03 Sep
|
Promaynov Advisory Services
|
Mumbai
03 Sep
Promaynov Advisory Services
Mumbai
Role OverviewThe Manager – Information Security will be responsible for establishing and managing the organisation's information security framework. The role will own the
ISO 27001 certification lifecycle , drive security operations, manage information security risks, and lead internal and external audits.The ideal candidate should have strong experience in information security operations and compliance, with proven expertise in
ISO 27001 implementation and certification , security operations, cloud security, risk management, and audit management.
Key ResponsibilitiesISO Certification & ComplianceOwn the end-to-end
ISO 27001 ISMS implementation and certification lifecycle , from gap assessment through certification and ongoing surveillance.Coordinate with certification bodies and internal stakeholders to ensure continuous audit readiness.Track and close non-conformities and maintain audit documentation and corrective action plans.Ensure compliance with applicable regulations, including the
IT Act, DPDP Act, and CERT-In advisories .Security OperationsManage day-to-day information security operations, including threat monitoring, incident response, and vulnerability management.Administer security solutions including
SIEM, endpoint protection, WAF, IAM, and DLP .Define and enforce security baselines across cloud infrastructure and API environments.Embed security practices into the software development lifecycle in collaboration with engineering teams through
DevSecOps .Risk Management & GovernanceConduct periodic information security risk assessments and maintain an up-to-date risk register with mitigation plans.Develop, review, and maintain information security policies, standards, and procedures.Conduct security assessments of third-party vendors and external stakeholders.Report security metrics, risks, and overall security posture to senior leadership.Audit ManagementPlan and execute internal security audits across systems, processes, and integrations.Liaise with external auditors and regulatory bodies to facilitate smooth audit execution.Maintain comprehensive audit trails and evidence repositories for compliance purposes.Prepare management review inputs and support leadership reporting on information security posture.
Candidate Profile10–15 years of experience
in Information Security, with hands-on ownership of
ISO 27001 implementation and audit cycles .Proven experience in
security operations , including SOC management, incident response, and vulnerability management.Strong understanding of
cloud security
across AWS, GCP, or Azure.Strong understanding of
API security principles .Experience with information security governance, risk management, compliance, and audits.Relevant certifications such as
ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, CISSP, or CISM .Robust communication and stakeholder management skills, with the ability to engage effectively with both technical teams and senior leadership.
📌 Information Security (Mumbai)
🏢 Promaynov Advisory Services
📍 Mumbai