22 Sep
|
Crypto Mize
|
India
Security Manager jobs in Delhi at CryptoMize are open on a rolling, always-hiring basis — full time, permanent, immediate joining, based at our New Delhi HQ inside the security practice that operates the S3-SENTINEL platform for government and sovereign clients across 18 countries. This is a hands-on management role: you own the security posture of live engagement infrastructure, the policies deployments run under, and the incident-response discipline behind a 15+ year zero-incident record. Below is the complete job description — the responsibilities you will own from day one, the requirements, the seniority path, and the selection process.
LOCATION New Delhi (HQ)
EMPLOYMENT Full-time · Permanent
AVAILABILITY Immediate · Rolling intake
COMPENSATION Discussed at screening
TRACKS ON THIS DESK25
CRAFT SKILLS NAMED12
TOOLS & SYSTEMS5
PATH STAGES4
01
01The actual work
What will you actually do as a Security Manager at CryptoMize?
01
Own security governance for a portfolio of client engagements — policies, procedures, and the audit trail that proves both are followed
02
Run the risk-assessment programme: threat modelling, control mapping against ISO 27001 and NIST CSF, and the residual-risk decisions leadership signs against
03
Lead incident response on your engagements — severity calls, escalation, forensics coordination, and the client communications that keep trust intact
04
Manage compliance workstreams for government and enterprise clients: audit preparation, evidence packages, and gap remediation with named owners and dates
05
Direct and develop the security analysts attached to your engagements, including the intern bench — the teaching culture is the promotion path
06
Report posture to client C-suites in plain language: what is protected, what is exposed, what it costs, and what you recommend — with the evidence behind every claim
ROLE RESPONSIBILITIES
As a Security Manager at CryptoMize you will own the security posture of live engagement infrastructure: the policies, the assessments, the monitoring, and the response. The role exists because our clients — governments, political entities, enterprises across 18 countries — do not accept security theatre; every control must be demonstrable, every exception must carry a named owner and an expiry date, and every incident review must produce a change.
The managerial weight of the role sits in judgment: which residual risks leadership must see, which findings cannot wait for the weekly review, and how an engagement absorbs a client mandate without diluting the baseline. You will run tabletop exercises your analysts complain about and later credit, and you will write the post-incident reports that read like engineering documents rather than apologies.
Institution-building is a standing duty: the security practice grows through its teaching culture, so mentoring the analyst bench and the intern programme is part of the role definition, not a favour. The managers whose benches produce strong analysts are the ones the practice promotes first.
02
02Capability profile
What skills and tools does a Security Manager need?
Craft skills12
Tools & systems5
Offer standards4
Security governance — policy architecture that survives audits and incidents alikeRisk management — quantitative judgment, control mapping, residual-risk ownershipIncident command — severity classification, escalation discipline, post-incident reviewDeep working knowledge of ISO 27001 and the NIST Cybersecurity FrameworkCompliance programme management — evidence pipelines, not scramble-and-hopeSIEM operations leadership — tuning, detection coverage, and knowing what the console hidesInfrastructure fluency — networks, Linux/Windows estates, cloud and air-gapped patternsTeam leadership and mentorship of analysts and internsExecutive communication — translating technical exposure into board-grade decisionsVendor and tooling judgment — build, buy, and when to trust neitherDiscretion at NDA and sovereign-client grade (non-negotiable)Calm under live-incident pressure, proven not claimed
SIEM platforms (Wazuh / Splunk-class) at operations-leadership levelISO 27001 & NIST CSF control cataloguesVulnerability management suites (OpenVAS / Tenable-class)Grafana for posture and metrics reportingIncident-response runbooks and tabletop facilitation
Depth of demonstrated skill in the specific role disciplineClassification and scope of the client engagement the role supportsUrgency and time-sensitivity of active project requirementsTrack record built across CryptoMize engagements
Also known as: security manager jobs · infosec manager vacancy · security lead · information security manager
03
03Seniority ladder
Security Manager — seniority path at CryptoMize
The security practice promotes by posture defended and incidents handled well, not tenure. The ladder below is how engagement security is actually organized.
- Security Manager
Owns governance, risk, and incident response for one to two engagement portfolios. The accountability layer between analysts and the practice lead.
1/4
- Senior Security Manager
Runs security for an entire client vertical, designs the compliance programmes others execute, and fronts the hardest client briefings.
2/4
- Security Practice Lead
Owns S3-SENTINEL operations end-to-end — staffing, standards, the zero-incident record, and final accountability for every posture claim CryptoMize makes.
3/4
- Chief Security Advisor
The crossover track: managers who graduate into sovereign-client counsel, shaping national-grade security architecture rather than one engagement at a time.
4/4
04
04The engagement surface
CryptoMize work a Security Manager touches
Every role plugs into live engagements across the five Penta-P domains — these are the services your work feeds.
Security Manager · Job Opening
This seat plugs into 6 live CryptoMize services across the five Penta-P domains — the work below is where yours lands.
6 SERVICESPENTA-P
- Information Security
- Security Consultancy
- Penetration Testing
- Vulnerability Assessment
- Infrastructure Security
- Security Training
WHAT DOES SECURITY MANAGER COMPENSATION DEPEND ON?
Compensation is discussed during screening — never a fixed public figure, because it varies per person and per engagement. It depends on:
#
OFFER CONSTRUCTION FACTOR
01
Depth of demonstrated skill in the specific role discipline
02
Classification and scope of the client engagement the role supports
03
Urgency and time-sensitivity of active project requirements
04
Track record built across CryptoMize engagements
📌 Security Manager (India)
🏢 Crypto Mize
📍 India