19 Sep
|
Cashify
|
Gurugram
Manager-Information Security, Compliance & Data Protection- Gurgaon
ROLE OVERVIEW
Execution-focused governance role responsible for maintaining the organization's information security, privacy, and compliance posture across ISO 27001/27701, DPDPA, ITGC, third-party risk, and R2v3 requirements. The role owns documentation, audit readiness, and the timely closure of non-conformities, coordinates with internal and regulatory/government stakeholders, and supports contract/DPA reviews, awareness training, and ESG reporting.
KEY RESPONSIBILITY AREAS
- ISO 27001 / 27701 Documentation: Maintain the documentation, policies, procedures, processes, and records required for ISO 27001 and ISO 27701 compliance.
- Audits & NC Closure: Conduct internal audits, support external audits, identify gaps, and track and drive the timely closure of Non-Conformities (NCs), observations, and audit findings.
- Process & Control Documentation: Create, review, update, and monitor process documents, SOPs, policies, and control documentation, working with process owners to implement corrective actions.
- Regulatory & Government Coordination: Coordinate with relevant stakeholders to implement current requirements, including those arising from engagements with government and regulatory bodies such as the Department of Telecommunications
- Third-Party Risk Management: Manage third-party risk assessments and due diligence, including responding to questionnaires, coordinating evidence, and supporting third-party audits and site visits.
- R2v3 Responsible Recycling: Implement and maintain R2v3 (R2 Responsible Recycling Standard) requirements, including downstream due diligence, data sanitisation, secure data wiping,
and applicable environmental, factory, and operational controls.
- Evidence & Audit Readiness: Maintain audit-ready evidence and documentation across applicable compliance and operational requirements.
- Contract & DPA Review: Review contracts, Data Processing Agreements (DPAs), and other documents from an information security and privacy perspective, including redlining where required.
- Awareness & Training: Conduct information security and privacy awareness training for employees and relevant stakeholders.
- ESG Reporting: Prepare and maintain ESG-related metrics, policies, documentation, and reports in line with organisational requirements.
KEY PERFORMANCE INDICATORS
ISO 27001 / 27701 documentation kept current and audit-ready Timely closure of NCs, observations, and audit findings within SLA Third-party risk assessments and due diligence completed within agreed TATR2v3 downstream due diligence and data-sanitization compliance maintained Contract / DPA reviews turned around within SLA Information security and privacy awareness training coverage and completion ESG metrics and reports prepared accurately and submitted on time QUALIFICATIONS & EXPERIENCE
Education: B.E./B.Tech/B.Sc. in CS/IT/ECE (essential); M.Tech/MCA/MBA-IT/M.Sc. Cybersecurity (preferred). Relevant certifications such as ISO 27001 Lead Auditor / Lead Implementer, ISO 27701, CISA, or a recognised privacy / data-protection certification (preferred).
Experience: 5-6 years with at least 3-4 years in a hands-on InfoSec/compliance role and worked on third-party risk assessments. Exposure to R2v3 and ESG reporting is an advantage.
Should have been part of at least one full ISO 27001 certification cycle.
📌 Information Security Manager (Gurugram)
🏢 Cashify
📍 Gurugram