- Maintain and continuously improve the organization's ISMS in alignment with ISO/IEC 27001.
- Coordinate internal and external ISO audits, including audit preparation, evidence collection, and closure of observations.
- Conduct information security risk assessments and maintain the risk register and risk treatment plans.
- Develop, review, and maintain information security policies, procedures, standards, and guidelines.
- Coordinate the implementation and monitoring of ISO 27001 Annex A controls.
- Maintain ISMS documentation, control evidence, compliance records, and audit trackers.
- Conduct periodic user access reviews, asset reviews, and security compliance checks.
- Support vendor/third-party security assessments and compliance reviews.
- Coordinate information security incident reporting, investigation, corrective actions, and documentation.
- Support Business Continuity and Disaster Recovery activities.
- Conduct and coordinate employee information security awareness and training programs, including phishing awareness, password security, social engineering, data protection, and acceptable-use practices.
- Monitor compliance with organizational security policies and report deviations.
- Coordinate with IT, HR, Operations, and other internal teams for implementation of security controls.
- Track corrective and preventive actions and ensure timely closure.
- Prepare ISMS reports, dashboards, compliance reports, and management review inputs.
- Keep updated with applicable information security standards, regulations, and industry best practices.
Requirements
- 2–5 years of experience in ISMS / Information Security / IT GRC / IT Compliance / Cybersecurity Governance.
- Strong understanding of ISO 27001 and ISMS implementation.
- Knowledge of ISO 27001 Annex A controls.
- Hands-on experience in risk assessment and risk treatment.
- Experience supporting ISO/internal/external audits.
- Good understanding of:
- Information Security Governance
- Access Control
- Asset Management
- Incident Management
- Vendor Risk Management
- Business Continuity
- Data Protection & Privacy
- Security Awareness
- Robust documentation and report-writing skills.
- Good communication and stakeholder-management skills.
- Strong attention to detail and ability to manage compliance activities independently.
Benefits
- ISO 27001 Lead Implementer
- ISO 27001 Lead Auditor
- ISO 27001 Internal Auditor
- CISA
- CISM
- CRISC
📌 Information Security Executive (India)
🏢 InFynd
📍 India