep, long-lasting client relationships and strong domain expertise, drives every facet of our day-to-day operation. For our clients, it translates into strategic business value and for us, into consistent financial performance – Zensar clocked 25.3 percent average revenue growth over the last five years. We believe in leveraging the power of innovation to seize new opportunities. So, employees are encouraged to challenge opinions and ideas, and to push the boundaries of what is possible. Different perspectives that arise out of Zensar’s world culture - entailing diversity of gender, region, nationality, background, or education - blend to transform every vision into reality. Our Global Delivery Model, defined by robust service capabilities and the ability to source best talent from across the world, is backed by 24X7X365 support. The result: Superior value for clients.

    Skills

    • Amazon Web Services (AWS)unmatched
    • Auditingunmatched
    • Business Operationsunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Campaignsunmatched
    • Cloud Computingunmatched
    • Communications Security (COMSEC)unmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Contract Reviewunmatched
    • Control Systemsunmatched
    • Corrective Actionunmatched
    • Disaster Recoveryunmatched
    • Endpoint Securityunmatched
    • Enterprise Architectureunmatched
    • Enterprise Protectionunmatched
    • External Auditunmatched
    • Firewallsunmatched
    • ISO (International Organization for Standardization)unmatched
    • Identity Data Managementunmatched
    • Incident Managementunmatched
    • Incident Responseunmatched
    • Industry Standardsunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internal Auditunmatched
    • International Electro-Technical Commission (IEC)unmatched
    • Internet Securityunmatched
    • Investment Servicesunmatched
    • Leadershipunmatched
    • Maintain Complianceunmatched
    • Manufacturingunmatched
    • Metricsunmatched
    • Microsoft Windows Azureunmatched
    • Mine Operationsunmatched
    • Mine Securityunmatched
    • Network Securityunmatched
    • Performance Metricsunmatched
    • Phishingunmatched
    • Policy Developmentunmatched
    • Production Systemsunmatched
    • Protective Servicesunmatched
    • Regulationsunmatched
    • Regulatory Complianceunmatched
    • Reporting Dashboardsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Risk Management Framework (RMF)unmatched
    • Security Analysisunmatched
    • Security Architectureunmatched
    • Security Auditingunmatched
    • Security Complianceunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Infrastructureunmatched
    • Security Monitoringunmatched
    • Service Deliveryunmatched
    • Strategic Planningunmatched
    • Supervisory Control and Data Acquisition (SCADA)unmatched
    • VPN (Virtual Private Network)unmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder