23 Aug
|
Godrej Infotech
|
India
23 Aug
Godrej Infotech
India
About the Business & Position OverviewJob ProfileKey Responsibilities
- Implement security controls, risk assessment framework, and program that align to best practices and regulatory requirements.
- Assist with implementation of ISMS across the organisation entities.
- Good understanding of the security technologies such as DLP, NGAV, EDR, CASB, PIM/PAM, Firewall, Proxy, Email ATP, WAF etc.
- Well versed with well-known security frameworks such as ISO 27001:2022 / NIST CSF / PCI DSS / ISO 22301 / STRIDE / MITRE etc.
- Ensure key information security risks and issues are identified, addressed and resolved in a timely manner.
- Assess efficacy of security controls, document and report control failures and gaps to stakeholders. Provide remediation guidance and prepare management reports to track remediation activities.
- Ensure third party security assessments - Assist with Third Party Risk Management framework including policy updates, procedures, due diligence questionnaires and the monitoring of third parties' adherence to information security and data privacy obligations.
- Develop relevant metrics, analyse data, identify trends and help drive improvements to the control environment.
- Remains current on best practices and technological advancements.
- Drive security awareness program across the organisation.
- Lead Information Security Governance, Risk, and Compliance activities.
- Implement and maintain ISMS, policies, standards, and procedures.
- Conduct risk assessments, control reviews, and compliance audits.
- Manage third-party security reviews and due diligence assessments.
- Monitor security risks, compliance status, and remediation plans.
- Collaborate with technology teams on security controls and best practices.
- Drive security awareness programs and continuous improvement initiatives.
- Provide regular security reporting to management and stakeholders.
Qualification DetailsEssential Qualification
- Graduate in IT, Computer Science, Cyber Security, or related discipline.
- ISO 27001 Lead Auditor/Lead Implementer certification preferred.
- Professional certifications such as CISSP, CISM, CISA, CCSP, or CRISC (minimum two preferred).
- Strong knowledge of security frameworks including ISO 27001:2022, NIST CSF, PCI DSS, and ISO 22301.
Preferred Qualification
- Same as above.
Experience DetailsEssential Experience
- 8-10 years of experience in Information Security, Risk, Compliance, or Audit.
- Minimum 4-5 years of dedicated GRC experience.
- Hands-on experience managing ISMS in an ISO 27001-certified environment.
- Experience conducting risk assessments, audits, and compliance reviews.
- Exposure to Third-Party Risk Management (TPRM) and vendor assessments.
- Experience in policy development, governance reporting, and stakeholder management.
Preferred Experience
- Same as above.
Special SkillEssential
- Strong understanding of security technologies such as DLP, EDR, NGAV, CASB, PAM/PIM, Firewalls, WAF, Email Security, Proxy, and Cloud Security.
- Expertise in risk management, compliance assessment, and security governance.
- Strong analytical, problem-solving, and reporting skills.
- Excellent communication, stakeholder management, and presentation abilities.
- Ability to translate technical security requirements into business-focused recommendations.
- Self-motivated, proactive, and capable of working in a fast-paced workplace.
Preferred
- Same as above.
Locations
- Mumbai
📌 GRC Manager (India)
🏢 Godrej Infotech
📍 India