07 Aug
|
PNG Jewellers
|
Pune
07 Aug
PNG Jewellers
Pune
Role & responsibilities
Design, implement, and maintain the enterprise Information Security Management System (ISMS) aligned with ISO 27001 standards, driving the organisation toward certification readiness.
Own the compliance roadmap across all applicable frameworks SEBI CSCRF, DPDP Act 2023, CERT-In incident reporting directives, ITGC/ICFR controls, and PCI DSS for payment environments.
Conduct periodic risk assessments, vulnerability analyses, and control gap evaluations across IT infrastructure, applications, and third-party integrations.
Coordinate and manage VAPT (Vulnerability Assessment & Penetration Testing) cycles across web, mobile, and API surfaces, tracking remediation to closure.
Develop and enforce IT security policies, access control frameworks, data classification standards, and incident response procedures.
Serve as the primary point of contact for internal auditors, statutory auditors, and regulatory bodies on all IT security and compliance matters.
Drive security awareness training programmes across the organisation to build a culture of compliance and vigilance.
Monitor and respond to security incidents, ensuring adherence to CERT-In reporting timelines and internal escalation protocols.
Maintain audit-ready documentation policy registers, control evidence,
risk treatment plans, and compliance dashboards for board and audit committee review.
Evaluate and manage third-party/vendor security risk, ensuring SLA and contractual compliance with data protection obligations.
Preferred candidate profile
Graduate in any discipline; a Master's degree in Information Security, IT, or Management will be preferred.
7+ years of experience in information security, IT risk management, or IT compliance preferably in a listed company, BFSI, or organised retail workplace.
CISA certification required; ISO 27001 Lead Auditor / Lead Implementer certification required. Additional certifications (CISSP, CRISC, CEH) are a strong advantage.
In-depth knowledge of Indian regulatory frameworks like SEBI CSCRF, DPDP Act, CERT-In directives, and ITGC/ICFR controls.
Hands-on experience with VAPT coordination, security audits, and remediation tracking.
Familiarity with PCI DSS compliance requirements for retail payment settings.
Robust documentation and reporting skills ability to present security posture and compliance status to board-level stakeholders.
Excellent stakeholder management skills across IT, business, legal, and external audit teams.
📌 Manager Security & Compliance Pune
🏢 PNG Jewellers
📍 Pune