26 Aug
|
Vinculum Solutions
|
Noida
26 Aug
Vinculum Solutions
Noida
Key Responsibilities
Information Security & Compliance
- Own and continuously improve the organization's information security program, policies, and standards (ISMS).
- Lead implementation and maintenance of compliance frameworks such as ISO 27001, SOC 2, GDPR, DPDPA and other applicable regulatory/customer requirements.
- Conduct and coordinate periodic risk assessments, internal audits, and gap analyses; track remediation to closure.
- Manage security incident response detection, investigation, containment, root-cause analysis, and post-incident reporting.
- Drive security awareness training and a culture of security across the organization.
- Prepare and present security posture, risk, and compliance reports to leadership and, where required, to customers/auditors.
Cloud Security (Area of Expertise)
- Define and enforce cloud security architecture, configuration standards, and best practices across cloud environments (AWS/Azure/GCP).
- Own cloud security controls including IAM, network security, data encryption, key management, logging/monitoring, and workload protection.
- Perform cloud configuration reviews and risk assessments; work with engineering teams to remediate misconfigurations and vulnerabilities.
- Evaluate and implement cloud security tooling (CSPM, CWPP, CASB, SIEM/SOAR) as needed.
- Ensure cloud deployments align with applicable compliance and data residency/privacy requirements.
Basic Cloud Knowledge (Supporting)
- Maintain a working understanding of core cloud infrastructure and services (compute, storage, networking)
sufficient to engage credibly with engineering/DevOps teams on architecture and deployment decisions.
- Collaborate with cloud/infrastructure teams to embed security requirements early in design and deployment (shift-left security).
Vendor & Third-Party Risk Management
- Own the vendor security risk management process due diligence, security questionnaires, and risk scoring for new and existing vendors/partners.
- Review vendor contracts and SLAs for security, data protection, and compliance clauses, in coordination with Legal/Procurement.
- Monitor ongoing vendor compliance through periodic reassessments, audits, and evidence collection.
- Act as the primary point of contact for security-related vendor escalations and remediation plans.
- Maintain a vendor risk register and report on third-party risk exposure to leadership.
Team & Stakeholder Management
- Partner with IT, Engineering, Legal, and business teams to align security initiatives with organizational goals.
- Represent Infosec in customer security reviews, RFPs, and due-diligence calls.
Required Skills & Qualifications
- 5–8 years of overall experience in Information Security, with demonstrated expertise in cloud security and compliance.
- Proven,
hands-on expertise in securing at least one major cloud platform (AWS, Azure, or GCP); working knowledge of others is a plus.
- Strong understanding of security frameworks and standards: ISO 27001, NIST, SOC 2, CIS Benchmarks, OWASP.
- Demonstrated experience managing vendor/third-party security risk, including questionnaires, audits, and contract reviews.
- Solid grasp of core infosec domains: network security, identity & access management, data protection, vulnerability management, and incident response.
- Experience leading or supporting external audits, certifications, and customer security assessments.
- Strong stakeholder management, communication, and report-writing skills — able to translate technical risk into business language for leadership.
- Prior experience managing or mentoring a team is preferred.
Preferred Certifications
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CCSP (Certified Cloud Security Professional)
- ISO 27001 Lead Auditor / Lead Implementer
- Cloud provider security certifications (e.g., AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer) — valuable to have
- CRISC (Certified in Risk and Information Systems Control) — good to have
Education
- Bachelor's degree in Computer Science, Information Technology, or a related field; relevant certifications and experience will be given strong consideration in lieu of a specific degree.
📌 Information Security (Infosec) Manager (Noida)
🏢 Vinculum Solutions
📍 Noida