16 Sep
|
DS Group
|
Uttar Pradesh
16 Sep
DS Group
Uttar Pradesh
Designation: MANAGER
Location: India UTTAR PRADESH Noida - A
Group: DS Group
Entity: Dharampal Satyapal Limited
SBU: CORPORATE
Department: INFORMATION TECHNOLOGY
Function: INFORMATION SECURITY
Job Description:
1. Information Security Governance & GRC
- Manage and continuously improve the organization's Information Security Governance, Risk and Compliance (GRC) framework.
- Develop, review and maintain information security policies, standards, procedures, guidelines and control frameworks.
- Conduct periodic Information Security Risk Assessments and maintain risk registers.
- Track remediation of identified security risks and ensure timely closure of risk treatment plans.
- Coordinate internal, external, customer and regulatory security audits.
- Prepare management reports, dashboards and security KPIs/KRIs for senior management.
- Drive compliance with applicable regulatory and contractual information security requirements.
- Support third-party/vendor security risk assessments and security due diligence.
2. ISO 27001:2022 / ISMS
- Own and manage day-to-day activities related to the ISO 27001:2022 ISMS.
- Ensure implementation and effectiveness of applicable ISO 27001:2022 controls.
- Maintain ISMS documentation, Statement of Applicability (SoA), risk treatment plans and supporting evidence.
- Coordinate internal audits, surveillance audits and certification audits.
- Manage audit observations, non-conformities, corrective actions and preventive actions.
- Conduct periodic ISMS reviews and support Management Review Meetings (MRM).
- Drive continual improvement of the organization's information security management system.
3. Data Loss Prevention (DLP)
- Manage and monitor the organization's DLP solution and data protection controls.
- Develop and fine-tune DLP policies based on business requirements and data classification.
- Monitor DLP incidents involving email, endpoints, web, cloud applications and removable media.
- Investigate potential data leakage incidents and coordinate remediation with relevant stakeholders.
- Reduce false positives while ensuring effective protection of sensitive and confidential information.
- Prepare DLP dashboards, incident reports and management metrics.
4. Endpoint Detection & Response (EDR)
- Manage and oversee EDR operations across endpoints and servers.
- Monitor endpoint security alerts and coordinate investigation and response.
- Ensure appropriate endpoint security policies, configurations and exclusions are implemented.
- Track malware, ransomware, suspicious activity and other endpoint security incidents.
- Coordinate with SOC/IT teams for containment, remediation and recovery.
- Monitor endpoint security posture and coverage across the organization.
5. Vulnerability Assessment & Penetration Testing (VAPT)
- Manage the organization's periodic Vulnerability Assessment and Penetration Testing (VAPT) program.
- Define VAPT scope covering applications, infrastructure, networks, APIs, cloud and external-facing assets.
- Review VAPT reports and validate the risk rating of identified vulnerabilities.
- Coordinate with application, infrastructure and business teams for remediation.
- Track vulnerability remediation against defined SLA timelines.
- Conduct periodic vulnerability closure validation and exception management.
- Maintain vulnerability dashboards and report security posture to management.
6. Security Operations & Incident Management
- Coordinate with the SOC for monitoring, detection, investigation and response to security incidents.
- Review security alerts and incident trends and ensure appropriate escalation.
- Participate in investigation and response to cybersecurity incidents.
- Support development and testing of Incident Response and Business Continuity processes.
- Conduct root-cause analysis and track corrective actions following significant incidents.
- Participate in security incident drills and tabletop exercises.
7. Security Awareness & Stakeholder Management
- Drive organization-wide information security awareness initiatives.
- Conduct security awareness sessions covering phishing, social engineering, password security, data protection and cyber hygiene.
- Work closely with IT, Infrastructure, Network, Application, HR, Legal, Privacy, Procurement and Business teams.
- Provide security requirements and guidance for recent projects, applications, technologies and vendors.
- Promote a strong security-by-design and risk-based approach across the organization.
Key Deliverables / KPIs
- ISO 27001:2022 certification and continual compliance.
- Timely closure of internal/external audit observations.
- Reduction in critical and high-risk vulnerabilities.
- VAPT remediation within defined SLAs.
- DLP incident reduction and effective protection of sensitive data.
- EDR coverage and endpoint security posture.
- Timely closure of information security risks.
- Security incident response and resolution within defined SLAs.
- Vendor/third-party security assessment coverage.
- Information security awareness and training completion.
- Periodic cybersecurity dashboards and management reporting.
Education & Certifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity or related discipline.
- 7–10 years of relevant Information Security / Cybersecurity experience.
Preferred Certifications:
- CISM / CISSP
- ISO 27001 Lead Implementer / Lead Auditor
- CEH / OSCP
- CRISC
- CompTIA Security+
- Other relevant cybersecurity certifications
Skills:
IT Audit
Vulnerability Assessment
ISO 27001
Security
Information Security
SOC
Risk Management
📌 Manager - Information Security (Uttar Pradesh)
🏢 DS Group
📍 Uttar Pradesh