• Maintain and continuously improve the organization's ISMS in alignment with ISO/IEC 27001.
• Coordinate internal and external ISO audits, including audit preparation, evidence collection, and closure of observations.
• Conduct information security risk assessments and maintain the risk register and risk treatment plans.
• Develop, review, and maintain information security policies, procedures, standards, and guidelines.
• Coordinate the implementation and monitoring of ISO 27001 Annex A controls.
• Maintain ISMS documentation, control evidence, compliance records, and audit trackers.
• Conduct periodic user access reviews, asset reviews, and security compliance checks.
• Support vendor/third-party security assessments and compliance reviews.
• Coordinate information security incident reporting, investigation, corrective actions, and documentation.
• Support Business Continuity and Disaster Recovery activities.
• Conduct and coordinate employee information security awareness and training programs, including phishing awareness, password security, social engineering,
data protection, and acceptable-use practices.
• Monitor compliance with organizational security policies and report deviations.
• Coordinate with IT, HR, Operations, and other internal teams for implementation of security controls.
• Track corrective and preventive actions and ensure timely closure.
• Prepare ISMS reports, dashboards, compliance reports, and management review inputs.
• Keep updated with applicable information security standards, regulations, and industry best practices.
Requirements
• 2–5 years of experience in ISMS / Information Security / IT GRC / IT Compliance / Cybersecurity Governance.
• Strong understanding of ISO 27001 and ISMS implementation.
• Knowledge of ISO 27001 Annex A controls.
• Hands-on experience in risk assessment and risk treatment.
• Experience supporting ISO/internal/external audits.
• Positive understanding of:
• Information Security Governance
📌 Information Security Executive (India)
🏢 InFynd
📍 India