
Information Security Manager
1 day ago
Job Description :
Company : Glan Management Consultancy
Location : Gurgaon
Experience : 7-15 year
Employment Type :
Job Description :
Job Title : Manager Information Security - IT
Job Purpose :
Acting in a key technical management & execution capacity to provide a conduit between IT teams and key business stakeholders in your functional area of IT Security to ensure information technology needs are managed consistently, following professional IT and global standards, and delivered with a high level of quality and customer satisfaction.
Reward level : Middle Management
Job Location : Gurgaon
Experience : 10+ years
Relevant Experience : 7+ years
Reporting to : General Manager
Qualification : Bachelor degree in IT
Key Deliverables :
- Provide support as Lead auditor towards ISMS and PIMS policies, procedures, and guidelines and perform regular review and update.
- Perform deep assessment to gather evidence of continuous compliance with ISO 27001 : 2022 and ISO 27701 : 2019, DPDPA, IT Act and Cert In Regulation including audit logs, records of reviews, timely closure of open audit and risks and sharing the report with management.
- Prioritize identified vulnerabilities, detailed findings, remediation recommendations, trending reports on vulnerability posture towards closure with stakeholders.
- Development and implementation of a comprehensive, ongoing security awareness and training program for all employees.
- Encourage secure behaviours among colleagues and reinforce the importance of information security and privacy in daily operations.
- Prepare regular report on overall information security posture, GRC maturity, and risk landscape to relevant stakeholders
- Ability to collect lessons learned from incidents, audits, and assessments to drive continuous improvement in ISMS/PIMS and security processes.
Key Relationships :
- Internal IT and business customers.
- Global IT Vendor, market and global (HQ) colleagues, Local vendor partners
- Internal staff - direct reports (where applicable)
- IT vendors, contractors (where applicable)
Knowledge Skills and Abilities :
- Must possess and demonstrate ISO 27001 Lead Implementer/Auditor and ISO 27701 Lead Implementer/Auditor certifications and knowledge.
- In depth understanding of IT Act, DPDPA, Cert In regulations, CIS Controls as well as UK DPA and ISO 31000
- Good to have certification on CISM (Certified Information Security Manager), CISSP (Certified Information Systems Security Professional) and Cloud Security certifications (e.g., CCSK, CCSP, vendor-specific like AWS Security Specialty)
- Familiarity with common vulnerability scanning tools like Qualys (features, reporting, agent-based vs. network scans) and Cloud Security Posture Management (CSPM) tools like Wiz (cloud service provider configurations, misconfigurations, compliance checks in AWS, Azure, GCP).
- Understanding of various penetration testing types (e.g., network, web application, API, mobile, cloud) and methodologies
- Knowledge of common attack vectors and exploitation techniques like MITRE ATTACK and DEFEND framework.
- Basic to intermediate knowledge of common security controls and technologies (e.g., firewalls, EDR, Cloud Security, VAPT tools, SIEM, WAF, DLP, encryption).
- Understanding of network protocols, operating systems (Windows, Linux), and common application architectures.
- Knowledge of audit principles and practices (internal and external audits).
- Understanding of corrective action planning and non-conformity management.
- Understanding of third-party risk management principles and vendor due diligence processes.
- Excellent technical writing skills for creating clear, concise, and comprehensive security policies, standards, and procedures.
- Ability to analyse complex risk data and present actionable insights.
- Hands-on experience with Qualys for configuring scans, analysing reports, and managing vulnerabilities.
- Hands-on experience with Wiz CSPM for monitoring cloud environments, identifying misconfigurations, and generating compliance reports.
- Proficiency with GRC platforms or tools for managing policies, risks, and controls
- Exceptional verbal and written communication skills to articulate complex security concepts to technical and non-technical stakeholders
- Ability to build strong relationships and collaborate effectively with diverse teams (IT, Legal, HR, Development, Business Units).
- Skills in influencing behaviour and driving change across the organization to improve security posture.
- Strong analytical skills to diagnose security issues, identify root causes, and develop effective solutions.
- Ability to critically evaluate security controls and identify gaps.
- Contract review and negotiation skills specifically for security-related services.
- Ability to effectively manage vendor relationships and performance.
- Ability to develop and deliver engaging security training sessions and awareness campaigns.
- Ability to stay updated with the latest security threats, vulnerabilities, technologies, and regulatory changes.
- Capacity to quickly learn and adapt to new tools and methodologies.
- Meticulous attention to detail in policy creation, audit documentation, and vulnerability analysis.
