Virtual Chief Information Security Officer (vCISO) - OT & Cybersecurity Governance
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
Role Overview
Position Title: Virtual Chief Information Security Officer (vCISO) - OT & Cybersecurity Governance
Key Skills for This Role
Full Job Posting
Reporting To
Service Delivery Director
Job Purpose
The Virtual Chief Information Security Officer (vCISO) will provide strategic leadership and governance for Cybersecurity and Operational Technology (OT) security program. The role is responsible for establishing and executing the cybersecurity strategy, developing governance frameworks, managing cyber risk, ensuring regulatory and audit compliance, overseeing security policies and controls, driving security awareness, coordinating incident response activities, and providing executive-level reporting to management and Board stakeholders.
The vCISO will act as trusted cybersecurity advisor, ensuring that IT and OT environments remain secure, resilient, compliant, and aligned with business objectives. The role will be particularly focused on securing mining operations, industrial control systems, SCADA environments, critical infrastructure, and enterprise technology platforms.
Security Strategy & Leadership
Develop and maintain Cybersecurity and OT Security Strategy.
Define short-term, medium-term, and long-term security roadmaps.
Align cybersecurity initiatives with business objectives and operational risks.
Advise executive leadership on security priorities, investments, and emerging threats.
Establish cybersecurity governance structures and steering committees.
OT Security Governance
Develop security controls and governance frameworks for Operational Technology (OT) environments.
Assess and improve security posture across mining operations, industrial networks, SCADA systems, and production environments.
Define network segmentation and security architecture standards between IT and OT environments.
Oversee OT cybersecurity risk management and mitigation programs.
Recommend security controls for critical industrial infrastructure.
Cyber Risk Management
Establish enterprise cybersecurity risk management frameworks.
Conduct cyber risk assessments and maturity assessments.
Maintain Cyber Risk Registers and remediation roadmaps.
Identify vulnerabilities, threats, and potential business impacts.
Present risk findings and mitigation plans to executive leadership and governance boards.
Security Governance & Compliance
Establish cybersecurity policies, standards, procedures, and security baselines.
Define governance controls for identity management, privileged access, endpoint security, network security, cloud security, and OT environments.
Ensure compliance with industry standards and internal security requirements.
Support internal audits, external audits, and regulatory assessments.
Drive closure of audit observations and security findings.
Security Architecture & Control Oversight
Review and approve security designs for infrastructure and transformation initiatives.
Provide governance over firewalls, VPNs, endpoint protection, identity services, network security, cloud security, and monitoring platforms.
Ensure security-by-design principles are adopted across projects.
Review security exceptions and compensating controls.
Advise on technology investments and cybersecurity improvements.
Incident Response & Cyber Resilience
Establish and maintain Cyber Incident Response and Escalation Procedures.
Provide executive oversight during cybersecurity incidents.
Coordinate investigation, containment, recovery, and post-incident reviews.
Ensure lessons learned and corrective actions are implemented.
Develop cybersecurity resilience, business continuity, and disaster recovery governance programs.
Security Awareness & Culture
Develop and lead enterprise-wide cybersecurity awareness programs.
Conduct executive security awareness sessions and phishing simulations.
Promote cybersecurity best practices across business and operational teams.
Develop security communications, advisories, and awareness campaigns.
Improve overall security maturity and culture.
Executive & Board Reporting
Prepare cybersecurity dashboards and executive reports.
Present cybersecurity risks, compliance status, incidents, and strategic initiatives to management and board members.
Define and report cybersecurity KPIs, KRIs, and maturity metrics.
Provide recommendations on risk acceptance, mitigation priorities, and investment planning.
Facilitate periodic Cybersecurity Governance Review meetings.
Third-Party & Vendor Security Governance
Assess third-party cybersecurity risks.
Review vendor security controls and compliance requirements.
Participate in contract reviews from a security perspective.
Ensure suppliers and service providers comply with security expectations.
Monitor remediation of third-party security risks.
Core Cybersecurity Competencies
Cybersecurity Governance
OT/ICS/SCADA Security
Enterprise Security Architecture
Risk Management
Security Compliance & Audits
Incident Response Governance
Business Continuity & Disaster Recovery
Security Awareness & Training
Third-Party Risk Management
Security Program Development
Technical Knowledge
Industrial Control Systems (ICS)
SCADA Security
Network Security
Identity & Access Management (IAM)
Privileged Access Management (PAM)
Endpoint Security
Cloud Security (M365, Azure, AWS)
Vulnerability Management
Security Operations & SIEM
Data Protection & Information Security
Experience
15+ years of IT and Cybersecurity experience.
8+ years in Cybersecurity Leadership, Governance, or CISO-level functions.
Demonstrated experience securing OT, SCADA, Industrial, Mining, Utilities, Manufacturing, or Critical Infrastructure environments.
Experience leading audit readiness, risk management, and enterprise security programs.
Experience presenting to Executive Leadership and Board-level stakeholders.
Educational Qualifications
- Bachelor's Degree in Information Technology, Cybersecurity, Computer Science, Engineering, or related field.
- Master's Degree preferred.
Preferred Certifications
CISSP
CISM
CRISC
CGEIT
ISO 27001 Lead Implementer / Lead Auditor
IEC 62443 (Industrial Cybersecurity)
CCSP or equivalent cloud security certification
About Zensar
Global technology firm providing digital transformation and infrastructure services.
Visit company websiteJobs and hiring trendsApply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at Zensar
Enterprise architect
, GBR
Enterprise Architect- German Speaking Role Description The Enterprise Architect (EA) serves as the primary technical driver for closing sales opportunities and supporting existing customer success with their marketing te
AES - Application Modernization - Advanced Skills - Cloud
, IND
Role Overview We are seeking an experienced Senior Software Engineer / Technical Lead with 8+ years of hands-on development experience and 3+ years of team leadership experience. The ideal candidate will have strong expe
AES - DE - MOBILITY - Cross Platform - ReactNative
Hyderabad, IND
We're seeking a Senior React Native Developer with 10+ years of experience building secure, high-performance cross-platform mobile apps. The ideal candidate is expert in React Native (JavaScript/TypeScript) with working
Frontend Lead
, IND
Lead mobile/frontend architecture across Android, iOS, and Flutter. Drive quality, scalability, and integration standards.
Broadcom API Gateway implementations (Layer7)
, IND
Skill Set: 5 to 8 Years of work exp. Must Have: Hands on experience with Broadcom API Gateway implementations (Layer 7) Java/J2EE experience for IAM custom code integration & management. SAML 2.0 Provider [preferrable Si
Java AI Engineer
, IND
Role Overview We are seeking a skilled AI Engineer to design, develop, deploy, and optimize AI-powered solutions that drive business value. The ideal candidate will have expertise in Machine Learning, Generative AI, Larg
BUSINESS FINANCE MANAGER
Pune, IND
Zensar Technologies Limited is looking for a proactive Business Finance Manager to join its Finance department. The role will focus on applying Ind AS 115 revenue‐recognition guidelines, handling complex accounting tasks
D 365- Data Engineer
, IND
We are seeking a highly skilled Senior Data Engineer with 8–12 years of experience in designing, developing, and managing scalable data platforms and enterprise data solutions. The ideal candidate will have strong expert
Enterprise architect
, GBR
AES - Application Modernization - Advanced Skills - Cloud
, IND
AES - DE - MOBILITY - Cross Platform - ReactNative
Hyderabad, IND
Frontend Lead
, IND
Broadcom API Gateway implementations (Layer7)
, IND
Java AI Engineer
, IND
BUSINESS FINANCE MANAGER
Pune, IND
D 365- Data Engineer
, IND