Information Security Manager
4 weeks ago
Job Description : Company : Glan Management ConsultancyLocation : GurgaonExperience : 7-15 yearEmployment Type : Job Description : Job Title : Manager Information Security - ITJob Purpose : Acting in a key technical management & execution capacity to provide a conduit between IT teams and key business stakeholders in your functional area of IT Security to ensure information technology needs are managed consistently, following professional IT and global standards, and delivered with a high level of quality and customer satisfaction.Reward level : Middle ManagementJob Location : GurgaonExperience : 10+ yearsRelevant Experience : 7+ yearsReporting to : General ManagerQualification : Bachelor degree in ITKey Deliverables : - Provide support as Lead auditor towards ISMS and PIMS policies, procedures, and guidelines and perform regular review and update.- Perform deep assessment to gather evidence of continuous compliance with ISO 27001 : 2022 and ISO 27701 : 2019, DPDPA, IT Act and Cert In Regulation including audit logs, records of reviews, timely closure of open audit and risks and sharing the report with management.- Conduct regular, documented information security and privacy risk assessments identifying assets, threats, vulnerabilities, likelihood, and impact with stakeholders.- Prioritize identified vulnerabilities, detailed findings, remediation recommendations, trending reports on vulnerability posture towards closure with stakeholders.- Development and implementation of a comprehensive, ongoing security awareness and training program for all employees.- Encourage secure behaviours among colleagues and reinforce the importance of information security and privacy in daily operations.- Prepare regular report on overall information security posture, GRC maturity, and risk landscape to relevant stakeholders- Ability to collect lessons learned from incidents, audits, and assessments to drive continuous improvement in ISMS/PIMS and security processes.Key Relationships :- Internal IT and business customers.- Global IT Vendor, market and global (HQ) colleagues, Local vendor partners- Internal staff - direct reports (where applicable)- IT vendors, contractors (where applicable)Knowledge Skills and Abilities : - Must possess and demonstrate ISO 27001 Lead Implementer/Auditor and ISO 27701 Lead Implementer/Auditor certifications and knowledge.- In depth understanding of IT Act, DPDPA, Cert In regulations, CIS Controls as well as UK DPA and ISO 31000- Good to have certification on CISM (Certified Information Security Manager), CISSP (Certified Information Systems Security Professional) and Cloud Security certifications (e.g., CCSK, CCSP, vendor-specific like AWS Security Specialty)- Familiarity with common vulnerability scanning tools like Qualys (features, reporting, agent-based vs. network scans) and Cloud Security Posture Management (CSPM) tools like Wiz (cloud service provider configurations, misconfigurations, compliance checks in AWS, Azure, GCP).- Understanding of various penetration testing types (e.g., network, web application, API, mobile, cloud) and methodologies- Knowledge of common attack vectors and exploitation techniques like MITRE ATTACK and DEFEND framework.- Basic to intermediate knowledge of common security controls and technologies (e.g., firewalls, EDR, Cloud Security, VAPT tools, SIEM, WAF, DLP, encryption).- Understanding of network protocols, operating systems (Windows, Linux), and common application architectures.- Knowledge of audit principles and practices (internal and external audits).- Understanding of corrective action planning and non-conformity management.- Understanding of third-party risk management principles and vendor due diligence processes.- Excellent technical writing skills for creating clear, concise, and comprehensive security policies, standards, and procedures.- Ability to analyse complex risk data and present actionable insights.- Hands-on experience with Qualys for configuring scans, analysing reports, and managing vulnerabilities.- Hands-on experience with Wiz CSPM for monitoring cloud environments, identifying misconfigurations, and generating compliance reports.- Proficiency with GRC platforms or tools for managing policies, risks, and controls- Exceptional verbal and written communication skills to articulate complex security concepts to technical and non-technical stakeholders- Ability to build strong relationships and collaborate effectively with diverse teams (IT, Legal, HR, Development, Business Units).- Skills in influencing behaviour and driving change across the organization to improve security posture.- Strong analytical skills to diagnose security issues, identify root causes, and develop effective solutions.- Ability to critically evaluate security controls and identify gaps.- Contract review and negotiation skills specifically for security-related services.- Ability to effectively manage vendor relationships and performance.- Ability to develop and deliver engaging security training sessions and awareness campaigns.- Ability to stay updated with the latest security threats, vulnerabilities, technologies, and regulatory changes.- Capacity to quickly learn and adapt to new tools and methodologies.- Meticulous attention to detail in policy creation, audit documentation, and vulnerability analysis.- Ability to act calmly and effectively during security incidents and contribute to incident response efforts.Key Skill : information security manager, IT security, ISO 27001 LA, ISO 27001 LI, ISO 27001 LI/LA, ISO 27701, ISO 31000, internal auditor, DPDPA, CISM, compliance ISO 27001 : 2022Job Type : Full-time (ref:hirist.tech)
-
Manager-Information Security
3 weeks ago
Gurugram, Gurugram, India Genpact Full timeJob Description Ready to shape the future of work At Genpact, we don't just adapt to change-we drive it. AI and digital innovation are redefining industries, and we're leading the charge. Genpact's AI Gigafactory, our industry-first accelerator, is an example of how we're scaling advanced technology solutions to help global enterprises work smarter, grow...
