15 Sep
|
Openlm India
|
Kolkata
15 Sep
Openlm India
Kolkata
OpenLM India Pvt. Ltd. is looking for a Cyber Security Specialist to lead and manage information security, cybersecurity, risk, compliance, and related governance activities across the organization.
The ideal candidate will have hands-on experience with Information Security Management Systems (ISMS), IT security and compliance standards, risk management, vulnerability management, incident response, IT Asset Management (ITAM), Business Continuity Planning (BCP), and security documentation.
The role will also involve supporting and maintaining security certifications and compliance frameworks such as ISO 27001, SOC 2, and GDPR, while working closely with internal teams, customers, prospects, and global stakeholders.
Key Responsibilities
ISMS Management
- Design, implement, maintain, and continuously improve an effective Information Security Management System (ISMS) aligned with organizational requirements.
- Develop and manage information security policies, procedures, processes, controls, and supporting documentation.
- Ensure effective implementation and monitoring of security controls across relevant business and technology functions.
IT Asset & Risk Management
- Manage and maintain IT Asset Management (ITAM) processes and associated security controls.
- Identify, assess, document, and manage information security risks.
- Support risk mitigation activities and track remediation of identified security gaps.
- Contribute to effective Change Management processes from an information security perspective.
Cyber Security Assessment
- Conduct regular cybersecurity and security control assessments to identify potential threats, risks, and control weaknesses.
- Recommend and implement appropriate corrective and preventive measures.
- Monitor the effectiveness of security controls and drive continuous security improvement.
Threat & Vulnerability Management
- Proactively identify, assess, prioritize, and manage security threats and vulnerabilities.
- Coordinate remediation activities and follow up on identified vulnerabilities.
- Help minimize the potential business and technical impact of cybersecurity threats.
Privacy Assessment & Management
- Support privacy assessments and ongoing privacy management activities.
- Ensure information security and privacy practices align with applicable regulations, contractual requirements, and industry best practices.
- Assist in identifying and addressing privacy-related risks and compliance gaps.
Incident Response
- Document, manage, and track information security incidents.
- Support investigation, response, root-cause analysis, and remediation of security incidents.
- Implement and monitor corrective actions to address identified security gaps and prevent recurrence.
Documentation & Compliance
- Develop and maintain comprehensive documentation for IT security policies, procedures, standards, processes, and controls.
- Ensure security documentation remains accurate, current, and audit-ready.
- Support internal and external audits and compliance activities.
Customer & Prospect Security Questionnaires
- Complete customer and prospect security questionnaires accurately and within required timelines.
- Coordinate with relevant internal teams to gather technical, security, compliance, and operational information.
- Analyze customer security requirements and identify potential compliance or security improvement opportunities.
Security Compliance & Continuous Improvement
- Review customer, prospect, and regulatory security requirements.
- Identify opportunities to improve OpenLM's security posture and compliance with applicable standards.
- Support the implementation and continuous improvement of security controls, policies, and processes.
Security Certifications & Compliance Frameworks
- Prepare, coordinate, and guide the organization through maintaining relevant security certifications and compliance frameworks.
- Support activities related to ISO 27001, SOC 2, GDPR, and other applicable security and privacy standards.
- Maintain evidence, documentation, control records, and other requirements necessary for certification and compliance activities.
Required Qualifications & Experience
- Experience in cybersecurity, information security, IT security, security compliance, or a similar role.
- Strong understanding of key IT security and compliance standards/frameworks.
- Experience developing and maintaining process and security documentation.
- Solid understanding of networking, firewalls, and antivirus/security solutions.
- Experience with IT Asset Management (ITAM).
- Experience with Business Continuity Planning (BCP).
- Understanding of risk management, security assessments, and compliance processes.
- Strong analytical, documentation, communication, and coordination skills.
- Ability to work effectively with cross-functional and global teams.
Good to Have
- Knowledge of industry-standard security frameworks and best practices.
- Experience with ISO 27001, SOC 2, GDPR, or similar compliance frameworks.
- Experience in a similar cybersecurity/information security role within the technology or software industry.
- Exposure to vulnerability management, incident response, privacy management, and security audits.
What We Offer
- Competitive salary commensurate with experience.
- Robust performance and results are well rewarded.
- Ongoing professional development and training.
- Opportunities to work on exciting projects involving cutting-edge solutions.
- Exposure to global business leaders and technology pioneers.
- Challenging projects supporting professional and career growth.
- Opportunity to collaborate with global teams and clients.
Perks & Benefits
- Mandatory vacation policy.
- Flexible working hours.
- Opportunities to work with global business leaders and technology pioneers.
- Challenging projects that support professional and career growth.
- Collaboration with global teams and clients.
- No overtime policy.
- Employee referral rewards.
Ideal Candidate Profile
We are looking for a security professional who combines strong cybersecurity fundamentals with excellent documentation, compliance, risk management, and stakeholder-management skills. The candidate should be comfortable working across technical and business functions and should have a proactive approach toward improving the organization's overall security and compliance posture.
📌 Cyber Security Specialist- Immediate Joiner (Kolkata)
🏢 Openlm India
📍 Kolkata