Job opening: Senior Information Security Officer
Location:
GIFT CITY, Gandhinagar
Department:
Information Security / Quality & Compliance
Employment type:
Full-time
Experience:
Minimum 3 to 7 years in information security, IT governance, risk and compliance, with demonstrable ISO 27001 experience
Compensation:
No salary bar for the right candidate. Compensation will be structured to attract and retain proven expertise
About the Company The Innovation Family group is a multi-brand technology group operating across the Netherlands, India and the UAE. Our companies include NowOnline Media B.V. (web, hosting and the NOX headless CMS/BaaS platform), WYKYK B.V. (AI-driven offensive cybersecurity), GO-tickets (event ticketing), Referral Tool B.V. and GO Events. The group is ISO/IEC 27001 and ISO 9001 certified (DEKRA) and delivers engineering across AI/ML, Cybersecurity, .NET, Full Stack, QA, Mobile and Design disciplines.
Role Overview
We are looking for an experienced Senior Information Security Officer to own and drive information security compliance across the group. This person will be the internal authority on our security standards, policies and certifications, working across every engineering department (AI/ML, Cybersecurity, .NET, Full Stack, QA, Mobile and Design) to make sure everyone understands and follows the rules that keep the company ISO/IEC 27001 and ISO 9001 compliant. The ideal candidate combines deep technical security knowledge with the credibility and communication skills to enforce standards across diverse teams.
Key Responsibilities
Policy, Standards and Governance
- Own, maintain and continuously improve the Information Security Management System (ISMS) in line with ISO/IEC 27001, and support the Quality Management System aligned to ISO 9001.
- Translate ISO 27001 / ISO 9001 requirements into practical internal policies,
procedures and checklists that engineering teams can actually follow.
- Keep all security and quality documentation current, version-controlled and audit-ready.
- Track regulatory and legal developments (GDPR and other applicable data protection law) and update internal policy accordingly.
Compliance Monitoring and Audits
- Run internal audits and readiness checks across all departments (AI/ML, Cybersecurity, .NET, Full Stack, QA, Mobile, Design) to confirm adherence to company standards.
- Act as the primary point of contact for external certification audits (DEKRA) and coordinate evidence collection, corrective actions and follow-up.
- Maintain the risk register, run periodic risk assessments, and track remediation of findings to closure.
- Monitor compliance with access control, data handling, secure development and change management policies.
Awareness and Enforcement
- Deliver security and compliance training and onboarding sessions so every team member knows the standards relevant to their role.
- Work with department leads to embed secure practices into daily workflows without blocking delivery.
- Investigate policy breaches, security incidents and near-misses, and drive corrective and preventive actions.
- Report compliance status, risks and incidents to management with clear, actionable summaries.
Cross-Department Collaboration
- Partner with the WYKYK cybersecurity specialists on findings from AI Exposure Scan, AI Deep Scan, AI Pentest and Continuous Pentesting engagements, and ensure remediation is tracked through to closure.
- Review vendor, contractor and third-party arrangements for information security risk.
- Support secure software development lifecycle practices (OWASP-aligned) across .NET, Full Stack, Mobile and AI/ML teams.
- Coordinate with HR and IT on access provisioning, deprovisioning and physical/logical security controls.
Requirements
- Bachelor's or Master's degree in Information Security, Computer Science, IT or a related field.
- At least 3 to 7 years of experience in information security, IT compliance, risk management or a similar governance role.
- Hands-on experience implementing, maintaining or auditing an ISO/IEC 27001 ISMS is mandatory.
- Working knowledge of ISO 9001 quality management principles.
- Solid understanding of GDPR and data protection principles.
- Familiarity with common security domains: access control, incident response, vulnerability management, secure SDLC, cloud security (Azure preferred).
- Ability to communicate confidently with engineers, management and external auditors alike.
- Solid documentation, analytical and stakeholder management skills.
- Fluent in English; working knowledge of Dutch is an advantage.
Preferred Certifications
- ISO/IEC 27001 Lead Auditor or Lead Implementer
- CISA, CISM, CISSP or equivalent
- ISO 9001 Auditor certification (advantageous)
What We Offer
- No salary bar for the right candidate: compensation is structured around expertise, not a fixed band.
- A senior, high-visibility role with direct influence over group-wide security posture.
- Exposure to a diverse technology stack spanning AI/ML, Cybersecurity, .NET, Full Stack, QA, Mobile and Design.
- Work within an ISO 27001 and ISO 9001 certified, security-first organisation.
Interested candidates can share their CVs at
[email protected] or can connect on 76002 35007
📌 Information Security Officer (Gandhinagar)
🏢 NowOnline Tech India
📍 Gandhinagar