-
Manager-Information Security
22 hours ago
Gurugram, India Genpact Full timeReady to shape the future of work? At Genpact, we don’t just adapt to change—we drive it. AI and digital innovation are redefining industries, and we’re leading the charge. Genpact’s AI Gigafactory, our industry-first accelerator, is an example of how we’re scaling advanced technology solutions to help global enterprises work smarter, grow faster,...
-
Director / AVP Information Security
23 hours ago
Gurugram, India Cvent Full timeOverview: You are an experienced and dynamic cybersecurity leader able to provide regional, executive-level support for a variety of programs and initiatives as well as manage the day-to-day operations of Cvent's India Information Security team based in Gurgaon, India. In this role you will be responsible for supporting regional teams to execute a variety of...
-
Information Security Manager
1 week ago
Delhi, Gurugram, NCR, Noida, India Newgen Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob description - Information Security ManagerRole & responsibilities-Shall be accountable for interpreting the RFI/RFP, or Customer queries, and responding to them.-Review Contracts/MSA/DPA to ensure they include appropriate risk-related clauses, such as security controls, data privacy, liability, and business continuity terms.-Shall be accountable for...
-
Information Security
2 days ago
Delhi, Gurugram, NCR, Noida, India Aliqan Services Full time ₹ 15,00,000 - ₹ 25,00,000 per yearInformation Security & Data Protection Officer (DPO) – Manager,GDPR, DPDP Act, HIPAA, and other global privacy laws/regulations, IT security expertise (firewalls, intrusion detection/prevention, cloud security, identity & access management
-
Supply Chain Security/information Security
2 weeks ago
Gurugram, Haryana, India Stefanini, Inc Full time*Listed salary ranges may vary based on experience, qualifications, and local market. Also, some positions may include bonuses or other incentives* **About Stefanini Group** **Role Description**: **Responsibilities**: - Perform focused risks assessments of existing or new service providers, and technologies being introduced into the firm's technology...
-
Information Security Architect
2 weeks ago
Gurugram, Haryana, India Cepheid Full timeAt Cepheid, we are passionate about improving health care through fast, accurate diagnostic testing. Our mission drives us, every moment of every day, as we develop scalable, groundbreaking solutions to solve the world’s most complex health challenges. Our associates are involved in every stage of molecular diagnostics, from ideation to development and...
-
gurugram, India Talent Worx Full timeJob Title: Information Security Programs AdministratorCorp Level : Associate ILocation: COEKey responsibilities:Track the performance of security measures to protect information and network infrastructure and computer systems Responsible for the operations of the Third-Party Cyber Risk Management program.Conduct thorough risk assessments of third-party...
-
Chief Information Security Officer
2 weeks ago
Gurugram, Haryana, India gHRig People Solutions Full time**Position Title**: Chief Information Security Officer (CISO)**: **Location**: Gurugram **Reports To**: CEO /CTO **Employment Type**: Full-Time **Experience**: 10-15 years, with minimum 5 years in NBFC/financial services **Position Summary**: The Chief Information Security Officer (CISO) is a CXO-level executive responsible for establishing and leading the...
-
Gurugram, India Alpha Orion Full timeWe are seeking a highly skilled CISO / Information Security Expert with a strong technical background in security tools, threat mitigation, and cybersecurity operations. This role focuses on hands-on security implementation, monitoring, and incident response. The ideal candidate should have deep expertise in security technologies, risk management, and...