URGENT HIRING FOR ISMS Manager — Security Architecture & Compliance
Preferred immediate joiner
Email ID:
[email protected]
Contact: (phone hidden)
Location – Bangalore
JOB TITLE : Marketing Manager
Industry: Manufacturing
Experience: 7 - 9 years, at least 3 years in a senior security management or advisory capacity.
Salary: Upto 18 LPA
Purpose of the Role The ISMS Manager is a senior practitioner responsible for delivering end-to-end information security management across four core functions: security architecture reviews, ISO 27001 and SOC 2 compliance, presales security engagements, and post-sales RFI/RFP support. The role requires an individual reviewcloud architecture, managing audit cycles, briefing enterprise CISOs, and responding to client security questionnaires — operating with a high degree of independence and accountability.
Key Responsibilities
1. Security Architecture Review
● Conduct end-to-end security architecture reviews for product and platform offerings, covering application, API, cloud infrastructure, and data layers. ● Engage directly with engineering and product teams to embed security controls at the design stage — threat modelling, data flow validation, and trust boundary definition.
● Assess third-party integrations, vendor components, and recent feature deployments for security risk prior to go-live.
● Maintain security architecture documentation including reference architecture, component-level controls mapping, and deviation/exception registers.
● Define and enforce secure SDLC practices in alignment with industry standards (OWASP, NIST, CIS).
1. Compliance — ISO 27001 & SOC 2 (BAU)
● Own the information security management system (ISMS) and drive ongoing compliance for ISO 27001 and SOC 2 Type II — from BAU control maintenance through audit readiness and recertification. ● Manage the full evidence lifecycle: control testing, artefact collection, gap remediation, and liaison with external auditors and certification bodies.
● Drive remediation of audit findings in coordination with engineering, infrastructure, and operations teams.
● Maintain the risk register, asset inventory, incident response plan, business continuity provisions, and vendor risk assessment programme in alignment with ISO 27001 Annex A.
● Track changes in applicable regulations and standards, updating the control framework accordingly.
1. Presales — Security Architecture Briefings
● Act as the security subject-matter expert during enterprise sales cycles — briefing CISOs, CIOs, and technical evaluators at prospective accounts on architecture, data residency, access controls, encryption, and compliance certifications. ● Develop and maintain standard presales security collateral: security overview decks, trust and compliance one-pagers, data processing summaries, and product security FAQs.
● Support sales and product teams in scoping security requirements during deal qualification, solution design, and contract negotiation stages.
● Represent the security function at client meetings and procurement panels as required.
1. Post-Sales Support — RFI / RFP Responses
● Own end-to-end completion of security RFIs and RFPs from enterprise clients, including those in regulated sectors (BFSI, healthcare, government). ● Produce accurate, technically detailed responses covering penetration testing, cloud security, VAPT findings and remediation status, data privacy compliance, and third-party risk management.
● Build and maintain a structured RFI/RFP response library, keeping answers current with the evolving controls landscape and certification status.
● Manage client security questionnaires (SIG, CSA CAIQ,
and bespoke sector questionnaires) within agreed SLA commitments.
● Serve as the primary point of contact for post-sales security queries, escalations, and due diligence reviews from enterprise accounts.
Required Qualifications & Experience
Experience
● 8–12 years of progressive information security experience, with at least 3 years in a senior security management or advisory capacity.
● Demonstrated end-to-end ownership of ISO 27001 and SOC 2 compliance programmes — from implementation through sustained BAU and certification cycles.
● Hands-on background in security architecture review for SaaS or cloud-native platforms; familiarity with API security, microservices, and multi-tenant architectures.
● Proven experience owning or significantly contributing to enterprise RFI/RFP security responses.
● Prior exposure to regulated industry sectors (BFSI, healthcare, or equivalent) — understanding of client security assessment dynamics and procurement-driven security requirements.
Technical Knowledge
● Cloud security across AWS / Azure / GCP — IAM, network controls, encryption, logging, and CSPM concepts.
● Application and API security — OWASP Top 10, authentication mechanisms (OAuth 2.0, SAML, OpenID Connect), and secure SDLC practices.
● Data protection and privacy — DPDPA, GDPR concepts, data classification frameworks, DLP controls.
● Vulnerability management lifecycle — VAPT coordination, CVSS scoring, remediation tracking, and risk acceptance.
● Governance frameworks — ISO 27001, SOC 2, NIST CSF, CIS Controls; ability to map controls across multiple frameworks.
Certifications
● CISSP or CISM — required.
● ISO 27001 Lead Auditor or Lead Implementer — strongly preferred.
● CCSP, AWS Security Specialty, or equivalent cloud security certification — preferred.
● CEH or equivalent offensive security certification — advantageous.
Email ID:
[email protected]
Contact: (phone hidden)
📌 Security Solutions Architect (Bangalore Urban)
🏢 White Force Group
📍 Bangalore Urban