Incumbent serves as an information security executive and will be required to work with information security team members from respective work area
Job Designation:
ISMS Compliance - Manager / Deputy Manager
Key Responsibilities:
- Develops & revises information security policies & procedures
- Initiates, facilitates and promotes activities to create information security awareness within the organization
- Managing Information Security Exception Management by resolving service requests
- Supports and Facilitates Customer and 3rd Party Information Security Audits
- Plans and performs internal audit and technical compliance checks
- Provide necessary support in filling out RFI/RFP/Customer Contracts/SOW requirements
- Organizes & conducts ISMS core team meetings and security council
- Facilitates the process owners in performing the risk assessment & mitigation actions
- Facilitates the process owners in performing the root cause analysis for the critical incidents & other non-conformities identified during internal / external / customer audits
- Monitors compliance with information security policies and procedures, referring problems to the appropriate Function / Operation Manager and report to CISO
- Develops and supervises all information security measures in the organization
- Advises the team with current details about information security technologies and related regulatory issues
- Assists the BCP / DR team in establishing the robust framework on business continuity & disaster recovery
- Managing customer specific compliance as per customer requirements
General Skills and Specifications:
- Ability to define problems, collect data, establish facts, and draw valid conclusions
- Ability to work independently and to take emergent decisions on his/her own
- Ability to effectively present information and respond to questions from top management, groups of managers and customers
- Experience across developing policies, standards, and procedures as per ISO/IEC 27001, TiSAX and other information security related standards / frameworks
- Robust Auditing skill, well differentiation between observation & Non-conformances. Analysis of Audit findings to indicate trend and identify the weak area
- Good knowledge of GDPR and DPDPA regulations / requirements and implementation
- Hands-on on conducting process trainings and facilitate eternal certification audits
- Implementation knowledge on BCP and DR policies / procedures at Org level and customer account level
- Excellent interpersonal communication and organizational skills with demonstrated abilities in team crisis management. Valuable team player, Strong team orientation & leadership qualities, hardworking, enthusiastic with good attitude
Education & Qualifications:
- Bachelors degree / Masters Degree or higher in Computer Science, Information Systems or a related field.
- At least 10 - 20 years of experience in computing or related area with a focus on information security related activities.
- Lead Auditor on ISO/IEC 27001 standard and other security related frameworks
Professional IT security related certifications is an added advantage.
Work Experience
Education & Qualifications:
- Bachelor’s degree / Master’s Degree or higher in Computer Science, Information Systems or a related field.
- At least 10 - 20 years of experience in computing or related area with a focus on information security related activities.
- Lead Auditor on ISO/IEC 27001 standard and other security related frameworks
Professional IT security related certifications is an added advantage