
Cuerate - Lead/Manager/Senior Manager - Information Security
3 weeks ago
Preferred Candidate : Big-4 client facing, large corporates/MNC's corporate IT
Position Summary:
The Information Security Lead will lead the enterprise security compliance agenda, ensuring full alignment with evolving regulatory frameworks such as ISO 27001, DPDP Act, CERT-IN, ITGC, and ISO/IEC 42001 (AI Governance).
This role is crucial in maintaining client trust, operational resilience, audit readiness, and risk posture across all firm systems, platforms, and third-party integrations.
Key Responsibilities:
- Implement ISO 27001 in all offices.
- Lead and maintain ISO 27001 certification, including ISMS policy enforcement, risk treatment plans, SoA, internal audits, and management reviews.
Implement and monitor compliance with:
- DPDP Act (India)
- CERT-IN Guidelines (incident response, remote access, logging, reporting)
- ITGC Controls (as part of statutory and internal audits)
- ISO/IEC 42001 - AI Governance framework and AI risk registers
- Build and maintain a firm-wide risk register for cyber, privacy, and technology controls.
- Define and review Information Security Policies, Data Classification, Encryption Standards, Third-party Risk, etc.
- Partner with Legal, Risk, and IT teams to map risk ownership and corrective action workflows.
- Own and manage all client security assessments, and due diligence questionnaires.
- Maintain a structured repository of pre-approved responses, certificates, and audit summaries.
- Engage with clients' cybersecurity teams and support InfoSec audits or certifications demanded during onboarding or renewals.
- Lead GRC and access controls review across all IT systems and applications.
- Lead cyber insurance renewals, manage exposure data, and maintain claim readiness documentation.
- Define and test the incident response plan and conduct periodic tabletop exercises with senior leadership and external advisors.
- Lead BCP for the firm, and ensure it's regularly tested.
- Ensure alignment with business continuity and disaster recovery strategies.
- Define quarterly and annual Vulnerability Assessment & Penetration Testing (VAPT) plan with top-tier CERT-IN certified vendors.
- Oversee closure of vulnerabilities and tracking of all red/amber findings.
- Coordinate with IT Infrastructure and App teams for secure configuration baselines (servers, endpoints, cloud).
Track global trends and legal obligations in:
- AI & Data Ethics (align to ISO/IEC 42001)
- Cloud Security (including contractual obligations with SaaS providers)
- Encryption & Logging requirements under CERT-IN
- Draft internal advisories and update control frameworks accordingly.
- Lead the firm's cybersecurity awareness and phishing simulation program.
- Conduct annual ISMS awareness campaigns and mandatory user certification programs.
- Build a security-conscious culture by regularly engaging with Practice Heads, Partners, and Business Services.
Key Deliverables:
- ISO 27001 maintained with zero non-conformities
- Full compliance with CERT-IN guidelines and DPDP readiness documentation
- Quarterly VAPT assessments with remediation closure tracking
- Quarterly internal reviews to maintain compliance
- 100% client audit response turnaround within defined SLA
- Annual cyber tabletop drill executed with report and improvements tracked
- Internal and external audits passed with minimal observations
- Cyber Insurance aligned to evolving risks and policy coverage verified
- Conduct quarterly reviews to maintain all the compliance
Certifications Required:
- ISO 27001 Lead Implementer / Auditor
- CISSP / CISM
- DPDP Act / Privacy Certifications
- ISO/IEC 42001 (AI Governance Awareness) - Preferred
- ITIL v4 - Preferred
Education: B.E/B.Tech/M.Tech/Master in computer science
Leadership & Behavioral Competencies:
- Highly structured, audit-ready, and documentation-oriented
- Strong stakeholder engagement with Partners, Clients, cross functional teams, and Auditors
- Proactive risk identifier with a strong grasp of Indian and global compliance regimes
- Calm under pressure with strong incident response instincts
- Strategic mindset with tactical attention to operational control and reporting
-
Information Security Risk Lead
4 weeks ago
Delhi, Delhi, India Tide Full timeJob DescriptionJob descriptionAbout The Role- You'll be an information security expert, with a great eye for information security risk reduction and continual improvement opportunities. If fast-paced environments, cross-team exposure, inquisitive freedom and the ability to have a real impact on a rapidly growing scale-up appeals to you, then you already have...
