• Maintain
and continuously improve the organization's ISMS in alignment with
ISO/IEC 27001.
• Coordinate internal and external ISO audits, including audit preparation,
evidence collection, and closure of observations.
• Conduct information security risk assessments and maintain the risk
register and risk treatment plans.
• Develop,
review, and maintain information security policies, procedures,
standards, and guidelines.
• Coordinate
the implementation and monitoring of ISO 27001 Annex A controls.
• Maintain
ISMS documentation, control evidence, compliance records, and audit
trackers.
• Conduct
periodic user access reviews, asset reviews, and security compliance
checks.
• Support vendor/third-party security assessments and compliance reviews.
• Coordinate
information security incident reporting, investigation, corrective
actions, and documentation.
• Support Business Continuity and Disaster Recovery activities.
• Conduct
and coordinate employee information security awareness and training
programs, including phishing awareness, password security, social
engineering,
data protection, and acceptable-use practices.
• Monitor
compliance with organizational security policies and report deviations.
• Coordinate
with IT, HR, Operations, and other internal teams for
implementation of security controls.
• Track
corrective and preventive actions and ensure timely closure.
• Prepare ISMS reports, dashboards, compliance reports, and management review
inputs.
• Keep
updated with applicable information security standards, regulations, and
industry best practices.
Requirements
• 2–5
years of experience in ISMS / Information Security / IT GRC / IT
Compliance / Cybersecurity Governance.
• Robust
understanding of ISO 27001 and ISMS implementation.
• Knowledge
of ISO 27001 Annex A controls.
• Hands-on
experience in risk assessment and risk treatment.
• Experience
supporting ISO/internal/external audits.
• Good
understanding of:
• Information
Security Governance
📌 Information Security Executive (India)
🏢 InFynd
📍 India