- Ability to act calmly and effectively during security incidents and contribute to incident response efforts.
Key Skill :
information security manager, IT security, ISO 27001 LA, ISO 27001 LI, ISO 27001 LI/LA, ISO 27701, ISO 31000, internal auditor, DPDPA, CISM, compliance ISO 27001 : 2022
Job Type : Full-time
-
Information Security Manager
5 days ago
Gurgaon, Haryana, India ONE Full time ₹ 15,00,000 - ₹ 20,00,000 per yearJob summary:As Information Security Manager at / , you will serve as a critical link between global security functions and local business units, ensuring seamless adoption of group-provided security services while driving stakeholder alignment. This role requires an outgoing professional with exceptional coordination skills, a deep understanding of Indian...
-
Information Security Manager
7 days ago
Gurgaon, Haryana, India Glan Management Consultancy Full timeJob Title : Manager Information Security ITJob Purpose : Acting in a key technical management & execution capacity to provide a conduit between IT teams and key business stakeholders in your functional area of IT Security to ensure information technology needs are managed consistently, following professional IT and global standards, and delivered with a...
-
Information Security Manager
3 days ago
Gurgaon, Haryana, India glan management consultancy Full time ₹ 16,25,000 - ₹ 30,15,133 per yearCompany: Glan Management ConsultancyLocation: GurgaonExperience: 7-15 yearSalary:Employment Type:Job Description:Job Title: Manager Information Security – ITJob Purpose: Acting in a key technical management & execution capacity to provide a conduit between IT teams and key business stakeholders in your functional area of IT Security to ensure information...
-
Information Security Management
6 days ago
Gurgaon, Haryana, India IIRIS Consulting Pvt. Ltd. Full time US$ 15,00,000 - US$ 20,00,000 per yearIIRIS is hiring VP/Sr. VP – Information Security (Gurgaon). We're looking for an experienced leader with 15+ years in Cyber Security, Technology Risk Assessment, and IT Governance, with proven expertise in driving business growth and leading high-performing teams. Certifications like CISSP/CISM/CRISC are highly preferred.Responsibilities:Develop and...
-
Information Security Manager
2 weeks ago
Gurgaon, Haryana, India American Express Full time US$ 1,20,000 - US$ 2,00,000 per yearAt American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleagues. As part of Team Amex, you'll experience this powerful backing with comprehensive support for your holistic well-being and many opportunities to learn new...
-
Information Security Manager- .one
6 days ago
Gurgaon, Haryana, India group Full time ₹ 9,00,000 - ₹ 12,00,000 per yearJob summary:As Information Security Manager at / , you will serve as a critical link between global security functions and local business units, ensuring seamless adoption of group-provided security services while driving stakeholder alignment. This role requires an outgoing professional with exceptional coordination skills, a deep understanding of Indian...
-
Head of Information Security
6 days ago
Gurgaon, Haryana, India Unizent Technologies Private Limited Full time US$ 1,20,000 - US$ 2,00,000 per yearCompany DescriptionUnizent Technologies Private Limited is a leading system integrator focusing on building and optimizing state-of-the-art IT infrastructure for businesses of all sizes. We provide end-to-end IT system integration, including network design, server and storage solutions, cloud integration, and cybersecurity services. Partnering with industry...
-
Director Information Security
4 days ago
Gurgaon, Haryana, India American Express Full timeYou Lead the Way Weve Got Your Back With the right backing people and businesses have the power to progress in incredible ways When you join Team Amex you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers communities and each other Here youll learn and grow as we help you create a career...
-
Information Security Analyst
6 days ago
Gurgaon, Haryana, India Coforge Full time ₹ 9,00,000 - ₹ 12,00,000 per yearJob Title / Role: Information Security AnalystKey Skills: SIEM, SOAR, DLP MonitoringExperience: 5-10 YearsLocation: GurugramMode: HybridWe at Coforge are looking for Information Security Analyst with following skill set :Experience of using security tools - SIEM, Anti-Virus, Threat Intel Platform, DLP monitoring, Vulnerability Management, SOAR, etc....
-
Information Security Professional
3 days ago
Gurgaon, Haryana, India beBeeDataGovernance Full time ₹ 1,50,00,000 - ₹ 2,50,00,000Job DescriptionThe role of a Data Governance and Security Specialist involves playing a crucial part in ensuring the security and integrity of sensitive data across an organization.You will support the collection of up-to-date information from business stakeholders regarding their most valuable data and its use on a yearly basis at a Data Element level when...