Sr. Manager/Manager - Information Security (Goregaon)

Sr. Manager/Manager - Information Security (Goregaon)

22 Aug
|
BOBCARD
|
Goregaon

22 Aug

BOBCARD

Goregaon

Role & Responsibilities:

Key highlights of the role are listed below (purely indicative and not limiting):

This position would include the mentioned set of responsibilities but not limited to:

Third Party Risk Management (TPRM):

- Design, implement, and continuously improve the TPRM framework aligned with:
- ISO 27001
- NIST CSF / NIST 800-53
- SOC 2
- RBI / GDPR / industry regulations (as applicable)
- Conduct risk-based security due diligence assessments for:
- Vendors
- Partners
- Service providers
- Perform:
- Security questionnaires (Standardized Information Gathering - SIG/ Consensus

Assessment Initiative Questionnaire -CAIQ)
- Documentation reviews (policies, reports, certifications)
- Risk scoring and classification (critical/high/medium/low)
- Evaluate vendor controls across domains:
- Identity & Access Management
- Data Protection & Encryption
- Network Security
- Incident Response
- Business Continuity / DR
- Manage:
- Vendor onboarding security approvals
- Ongoing monitoring (continuous risk monitoring tools)
- Periodic reassessments and renewals
- Track and enforce risk remediation plans with vendors and business owner.
- Review vendor contracts for:
- Security clauses
- Data protection requirements
- Right-to-audit provisions
- Maintain third-party inventory and risk register

Cloud Security Review & Assurance:

- Perform security assessments of:
- SaaS platforms
- IaaS/PaaS environments (AWS, GCP)
- Evaluate cloud providers using frameworks:
- CSA CCM (Cloud Controls Matrix)




- CSA CAIQ (Consensus Assessment Initiative Questionnaire)
- CIS Benchmarks
- Review:
- Shared Responsibility Model implementation
- Multi-tenancy risks
- Data residency & sovereignty
- Encryption practices (at-rest, in-transit, key management)
- Assess cloud architecture for:
- Secure configurations
- Identity & access controls (IAM)
- Logging & monitoring
- Validate:
- Certifications (AWS Certified Security - Specialty, Google Cloud Certified

Qualified Cloud Security Engineer, ISO 27017, ISO 27018)
- Compliance posture
- Identify cloud-specific risks:
- Misconfigurations
- API vulnerabilities
- Shadow IT / unauthorized SaaS usage
- Provide risk recommendations and security approval for cloud onboarding

Governance, Risk & Compliance:

- Ensure alignment with internal policies, regulatory requirements, and risk appetite
- Generate dashboards and reports for:
- CISO
- Audit and Compliance teams
- Support internal and external audits (e.g., SOC 2, ISO audits)
- Develop TPRM and cloud security policies, standards, and procedures

Stakeholder Management:

- Collaborate with
- Procurement
- Legal
- IT / Cloud Engineering
- Business Units
- Act as a security advisor for vendor and cloud selection decisions
- Conduct awareness sessions on vendor and cloud risks

Continuous Monitoring & Threat Intelligence:

- Monitor third-party risks using tools (e.g., SecurityScorecard, BitSight)
- Track emerging risks related to:
- Supply chain attacks
- Cloud vulnerabilities
- Recommend mitigations and drive proactive risk reduction

📌 Sr. Manager/Manager - Information Security (Goregaon)
🏢 BOBCARD
📍 Goregaon

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: sr. manager/manager - information security (goregaon) / goregaon

Subscribe to this job alert:

Get the latest job offers by email for: sr. manager/manager - information security (goregaon) / goregaon