Information Security Manager (India)

Information Security Manager (India)

15 Sep
|
Focaloid Technologies
|
India

15 Sep

Focaloid Technologies

India

About the Role

We are looking for a hands-on and execution-oriented Information Security Manager to take end-to-end ownership of the organization's ISO/IEC 27001:2022 Information Security Management System (ISMS) while strengthening the organization's technical security, customer security assurance, Secure SDLC, and AI security practices.

This is not a purely compliance or documentation-focused role. The successful candidate will be responsible for ensuring that information security controls are continuously implemented, monitored, measured, evidenced, and improved throughout the year.

The ideal candidate should be comfortable operating across GRC and technical security, independently driving security initiatives, managing audits and remediation, responding to customer security requirements, and translating security requirements into practical controls.

Key Responsibilities

1. ISMS & ISO 27001 Operations – 40%

- Own and continuously operate the ISO/IEC 27001:2022 ISMS.
- Manage policies, procedures, registers, risk assessments, SoA, and compliance obligations.
- Drive risk identification, treatment, monitoring, escalation, and closure.
- Define and track ISMS objectives, KPIs, corrective actions, and continuous improvement.
- Coordinate Management Reviews, internal audits, surveillance/recertification audits, and audit readiness.
- Drive security awareness, training, onboarding awareness, and phishing simulations.

2. Hands-on Technical Security – 25%

- Manage VAPT, vulnerability scanning, remediation, and retesting.
- Review security configurations across Microsoft 365, Entra ID, AWS/Azure, and access controls.
- Drive least privilege, patch compliance, and periodic access reviews.
- Coordinate security incident triage, containment, RCA, corrective actions, and escalation.
- Support CERT-In reporting, security monitoring, threat intelligence, and control improvements.

3. Customer Security Assurance & Third-Party Risk – 20%

- Own customer security questionnaires, assessments, due diligence, and audits.
- Conduct vendor and third-party security risk assessments.
- Review security requirements in NDAs, contracts, DPAs, and outsourcing arrangements.
- Support Sales/AM teams in customer security discussions and pre-sales engagements.
- Maintain security evidence, certification information, and a reusable security questionnaire/evidence library.

4.



Secure SDLC & AI Security – 15%

- Drive Secure SDLC, secure coding, and application security practices.
- Support SAST, SCA, secret scanning, vulnerability management, and CI/CD security controls.
- Partner with engineering teams on security findings, project risks, architecture, and access reviews.
- Assess AI/LLM security risks, including prompt injection, data disclosure, excessive privileges, insecure outputs, and unauthorized access.
- Promote recognized AI and application security best practices

Mandatory Qualifications & Experience

- 5–8+ years of relevant experience in Information Security, Cybersecurity, GRC, ISMS, or a closely related domain.
- Robust hands-on experience in ISO/IEC 27001:2022 implementation and ISMS operations.
- Practical experience managing information security risk registers, risk assessments and treatment plans, Statement of Applicability (SoA), internal audits, management reviews, corrective actions, and audit readiness.
- Strong practical understanding of information security controls and their implementation within an organization.
- Experience in VAPT, vulnerability management, remediation tracking, and security findings management.
- Working knowledge of Microsoft 365 and Microsoft Entra ID security.
- Good understanding of cloud security across AWS and/or Azure.
- Experience coordinating information security incidents and response activities.
- Experience in responding to customer security questionnaires, assessments, and security due diligence requests.
- Good understanding of vendor and third-party security risk assessments.
- Understanding of Secure SDLC and application security practices.
- Exposure to SAST, SCA, secret scanning, CI/CD security controls, or similar application security practices.
- Awareness of emerging AI/LLM security risks.
- Robust documentation, analytical, communication, stakeholder-management, and problem-solving skills.

Good to Have





- CISSP / CISM / ISO 27001 Lead Implementer / ISO 27001 Lead Auditor or equivalent certification.
- Experience working in an IT services, software development, product engineering, or technology consulting organization.
- Experience supporting enterprise customers during security audits and due-diligence exercises.
- Knowledge of CERT-In and Indian information security compliance requirements.
- Knowledge of security frameworks such as CIS Controls, NIST CSF, OWASP, and OWASP ASVS / Top 10.
- Exposure to cloud security posture management and identity/security tools.
- Experience with AI Security, GenAI Security, or LLM application security assessments.
- Experience with enterprise security platforms, vulnerability management tools, SIEM, or security monitoring solutions.
- What We Are Looking For
- Hands-on and execution-oriented, rather than purely documentation-focused.
- Comfortable working across both GRC and technical security.
- Capable of independently driving security actions with IT, Engineering, Cloud, and Business teams.
- Confident interacting directly with enterprise customers and external auditors.
- Comfortable managing audits, evidence, remediation, risks, and deadlines throughout the year.
- Able to translate security and compliance requirements into practical and measurable controls.
- Strong in stakeholder management and cross-functional collaboration.
- Analytical, structured, detail-oriented, and capable of identifying security gaps proactively.
- Curious about emerging security risks, particularly cloud, applications, and AI security.
- Comfortable taking ownership rather than waiting for instructions.
- Why Join Us?
- This is an opportunity to take end-to-end ownership of an established ISO/IEC 27001:2022 ISMS and play a key role in strengthening the organization’s overall information security maturity.
- The role provides exposure across ISMS, GRC, technical security, cloud security, application security, customer assurance, third-party risk, Secure SDLC, and emerging AI security, making it an ideal opportunity for a security professional looking to build a broad and impactful information security profile.
- If you enjoy turning security requirements into real-world controls, driving continuous improvement, and working closely with both technology and business teams, this role offers significant ownership and visibility.

📌 Information Security Manager (India)
🏢 Focaloid Technologies
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: information security manager (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: information security manager (india) / india