Information Security Manager

2 days ago


New Delhi, India Mashreq Full time

Job PurposeManagement:- To Strategize, develop and implement Data Protection Controls in coordination with stakeholders across the Organization globally. - To ensure compliance of the Organization with the defined policy & framework with a data driven approachExecution- To ensure that the protection operations are executed effectively in a timely manner and with required quality - Assists in the development and implementation of Data Protection strategic initiatives. Leads all Data protection related tasks with effective monitoring and protection of information security assets.Manager – Data Protection has overall responsibility to coordinate and support the Head of Data Privacy and Protection to achieve organization’s Protection strategy and goals.He/she is a T-Shaped expert with proven skills in most core capability areas of Data Protection and security: Policy, Governance, Protection Strategy & Program Management.Performance evaluation of the role will be based on the positive impact on the bank in terms of Data protection posture enhancement rather than the effort put in place.Key result Areas- Develop and coordinate with stakeholder (internal/external) to implement Data Protection policies, procedures, and protocols. - Collaborate with internal departments, such as human resources, business and IT, to ensure compliance with security protocols and standards. - Drive the creation of a comprehensive data protection framework, ensuring compliance with applicable data security laws. - Develop and maintain metrics (Key Performance / Risk Indicators) for measuring effectiveness of the managed solution and reporting to key stakeholders. - Work closely with legal and compliance teams to manage risk, breaches, and audits related to data protection. - Advice on implementation robust security controls across all stages of the data lifecycle, including data collection, storage, processing, transmission, and destruction. - Ensure the use of encryption (at rest, in transit) and secure key management strategies. - Apply anonymization and pseudonymization techniques where required to mitigate privacy risks. - Collaborate with IT teams to integrate security measures into application and system design from the outset (security by design). - Good understanding/hands-on knowledge of DLP solution and data classification concepts. - Raise awareness and provide training about information handling rules to end-users; - Design and implement controls to reduce information risk and coordinate remediation actions with the support of the business; - Gather and document business and security requirements, identify and define opportunities and lead the development and implementation of Data Protection Controls that meet business needs. - Establish an exception management process for scenarios where data protection policies cannot be fully enforced. - Evaluate and approve security exceptions, ensuring that any deviations from standards are properly justified, documented, and risk-assessed. - Monitor and review approved exceptions regularly to ensure ongoing security and compliance.Knowledge, Skills and ExperienceEssential knowledge- Graduate/ Post Graduate degree in Science/ Engineering/ IT. - Minimum 2 Professional certification related to Information Security like CISM / CISSP./CASP+/ CEH / CCSP - 8+ years Information Security experience in large financial institution/ banks with minimum 5 years’ experience within Compliance, audit and/or risk function, with recent experience in Data protection projects implementation. - In-depth knowledge of data encryption, anonymization, pseudonymization techniques. - Strong understanding of security controls required at different stages of the data lifecycle.Skills and Application- Coordinate with internal stakeholders and cross-functional teams to execute Protection initiatives, ensuring that projects are completed on time and achieve desired outcomes. - Excellent communication skills with the ability to work cross-functionally with different teams.Strong analytical skills and the ability to evaluate the effectiveness of implemented security measures



  • New Delhi, India Envestnet Full time

    Job Title: Manager – Information SecurityJob SummaryWe are seeking an accomplished Information Security professional with extensive experience in cybersecurity best practices, enterprise security architecture, data protection, first-line information security risk management, and conducting security assessments. The Manager – Information Security will be...


  • New Delhi, India Envestnet Full time

    Job Title:Manager – Information SecurityJob Summary We are seeking an accomplished Information Security professional with extensive experience in cybersecurity best practices, enterprise security architecture, data protection, first-line information security risk management, and conducting security assessments. The Manager – Information Security will be...


  • New Delhi, India Peoplefy Full time

    Information Security ManagerLocation: Pune (Yerwada) | Hybrid ModeExperience: 11+ YearsNotice Period: Immediate to 60 DaysJob DescriptionWe are seeking an experienced Information Security Manager to lead and strengthen our security practices. This role requires a proven leader with strong expertise in Application Security, DevSecOps, and Vulnerability...


  • New Delhi, India Peoplefy Full time

    Information Security ManagerLocation: Pune (Yerwada) | Hybrid ModeExperience: 11+ Years⏳ Notice Period: Immediate to 60 DaysJob DescriptionWe are seeking an experienced Information Security Manager to lead and strengthen our security practices. This role requires a proven leader with strong expertise in Application Security, DevSecOps, and Vulnerability...


  • New Delhi, India Peoplefy Full time

    Information Security Manager Location: Pune (Yerwada) | Hybrid Mode Experience: 11+ Years ⏳ Notice Period: Immediate to 60 DaysJob Description We are seeking an experiencedInformation Security Managerto lead and strengthen our security practices. This role requires a proven leader with strong expertise inApplication Security, DevSecOps, and Vulnerability...


  • New Delhi, India Peoplefy Full time

    Information Security ManagerLocation: Pune (Yerwada) | Hybrid Mode Experience: 11+ Years ⏳ Notice Period: Immediate to 60 DaysJob Description We are seeking an experiencedInformation Security Managerto lead and strengthen our security practices. This role requires a proven leader with strong expertise inApplication Security, DevSecOps, and Vulnerability...

  • TAC Security

    4 days ago


    New Delhi, India TAC Security Full time

    & Program Management- Lead the full lifecycle of compliance programs from scoping and gap assessments to remediation, controls implementation, audit prep, and certification.- Maintain and continually improve the Information Security Management System (ISMS) as per ISO standards.- Oversee the SOC 2 program: manage readiness assessments, control design,...


  • New Delhi, India CryptoMize Full time

    Responsibilities END --> Our Principles These are some of the principles that we strongly believe in, preach and actually follow as well. Commitments We clearly commit what we can do, by when can we do it and how we would do it, And then we do it. Confidentiality We are extremely paranoid about protecting the confidentiality of what...


  • New Delhi, India Lexitas Full time

    About the companyLexitas is a high growth company. The Company is built on a belief that having strong personal relationships with our clients, and providing reliable, accurate and professional services, is the driving force of our success.Lexitas offers an array of services including local and national court reporting, medical record retrieval, process...


  • New Delhi, India Lexitas Full time

    About the companyLexitas is a high growth company. The Company is built on a belief that having strong personal relationships with our clients, and providing reliable, accurate and professional services, is the driving force of our success. Lexitas offers an array of services including local and national court reporting, medical record retrieval, process...