11 Sep
|
Yashraj Biotechnology
|
Mumbai
11 Sep
Yashraj Biotechnology
Mumbai
Role Overview
We are looking for an experienced ISMS Lead to drive end-to-end ISO 27001 implementation in a biotechnology setting, ensuring alignment with GxP, data integrity (ALCOA+), DPDP Act, IT Act 2003 etc. The role will be responsible not only for documentation and audit readiness but also for hands-on deployment of Annex A controls in coordination with the infrastructure, application team & business teams.
1. ISMS Implementation (ISO 27001 + DPDP Act + IT Act 2000 Alignment)
- Lead end-to-end ISMS deployment aligned with ISO 27001 standards
- Ensure alignment with DPDP Act, IT ACT 2000 and ALCOA+ principles
- Integrate ISMS controls QA systems
1. Annex A Controls Deployment (Hands-on)
- Possess strong practical knowledge of ISO 27001 Annex A controls
- Drive actual implementation of controls (not just documentation) across IT and business environments
- Work closely with businesses, business users, infrastructure, and application teams to:
i. Implement access controls, endpoint security, network security, logging & monitoring ii. Ensure backup, DR, patching, vulnerability management, and hardening practices iii. Validate effectiveness of controls through testing and periodic reviews
1. Policy, SOP & Documentation Framework
- Develop and maintain:
i. Information Security Policies ii. SOPs and Work Instructions iii. Templates, logs, and records
- Ensure documentation meets audit expectations
- Align with Quality Management System (QMS) documentation
1. Audit Readiness & Compliance
- Prepare for and manage ISO 27001 certification audits (Stage 1 & Stage 2)
- Support regulatory audits and inspections
- Ensure timely closure of audit observations and CAPAs
1. Data Integrity & Security Controls
- Ensure implementation of controls supporting:
i. ISO 27001 ISMS ii. ALCOA+ principles
- Audit trails, electronic records, and traceability
1. Evidence Management & Validation Support
- Collect and maintain ISMS evidences aligned with audits
- Support validation lifecycle documentation
- Ensure controls are documented, implemented, and auditable
1. Cross-functional Collaboration
- Liaise with:
i. QA/QMS teams for compliance alignment ii. HCD, QC, Production, R&D; teams for system-level controls iii. IT Infrastructure / Security team for technical implementation
1. Risk Management & Governance
i. Conduct risk assessments ii. Maintain risk register and mitigation plans iii. Establish governance dashboards and compliance tracking
1. Training & Awareness
i. Drive ISMS and cybersecurity awareness programs ii. Educate users on data integrity, phishing, and secure practices. iii. Build a culture of compliance and security ownership
📌 Executive ISMS- Digital Transformation (Mumbai)
🏢 Yashraj Biotechnology
📍 Mumbai