Manager - Information Security (Noida)

Manager - Information Security (Noida)

16 Sep
|
DS Group
|
Noida

16 Sep

DS Group

Noida

Designation: MANAGER
Location: India UTTAR PRADESH Noida - A
Group: DS Group
Entity: Dharampal Satyapal Limited
SBU: CORPORATE
Department: INFORMATION TECHNOLOGY
Function: INFORMATION SECURITY

Job Description:

1. Information Security Governance & GRC

- Manage and continuously improve the organization's Information Security Governance, Risk and Compliance (GRC) framework.
- Develop, review and maintain information security policies, standards, procedures, guidelines and control frameworks.
- Conduct periodic Information Security Risk Assessments and maintain risk registers.
- Track remediation of identified security risks and ensure timely closure of risk treatment plans.
- Coordinate internal, external, customer and regulatory security audits.
- Prepare management reports, dashboards and security KPIs/KRIs for senior management.
- Drive compliance with applicable regulatory and contractual information security requirements.
- Support third-party/vendor security risk assessments and security due diligence.

2. ISO 27001:2022 / ISMS

- Own and manage day-to-day activities related to the ISO 27001:2022 ISMS.
- Ensure implementation and effectiveness of applicable ISO 27001:2022 controls.
- Maintain ISMS documentation, Statement of Applicability (SoA), risk treatment plans and supporting evidence.
- Coordinate internal audits, surveillance audits and certification audits.
- Manage audit observations, non-conformities, corrective actions and preventive actions.
- Conduct periodic ISMS reviews and support Management Review Meetings (MRM).
- Drive continual improvement of the organization's information security management system.

3. Data Loss Prevention (DLP)

- Manage and monitor the organization's DLP solution and data protection controls.
- Develop and fine-tune DLP policies based on business requirements and data classification.
- Monitor DLP incidents involving email, endpoints, web, cloud applications and removable media.




- Investigate potential data leakage incidents and coordinate remediation with relevant stakeholders.
- Reduce false positives while ensuring effective protection of sensitive and confidential information.
- Prepare DLP dashboards, incident reports and management metrics.

4. Endpoint Detection & Response (EDR)

- Manage and oversee EDR operations across endpoints and servers.
- Monitor endpoint security alerts and coordinate investigation and response.
- Ensure appropriate endpoint security policies, configurations and exclusions are implemented.
- Track malware, ransomware, suspicious activity and other endpoint security incidents.
- Coordinate with SOC/IT teams for containment, remediation and recovery.
- Monitor endpoint security posture and coverage across the organization.

5. Vulnerability Assessment & Penetration Testing (VAPT)

- Manage the organization's periodic Vulnerability Assessment and Penetration Testing (VAPT) program.
- Define VAPT scope covering applications, infrastructure, networks, APIs, cloud and external-facing assets.
- Review VAPT reports and validate the risk rating of identified vulnerabilities.
- Coordinate with application, infrastructure and business teams for remediation.
- Track vulnerability remediation against defined SLA timelines.
- Conduct periodic vulnerability closure validation and exception management.
- Maintain vulnerability dashboards and report security posture to management.

6. Security Operations & Incident Management

- Coordinate with the SOC for monitoring, detection, investigation and response to security incidents.
- Review security alerts and incident trends and ensure appropriate escalation.




- Participate in investigation and response to cybersecurity incidents.
- Support development and testing of Incident Response and Business Continuity processes.
- Conduct root-cause analysis and track corrective actions following significant incidents.
- Participate in security incident drills and tabletop exercises.

7. Security Awareness & Stakeholder Management

- Drive organization-wide information security awareness initiatives.
- Conduct security awareness sessions covering phishing, social engineering, password security, data protection and cyber hygiene.
- Work closely with IT, Infrastructure, Network, Application, HR, Legal, Privacy, Procurement and Business teams.
- Provide security requirements and guidance for new projects, applications, technologies and vendors.
- Promote a robust security-by-design and risk-based approach across the organization.

Key Deliverables / KPIs

- ISO 27001:2022 certification and continual compliance.
- Timely closure of internal/external audit observations.
- Reduction in critical and high-risk vulnerabilities.
- VAPT remediation within defined SLAs.
- DLP incident reduction and effective protection of sensitive data.
- EDR coverage and endpoint security posture.
- Timely closure of information security risks.
- Security incident response and resolution within defined SLAs.
- Vendor/third-party security assessment coverage.
- Information security awareness and training completion.
- Periodic cybersecurity dashboards and management reporting.

Education & Certifications

- Bachelor's degree in Computer Science, Information Technology, Cybersecurity or related discipline.

- 7–10 years of relevant Information Security / Cybersecurity experience.

Preferred Certifications:

- CISM / CISSP

- ISO 27001 Lead Implementer / Lead Auditor

- CEH / OSCP

- CRISC

- CompTIA Security+

- Other relevant cybersecurity certifications

Skills:

IT Audit

Vulnerability Assessment

ISO 27001

Security

Information Security

SOC

Risk Management

📌 Manager - Information Security (Noida)
🏢 DS Group
📍 Noida

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: manager - information security (noida) / noida

Subscribe to this job alert:

Get the latest job offers by email for: manager - information security (noida) / noida