- Develop, implement and maintain information security policies, procedures and controls.
- Lead compliance efforts for standards such as ISO 27001 and SOC 2, and data protection laws such as India's DPDP Act and GDPR for international clients.
- Conduct regular risk assessments, security audits and gap analyses, and drive remediation.
- Manage access controls, user permissions and security reviews across company systems and tools.
- Handle client security questionnaires, vendor assessments and audit requests.
- Monitor for security incidents, lead incident response, and maintain incident records.
- Run security awareness training for employees.
- Work with engineering and DevOps teams to build security into products, cloud infrastructure and development processes.
What we're looking for
- 3 to 4 years of experience in information security, IT compliance or governance, risk and compliance (GRC).
- Hands-on experience with ISO 27001 implementation or audits; SOC 2 exposure is a plus.
- Understanding of data protection regulations, including India's DPDP Act and GDPR.
- Working knowledge of cloud security (AWS, Azure or GCP), access management and network security basics.
- Experience preparing security documentation, policies and audit evidence.
- Solid attention to detail, with the ability to explain security requirements clearly to non-technical teams.
Good to have
- Certifications such as ISO 27001 Lead Implementer or Lead Auditor, CISA, CISM, CompTIA Security+ or CEH.
- Experience in an IT services or product company.
- Exposure to IoT or industrial system security.
Job details
- Experience: 3 to 4 years
- Location: Jaipur (Hybrid). Candidates based in Jaipur are preferred.
- Working hours: 10:00 AM to 7:00 PM
📌 Information Security & Compliance Officer ( Jaipur | Hybrid | 3+ YOE ) (India)
🏢 Perimattic
📍 India
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.