Information Security Officer

24 hours ago


Mumbai Maharashtra, India Hyrmus Full time

**Job Title**: Information Security & Compliance Officer (Alternate Title: Infosec Auditor & Governance Manager)

**Location**: Mumbai (or Hybrid as per business need)

**Reporting To**: Chief Information Security Officer (CISO) / Head of Technology

**Purpose of the Role**: To manage and coordinate all Information Security audits, respond to auditor/banker queries, track remediation timelines, maintain audit-ready documentation, implement security controls, and ensure compliance with ISO 27001, RBI guidelines, CICRA (Credit Information Companies Regulation Act), and other regulatory requirements.

**Key Responsibilities**:
1. **Audit & Compliance Management**
- Own end-to-end audit lifecycle across internal, external, partner, and regulatory audits (ISO 27001, RBI, CISA, Bank Infosec teams, CICs).
- Liaise with banks, auditors, NBFC partners to provide timely responses and evidence.
- Maintain an exhaustive audit tracker with timelines, evidence folders, and closure reports. - Prepare documentation and ensure regular reviews of quarterly and half-yearly items (UARs, VAPT, password policy reviews, etc.).

2. **Policy Implementation & Review**
- Coordinate implementation and periodic review of all security policies such as:

- Information Security Policy
- Access Control Policy
- Encryption & Cryptographic Policy
- Password Policy
- Cloud Security Policy
- DLP, Antivirus & Patch Management Policy
- Data Retention & Disposal Policy
- Change Management & SDLC
- HR Policy Security Clauses (Separation, Laptop return, Fidelity declaration)
- Ensure all policies are updated, approved, communicated, and enforced.

3. **Security Controls & Infrastructure Compliance**
- Maintain evidence of:

- AWS security group reviews and hardening reports
- VPN tools and access mechanisms
- IDS/IPS deployment
- Endpoint protection software, patch deployment
- DR/BCP drills and logs
- Cloud/network diagrams and access logs
- Coordinate with infra & DevOps team to track VAPT, SIEM, and firewall configurations.

4. **Vendor, Cloud & Third-Party Governance**
- Monitor and govern cloud configurations and vendor relationships for:

- AWS (Encryption, KMS, access control, VPC architecture)
- Anti-virus/DLP/MDM/USB blocking tools
- VAPT / Penetration Test vendors
- Subcontractor compliance with privacy & data sharing agreements

5. **Documentation, Evidence & Automation**
- Maintain updated SOPs, policy documents, declaration forms, signed NDAs, audit reports. - Create periodic evidence checklists and trackers (UAR logs, patch updates, policy review minutes, Form III declarations).
- Work with tech & HR to automate compliance triggers (alerts for quarterly reviews, policy expiry, form sign-offs, etc.)

**Qualifications**:

- Bachelor’s degree in IT, Computer Science, Cybersecurity or equivalent.
- Preferred: CISA, ISO 27001 Lead Implementer/Auditor, CEH, or other infosec certifications.

**Experience**:

- 3-7 years of hands-on experience in information security audits, IT compliance, or governance roles.
- Experience with ISO 27001, RBI IT frameworks, CICRA, or financial sector infosec requirements preferred.

**Key Skills**:

- Strong documentation and audit response skills
- Familiarity with AWS cloud, SIEM tools, endpoint protection, patching cycles
- Working knowledge of SDLC and DevSecOps frameworks
- Comfortable working cross-functionally with Tech, HR, Admin, Vendors, and Legal teams
- Strong command over Excel trackers, file documentation, and policy drafting

**Bonus Skills**:

- Knowledge of Indian regulatory requirements (CICRA, RBI Circulars)
- Experience in fintech or BFSI domain
- Familiarity with VAPT report analysis and remediation tracking

**Job Types**: Full-time, Permanent

Pay: ₹40,000.00 - ₹70,000.00 per month

**Benefits**:

- Cell phone reimbursement
- Health insurance
- Paid sick time
- Provident Fund

Schedule:

- Day shift
- Fixed shift

Work Location: In person


  • Information Security

    24 hours ago


    Mumbai, Maharashtra, India Kuber and Company Full time

    **Job Title: Information Security & Compliance Officer** **(Alternate Title: Infosec Auditor & Governance Manager)** **Location**:Mumbai (or Hybrid as per business need) Reporting To: Chief Information Security Officer (CISO) / Head of Technology **Purpose of the Role**: To manage and coordinate all Information Security audits, respond to auditor/banker...


