Role Summary
KALKINE is seeking a Senior Manager – Information Security & Cybersecurity to own the organization’s security posture across operations in Australia, UK, Canada, New Zealand, USA, and India. This is a hands-on role combining technical cybersecurity depth with governance, risk, and compliance (GRC) expertise in a regulated financial environment. The ideal candidate can script and automate security operations, not just manage vendor tools.
Key Responsibilities
1. Security Program Management: Own the ISMS (ISO 27001), drive policies, risk assessments, and incident response lifecycle; report KPIs to leadership.
2. VAPT: Plan and execute vulnerability assessments and penetration tests; automate scanning/reporting with Python; track remediation.
3. SIEM & Threat Monitoring: Manage SIEM platform (Sentinel/Splunk/QRadar), build detection rules, conduct threat hunting via EDR/log analysis.
4. DLP & Endpoint Security: Administer DLP, data classification, UEM/MDM, and email security (DMARC/DKIM/SPF).
5. Cloud & Infrastructure Security: Harden AWS/Azure/M365 environments; implement IAM, CSPM, and zero-trust practices.
6. Compliance: Lead ISO 27001, SOC 2, PCI DSS, and DPDP audits; manage multi-jurisdictional regulatory compliance (GDPR, Privacy Act, PIPEDA).
7. Security Awareness: Design and run enterprise-wide training and phishing simulation programs.
8. Vendor Risk: Conduct third-party security assessments and manage supply chain risk.
Team Leadership: Lead a multi-geography security team; present risk and programs updates to C-suite/board.
Required Skills
1. Programming: Python (security automation, scripting); working knowledge of Bash/PowerShell.
2. Tools: Burp Suite, Nmap, Metasploit, Nessus/Qualys, Wireshark.
3. SIEM/EDR: Hands-on with a major SIEM (Sentinel/Splunk/QRadar) and EDR (CrowdStrike/SentinelOne/Defender)
4. Cloud & Identity: AWS/Azure security tools, Active Directory, Entra ID, MFA, PAM.
5. GRC: ISO 27001 (Lead Implementer/Auditor preferred), PCI DSS, SOC 2, DPDP, GDPR working knowledge
Certifications Like - CISSP, CISM, CEH/OSCP, ISO 27001 Lead Implementer/Auditor, AWS Security Specialty or SC-200/AZ-500. Etc.
- Soft Skills -
- 1. Excellent communication skills.
- 2. Ability to work independently and within timelines.
- 3. High level of integrity and confidentiality.
- 4. Eagerness to learn.
- 5. Strong stakeholder communication across geographies; confidence with auditors/regulators; report-writing skills; coaching mindset for team development
Security Program Management, VAPT, SIEM, Threat Monitoring, DLP, Endpoint Security, Information Security, Cybersecurity.