-
Information Security Architect
2 days ago
Delhi, Delhi, India beBeeInformationSecurity Full time ₹ 9,00,000 - ₹ 12,00,000Job DescriptionWe are seeking an experienced Information Security Architect to design and implement our organization's information security program.The ideal candidate will have a strong background in security governance, risk management, and compliance, with proven expertise in security strategy development and execution.Key Responsibilities:Develop and...
-
Information Security Leader
7 hours ago
Delhi, Delhi, India beBeeCybersecurity Full time ₹ 12,00,000 - ₹ 15,40,000Information Security Leadership RoleWe are seeking a highly skilled Information Security leader to join our organization. The successful candidate will be responsible for designing, implementing, and managing the organization's information security program.This role requires a strategic and technical professional with proven expertise in security governance,...
-
Lead - It Security
4 weeks ago
Delhi, Delhi, India SAEL Full timeJob Summary: We are seeking an experienced and highly skilled IT Security Lead to spearhead our cybersecurity initiatives, with a primary focus on managing and optimizing our Sophos perimeter security and Trend Micro endpoint and email security platforms, while also ensuring the continuous adherence to and improvement of our ISO 27001 Information Security...
-
Information Security Investigator
3 days ago
Delhi, Delhi, India beBeeSecurity Full time ₹ 8,00,000 - ₹ 12,00,000Junior SOC Security Analyst Job DescriptionWe are seeking a skilled SOC Security Analyst to join our team in this critical role.Conduct security investigations due to security incidents identified from various entry channels (SIEM, Tickets, Email and Phone).Our ideal candidate will have:Experience with Seceon Tool.Ability to act as a point of escalation in...
-
Senior Security Operations Manager
4 days ago
Delhi, Delhi, India beBeeSecurity Full time ₹ 9,00,000 - ₹ 12,00,000Job Title: Senior Security Managed Services EngineerThe ideal candidate for this role will have a solid understanding of security infrastructure and managed services. They will be responsible for providing proactive monitoring, identifying, investigating, and resolving technical incidents and problems to restore service to clients.This is a developing...
-
Delhi, Delhi, India Talent Worx Full time ₹ 15,00,000 - ₹ 20,00,000 per yearWe are seeking an accomplished SAP GRC (Governance, Risk, and Compliance) Security Manager/Director to oversee and strengthen our SAP security protocols. In this senior role, you will be responsible for the implementation and management of SAP security measures, ensuring compliance with regulatory standards while safeguarding the integrity of SAP...
-
Information Security Specialist
2 days ago
Delhi, Delhi, India beBeeAuditor Full time ₹ 15,00,000 - ₹ 25,00,000ISO 27001 Auditor Job DescriptionWe are seeking a qualified professional to assess, monitor and improve our Information Security Management System (ISMS) in accordance with the ISO/IEC 27001 standard.Main Responsibilities:Plan, conduct and report on internal audits of the ISMS as per ISO/IEC 27001 requirements.Identify non-conformities, risks and improvement...
-
Information Security Analyst
3 weeks ago
Delhi, Delhi, India Talent Integrators Full timeThis role is pivotal in developing, implementing, and monitoring security policies, ensuring compliance, and managing risk across the firm. The ideal candidate will have expertise in Governance, Risk, and Compliance (GRC) and will play a key role in tracking vulnerabilities, managing security alerts, and overseeing learning modules.Responsibilities and...
-
Security Engineer
4 weeks ago
Delhi, Delhi, India TAC Security Full timeJob descriptionAs a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and...