  • Pune, Maharashtra, India Davies Full time

    **Description**: - We are seeking a proactive and knowledgeable Information Security Officer to support the business across all aspects of information security. This role is essential in maintaining and strengthening our security posture, ensuring compliance with our regulatory and legal requirements, including maintaining our ISO/IEC 27001 certification. -...


  • Mumbai, Maharashtra, India PaywithRing Full time

    As the Chief Information Security Officer (CISO) at Ring, you will be responsible for overseeing and implementing comprehensive security strategies to safeguard our organization's information assets and ensure compliance with industry regulations. You will play a critical role in maintaining the confidentiality, integrity, and availability of our data,...


  • Mumbai, Maharashtra, India Shloka Security Services Full time

    Required Security Guard and also Required Field Officer For our Security Agency **Job Types**: Full-time, Permanent Pay: ₹15,000.00 - ₹35,000.00 per month **Benefits**: - Health insurance - Provident Fund **Experience**: - security field: 3 years (required) **Location**: - Mumbai, Maharashtra (required) Work Location: Remote


  • Fort, Mumbai, Maharashtra, India Dhara Consulting Group Full time US$ 80,000 - US$ 1,20,000 per year

    TodayTop SecretUnspecifiedUnspecifiedIT - SecurityFort Wayne, IN (ON-SITE/OFFICE)Date Posted: Country:United States of AmericaLocation:IN301: 1010 Production Rd Ft Wayne IN 1010 Production Road , Fort Wayne, IN, 46808 USAPosition Role Type:OnsiteU.S. Citizen, U.S. Person, or Immigration Status Requirements:Active and transferable U.S. government issued...


  • Mumbai, India Sattrix Information Security Full time

    Device Management (IDM) Support Engineers – L1, L2 & L3 Location: Chennai, Hyderabad and Mumbai Experience: 10–12 years (Minimum 7 years in Security Operations, Architecture & Device Management) Education: B.E. / B.Tech / MCA CISSP, CISM, CEH, CISA, ITIL, COBIT, ISO 27001 Experience: 4–6 years (Minimum 5 years in Security Device Management) Skills:...


  • Pune, Maharashtra, India Davies Full time

    **Description**: We are seeking a 3 year+ experienced Information Security Risk Officer to join our second line of defence, providing independent oversight, challenge, and assurance of information security practices across the organisation. This role is critical in ensuring that information security risks are effectively identified, assessed, managed, and...


  • Mumbai, India Wave HR and Advisory Pvt Ltd Full time

    ABOUT THE ROLE:We are building a Public Digital Infrastructure for Banking using emerging technologies to enable high-volume, cost-effective financial transactions. We are looking for a strategic and hands-on CISO to lead our cybersecurity efforts and ensure the integrity, security, governance, risk and compliance (GRC) and cyber security and BCP for of this...


  • Mumbai, Maharashtra, India Netcore Cloud Full time US$ 1,50,000 - US$ 2,00,000 per year

    Chief Information Security Officer (CISO) | Mumbai LocationPosition Summary:The Chief Information Security Officer (CISO) is a senior leadership role responsible for establishing, implementing, and managing the organization's comprehensive information security strategy. With a focus on protecting company assets, customer data, and application security, the...


  • Pune, Maharashtra, India Deutsche Bank Full time

    Job Title Technical Information Security Officer Location Pune India Corporate Title AVP Role Description The TISO acts based on the direction of and the tasks assigned by the Divisional TISO The TISO is typically assigned a set of Application Software Assets and associated Databases IT aspects only Infrastructure Software Assets IT Services Hardware Assets...