Twinings Ovaltine

Salary
Posted
Jun 28, 2026
Location
Last confirmed open
Jul 20, 2026

What this job asks for AI summary

A senior divisional security leadership role responsible for owning the cyber risk posture and IT governance, risk, and compliance environment for TwiningsOvaltine. The position involves operationalising group-level security standards locally, overseeing IT general controls across core platforms including SAP S/4HANA, embedding security into transformation programmes, and serving as the primary liaison to the parent group's CISO function and internal audit. It suits an experienced security and GRC leader comfortable working through influence rather than a large direct team.

Senior level · National · Full-time

Advertised as Principal, but the requirements read as Senior.

Must have (3)
IT GRCIT General Controls (ITGCs)audit readiness
Nice to have (5)
SAP S/4HANAISO 27001NIST CSFCIS Controlscloud security

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

Why we read it this way (9)

This role is based in India (location stated as 'India') — US compensation benchmarks do not apply.

The title is 'Director of Cyber Security & Governance', which maps to a Principal-level advertised seniority; however, the actual scope is a single-division business lead operating within a Group CISO framework with no large standing team, which is more consistent with a Senior band.

The role sits at the intersection of people leadership (BizTX Senior Leadership Team member, building culture and stakeholder relationships) and hands-on security/GRC ownership, making 11-3021 (Computer and Information Systems Managers) a credible alternative to 15-1212; 15-1212 was chosen because the JD emphasises owning the security posture and control environment as primary day-to-day work rather than managing a large team.

No minimum years of experience figure is stated explicitly; 'significant leadership experience' is qualitative only.

SAP S/4HANA, ISO 27001, NIST CSF, CIS Controls, cloud security (RISE), and AI governance all appear under the 'Desirable' section and are marked as preferred accordingly.

IT GRC, ITGCs, cyber risk management, audit readiness, identity & access management, and third-party/vendor risk assessment are drawn from the 'Essential' requirements section and are marked as required.

No compensation figures are provided in the posting beyond benefit reimbursement caps in INR.

Ignored 4 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): cyber risk management, identity & access management, third-party/vendor risk assessment, AI governance.

This role's work location reads as outside the US — the candidate pool, comp, and contention benchmarks here are US-only (BLS employment, Adzuna/USAJOBS demand, and certified H-1B wages), so treat them as a rough US reference, not a local market.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