06 Aug
|
PNG Jewellers
|
Pune
06 Aug
PNG Jewellers
Pune
Role & responsibilities
- Design, implement, and maintain the enterprise Information Security Management System (ISMS) aligned with ISO 27001 standards, driving the organisation toward certification readiness.
- Own the compliance roadmap across all applicable frameworks SEBI CSCRF, DPDP Act 2023, CERT-In incident reporting directives, ITGC/ICFR controls, and PCI DSS for payment environments.
- Conduct periodic risk assessments, vulnerability analyses, and control gap evaluations across IT infrastructure, applications, and third-party integrations.
- Coordinate and manage VAPT (Vulnerability Assessment & Penetration Testing) cycles across web, mobile, and API surfaces, tracking remediation to closure.
- Develop and enforce IT security policies, access control frameworks, data classification standards, and incident response procedures.
- Serve as the primary point of contact for internal auditors, statutory auditors, and regulatory bodies on all IT security and compliance matters.
- Drive security awareness training programmes across the organisation to build a culture of compliance and vigilance.
- Monitor and respond to security incidents, ensuring adherence to CERT-In reporting timelines and internal escalation protocols.
- Maintain audit-ready documentation policy registers, control evidence,
risk treatment plans, and compliance dashboards for board and audit committee review.
- Evaluate and manage third-party/vendor security risk, ensuring SLA and contractual compliance with data protection obligations.
Preferred candidate profile
- Graduate in any discipline; a Master's degree in Information Security, IT, or Management will be preferred.
- 7+ years of experience in information security, IT risk management, or IT compliance preferably in a listed company, BFSI, or organised retail workplace.
- CISA certification required; ISO 27001 Lead Auditor / Lead Implementer certification required. Additional certifications (CISSP, CRISC, CEH) are a strong advantage.
- In-depth knowledge of Indian regulatory frameworks like SEBI CSCRF, DPDP Act, CERT-In directives, and ITGC/ICFR controls.
- Hands-on experience with VAPT coordination, security audits, and remediation tracking.
- Familiarity with PCI DSS compliance requirements for retail payment environments.
- Strong documentation and reporting skills ability to present security posture and compliance status to board-level stakeholders.
- Excellent stakeholder management skills across IT, business, legal, and external audit teams.
📌 Manager- Security & Compliance (Pune)
🏢 PNG Jewellers
📍 Pune