05 Sep
|
Promaynov Advisory Services
|
New Delhi
05 Sep
Promaynov Advisory Services
New Delhi
Job Description
Role Overview
n
The Manager – Information Security will be responsible for establishing and managing the organisation's information security framework. The role will own the ISO 27001 certification lifecycle , drive security operations, manage information security risks, and lead internal and external audits.
n
The ideal candidate should have strong experience in information security operations and compliance, with proven expertise in ISO 27001 implementation and certification , security operations, cloud security, risk management, and audit management.
n
n
Key Responsibilities
n
ISO Certification & Compliance
n
n
- Own the end-to-end ISO 27001 ISMS implementation and certification lifecycle , from gap assessment through certification and ongoing surveillance.
n
- Coordinate with certification bodies and internal stakeholders to ensure continuous audit readiness.
n
- Track and close non-conformities and maintain audit documentation and corrective action plans.
n
- Ensure compliance with applicable regulations, including the IT Act, DPDP Act, and CERT-In advisories .
n
n
Security Operations
n
n
- Manage day-to-day information security operations, including threat monitoring, incident response, and vulnerability management.
n
- Administer security solutions including SIEM, endpoint protection, WAF, IAM, and DLP .
n
- Define and enforce security baselines across cloud infrastructure and API environments.
n
- Embed security practices into the software development lifecycle in collaboration with engineering teams through DevSecOps .
n
n
Risk Management & Governance
n
n
- Conduct periodic information security risk assessments and maintain an up-to-date risk register with mitigation plans.
n
- Develop, review, and maintain information security policies, standards, and procedures.
n
- Conduct security assessments of third-party vendors and external stakeholders.
n
- Report security metrics, risks, and overall security posture to senior leadership.
n
n
Audit Management
n
n
- Plan and execute internal security audits across systems, processes, and integrations.
n
- Liaise with external auditors and regulatory bodies to facilitate smooth audit execution.
n
- Maintain comprehensive audit trails and evidence repositories for compliance purposes.
n
- Prepare management review inputs and support leadership reporting on information security posture.
n
n
n
Candidate Profile
n
n
- 10–15 years of experience in Information Security, with hands-on ownership of ISO 27001 implementation and audit cycles .
n
- Proven experience in security operations , including SOC management, incident response, and vulnerability management.
n
- Robust understanding of cloud security across AWS, GCP, or Azure.
n
- Strong understanding of API security principles .
n
- Experience with information security governance, risk management, compliance, and audits.
n
- Relevant certifications such as ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, CISSP, or CISM .
n
- Strong communication and stakeholder management skills, with the ability to engage effectively with both technical teams and senior leadership.
n
📌 Information Security (New Delhi)
🏢 Promaynov Advisory Services
📍 New Delhi