27 Aug
|
Happiest Resume
|
Bengaluru
27 Aug
Happiest Resume
Bengaluru
Job Description
ISMS Manager — Security Architecture & Compliance
Full-Time · Mid-Level Manager Grade Role Title ISMS Manager — Security Architecture & Compliance Grade Mid-Level Manager Department Cybersecurity Reporting To Director of Cybersecurity
Purpose of the Role
The ISMS Manager is a senior practitioner responsible for delivering end-to-end information security management across four core functions: security architecture reviews, ISO 27001 and SOC 2 compliance, presales security engagements, and post-sales RFI/RFP support. The role requires an individual review cloud architecture, managing audit cycles, briefing enterprise CISOs, and responding to client security questionnaires — operating with a high degree of independence and accountability.
Key Responsibilities
1. Security Architecture Review
● Conduct end-to-end security architecture reviews for product and platform offerings, covering application, API, cloud infrastructure, and data layers.
● Engage directly with engineering and product teams to embed security controls at the design stage — threat modelling, data flow validation, and trust boundary definition.
● Assess third-party integrations, vendor components, and current feature deployments for security risk prior to go-live.
● Maintain security architecture documentation including reference architecture, component-level controls mapping, and deviation/exception registers.
● Define and enforce secure SDLC practices in alignment with industry standards (OWASP, NIST, CIS).
2. Compliance — ISO 27001 & SOC 2 (BAU)
● Own the information security management system (ISMS) and drive ongoing compliance for ISO 27001 and SOC 2 Type II — from BAU control maintenance through audit readiness and recertification.
● Manage the full evidence lifecycle: control testing, artefact collection, gap remediation, and liaison with external auditors and certification bodies.
● Drive remediation of audit findings in coordination with engineering, infrastructure, and operations teams.
● Maintain the risk register, asset inventory, incident response plan, business continuity provisions, and vendor risk assessment programme in alignment with ISO 27001 Annex A.
● Track changes in applicable regulations and standards, updating the control framework accordingly.
3. Presales — Security Architecture Briefings
● Act as the security subject-matter expert during enterprise sales cycles — briefing CISOs, CIOs, and technical evaluators at prospective accounts on architecture, data residency, access controls, encryption, and compliance certifications.
● Develop and maintain standard presales security collateral: security overview decks, trust and compliance one-pagers, data processing summaries, and product security FAQs.
● Support sales and product teams in scoping security requirements during deal qualification, solution design, and contract negotiation stages.
● Represent the security function at client meetings and procurement panels as required.
4. Post-Sales Support — RFI / RFP Responses
● Own end-to-end completion of security RFIs and RFPs from enterprise clients, including those in regulated sectors (BFSI, healthcare, government).
● Produce accurate, technically detailed responses covering penetration testing, cloud security, VAPT findings and remediation status, data privacy compliance, and third-party risk management.
● Build and maintain a structured RFI/RFP response library, keeping answers current with the evolving controls landscape and certification status.
● Manage client security questionnaires (SIG, CSA CAIQ, and bespoke sector questionnaires) within agreed SLA commitments.
● Serve as the primary point of contact for post-sales security queries, escalations, and due diligence reviews from enterprise accounts.
Required Qualifications & Experience
Experience
● 8–12 years of progressive information security experience, with at least 3 years in a senior security management or advisory capacity.
● Demonstrated end-to-end ownership of ISO 27001 and SOC 2 compliance programmes — from implementation through sustained BAU and certification cycles.
● Hands-on background in security architecture review for SaaS or cloud-native platforms; familiarity with API security, microservices,
and multi-tenant architectures.
● Proven experience owning or significantly contributing to enterprise RFI/RFP security responses.
● Prior exposure to regulated industry sectors (BFSI, healthcare, or equivalent) — understanding of client security assessment dynamics and procurement-driven security requirements.
Technical Knowledge
● Cloud security across AWS / Azure / GCP — IAM, network controls, encryption, logging, and CSPM concepts.
● Application and API security — OWASP Top 10, authentication mechanisms (OAuth 2.0, SAML, OpenID Connect), and secure SDLC practices.
● Data protection and privacy — DPDPA, GDPR concepts, data classification frameworks, DLP controls.
● Vulnerability management lifecycle — VAPT coordination, CVSS scoring, remediation tracking, and risk acceptance.
● Governance frameworks — ISO 27001, SOC 2, NIST CSF, CIS Controls; ability to map controls across multiple frameworks.
Certifications
● CISSP or CISM — required.
● ISO 27001 Lead Auditor or Lead Implementer — strongly preferred.
● CCSP, AWS Security Specialty, or equivalent cloud security certification — preferred.
● CEH or equivalent offensive security certification — advantageous.
Key Competencies Competency What We're Looking For Executive Presence Comfortable briefing CISOs, CIOs, and procurement panels — structured, credible, and calm under scrutiny. Client Communication Translates complex security concepts into clear, commercially relevant language for both technical and non-technical audiences. Compliance Rigour Detail-oriented in executing audit evidence cycles, control testing, and documentation — not just high-level oversight. Cross-Functional Collaboration Effective at working across engineering, product, legal, and sales teams to drive security outcomes. Commercial Awareness Understands how security posture influences enterprise deal velocity and client retention in regulated sectors. Ownership Mindset Proactive in identifying and addressing risks — takes accountability for outcomes without needing to be prompted. Adaptability Capable of shifting between architecture review, compliance delivery, and client-facing engagements within the same week.
Confidential | For internal recruitment purposes only.
📌 ISMS Manager (Bengaluru)
🏢 Happiest Resume
📍 Bengaluru