Security And Risk Governance Lead

Location
Ahmadabad City
Workplace
On-site

About this role

About the Role


Anderson Global is seeking an experienced Lead Information Security & Risk Manager to lead cybersecurity across our growing global organization.

This is a high-ownership role for a security professional who wants to build, influence, and drive meaningful security outcomes rather than operate within a large, siloed security team.

Reporting directly to the Global Head of Technology, you will serve as the primary internal security leader responsible for security operations, incident management, risk oversight, vendor governance, audits, and security improvement initiatives across multiple international offices.

You will work closely with our MDR partner, technology teams, business leaders, and external vendors to continuously strengthen our security posture while enabling business growth.

This role is ideal for someone who enjoys solving problems, challenging assumptions, building structure where little exists, and taking ownership of security outcomes.

Why This Role Is Different

·         Own security for a global organization spanning multiple countries and business units.

·         Direct access to executive leadership.

·         Opportunity to build and mature the security program.

·         Significant autonomy and decision-making authority.

·         Broad exposure across cloud platforms, Microsoft 365, SaaS applications, identity, endpoint security, and third-party risk.

·         Opportunity to influence technology strategy and security culture.

Key Responsibilities

·         Act as the primary owner of cybersecurity across the organization.

·         Manage and govern our MDR provider and security vendors.

·         Coordinate and lead security incident response activities.

·         Maintain and manage the enterprise security risk register.

·         Conduct security reviews and internal audits across global offices.

·         Drive remediation of security risks, vulnerabilities, and audit findings.

·         Review new technologies, vendors, and business initiatives from a security perspective.

·         Support client due diligence requests, security questionnaires, and audit activities.

·         Develop and improve security policies, standards, and governance processes.

·         Lead security awareness and security improvement initiatives.

·         Provide regular risk updates and recommendations to leadership.



Requirements

What We Are Looking For

·         Strong sense of ownership and accountability.

·         Passion for cybersecurity and continuous learning.

·         Curiosity and an investigative mindset.

·         Ability to challenge assumptions and identify hidden risks.

·         Excellent communication and stakeholder management skills.

·         Comfortable operating independently and driving initiatives forward.

·         Ability to balance security requirements with practical business needs.

·         Comfortable building processes, governance, and structure where little currently exists.

Required Experience

·         5+ years of experience in cybersecurity, information security, risk management, or related disciplines.

·         Experience managing security vendors and service providers.

·         Experience coordinating security incidents and remediation activities.

·         Strong understanding of cloud security, identity management, endpoint security, email security, and security operations.

·         Experience supporting audits, assessments, and compliance initiatives.

·         Strong documentation, organizational, and project management skills.

Preferred Qualifications

·         CISSP, CISM, CRISC, Security+, ISO 27001, or similar certifications.

·         Experience within financial services, professional services, or regulated industries.

·         Experience working with MDR, SIEM, vulnerability management, and security monitoring programs.

·         Familiarity with ISO 27001, NIST, CIS Controls, SOC 2, and GDPR.

What Success Looks Like

·         Establish effective governance of security vendors and MDR providers.

·         Build and maintain an enterprise security risk register.

·         Improve visibility into security risks across all offices.

·         Strengthen incident response and security governance processes.

·         Reduce organizational security risk through measurable improvements.

·         Become the trusted security advisor to leadership.



Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?