08 Oct
|
The Glove
|
India
Key Responsibilities
• Lead implementation and maintenance of ISO 27001:2022 compliance across the organization.
• Manage compliance for SOC 2 Type 2, SOX, and upcoming frameworks like GDPR, DPDPA, PCI DSS, and ISO 27701:2019.
• Coordinate with external auditors and manage end-to-end audit processes.
• Develop, review, and enforce information security policies, standards, and procedures.
• Manage and optimize security tools such as:
CrowdStrike EDR
SIEM systems
PAM and DAM solutions
Firewalls and network security devices
• Ensure security and integrity of Active Directory (AD).
• Oversee patch management to ensure timely updates and vulnerability remediation.
• Conduct regular risk assessments and vulnerability analyses.
• Identify security risks and implement mitigation strategies.
• Monitor compliance with security policies and highlight non-compliance issues.
• Work closely with IT, legal, and business teams to align security objectives.
• Conduct employee training and awareness programs on security and compliance.
• Stay updated on emerging threats and regulatory changes.
• Prepare reports on compliance status, risk assessments, and incidents.
• Maintain documentation for audits, policies, and compliance activities.
Qualifications & Experience
• Bachelors degree in Computer Science, Information Security, or a related field.
• 2–5 years of experience in information security compliance and risk management.
• Hands-on experience with ISO 27001:2022 implementation (mandatory).
• Exposure to SOC 2, SOX, GDPR, DPDPA, PCI DSS, ISO 27701 preferred.
• CISSP / CISA / CISM
• ISO 27001 Lead Implementer or Lead Auditor
• Experience with security tools:
EDR, SIEM, PAM, DAM
Firewalls and network security
Active Directory security
Patch management systems
• Solid understanding of:
IT infrastructure & networking
Application security
Regulatory compliance standards
• Excellent communication and interpersonal skills
• Solid leaders
📌 Am Compliance Mumbai (India)
🏢 The Glove
📍 India