03 Oct
|
DS Group
|
Noida
Information Security Governance & GRC
Manage and continuously improve the organization's Information Security Governance, Risk and Compliance (GRC) framework.
Develop, review and maintain information security policies, standards, procedures, guidelines and control frameworks.
Conduct periodic Information Security Risk Assessments and maintain risk registers.
Track remediation of identified security risks and ensure timely closure of risk treatment plans.
Coordinate internal, external, customer and regulatory security audits.
Prepare management reports, dashboards and security KPIs/KRIs for senior management.
Drive compliance with applicable regulatory and contractual information security requirements.
Support third-party/vendor security risk assessments and security due diligence.
ISO 27001:2022 / ISMS
Own and manage day-to-day activities related to the ISO 27001:2022 ISMS.
Ensure implementation and effectiveness of applicable ISO 27001:2022 controls.
Maintain ISMS documentation, Statement of Applicability (SoA),
risk treatment plans and supporting evidence.
Coordinate internal audits, surveillance audits and certification audits.
Manage audit observations, non-conformities, corrective actions and preventive actions.
Conduct periodic ISMS reviews and support Management Review Meetings (MRM).
Drive continual improvement of the organization's information security management system.
Data Loss Prevention (DLP)
Manage and monitor the organization's DLP solution and data protection controls.
Develop and fine-tune DLP policies based on business requirements and data classification.
Monitor DLP incidents involving email, endpoints, web, cloud applications and removable media.
Investigate potential data leakage incidents and coordinate remediation with relevant stakeholders.
Reduce false positives while ensuring effective protection of sensitive and confidential information.
Prepare DLP dashboards, incident reports and man
📌 Manager Information Security Noida
🏢 DS Group
📍 Noida