Information Security

13 hours ago


Mumbai Maharashtra, India Kuber and Company Full time

**Job Title: Information Security & Compliance Officer**

**(Alternate Title: Infosec Auditor & Governance Manager)**

**Location**:Mumbai (or Hybrid as per business need)

Reporting To: Chief Information Security Officer (CISO) / Head of Technology

**Purpose of the Role**:
To manage and coordinate all Information Security audits, respond to auditor/banker queries, track

remediation timelines, maintain audit-ready documentation, implement security controls, and ensure compliance with ISO 27001, RBI guidelines, CICRA (Credit Information Companies Regulation Act), and other regulatory requirements.

**Key Responsibilities**:
1. Audit & Compliance Management
- Own end-to-end audit lifecycle across internal, external, partner, and regulatory audits (ISO 27001, RBI, CISA, Bank Infosec teams, CICs).
- Liaise with banks, auditors, NBFC partners to provide timely responses and evidence.
- Maintain an exhaustive audit tracker with timelines, evidence folders, and closure reports.
- Prepare documentation and ensure regular reviews of quarterly and half-yearly items (UARs, VAPT, password policy reviews, etc.).

2. Policy Implementation & Review
- Coordinate implementation and periodic review of all security policies such as:

- Information Security Policy
- Access Control Policy
- Encryption & Cryptographic Policy
- Password Policy
- Cloud Security Policy
- DLP, Antivirus & Patch Management Policy
- Data Retention & Disposal Policyo Change Management & SDLC
- HR Policy Security Clauses (Separation, Laptop return, Fidelity declaration)
- Ensure all policies are updated, approved, communicated, and enforced.

3. Security Controls & Infrastructure Compliance
- Maintain evidence of:

- AWS security group reviews and hardening reports
- VPN tools and access mechanisms
- IDS/IPS deployment
- Endpoint protection software, patch deployment
- DR/BCP drills and logs
- Cloud/network diagrams and access logs
- Coordinate with infra & DevOps team to track VAPT, SIEM, and firewall configurations.

4. Vendor, Cloud & Third-Party Governance
- Monitor and govern cloud configurations and vendor relationships for:

- AWS (Encryption, KMS, access control, VPC architecture)
- Anti-virus/DLP/MDM/USB blocking tools
- VAPT / Penetration Test vendors
- Subcontractor compliance with privacy & data sharing agreements

5. Documentation, Evidence & Automation
- Maintain updated SOPs, policy documents, declaration forms, signed NDAs, audit reports.
- Create periodic evidence checklists and trackers (UAR logs, patch updates, policy review minutes, Form III declarations).
- Work with tech & HR to automate compliance triggers (alerts for quarterly reviews, policy expiry, form sign-offs, etc.)

**Qualifications**:

- Bachelor’s degree in IT, Computer Science, Cybersecurity or equivalent. **Preferred: CISA, ISO 27001 Lead Implementer/Auditor, CEH, or other infosec certifications.**

**Experience**:

- **3-7 years of hands-on experience in information security audits, IT compliance, or**

**governance roles.**
- Experience with ISO 27001, RBI IT frameworks, CICRA, or financial sector infosec

requirements preferred.

Key Skills:

- Strong documentation and audit response skills
- Familiarity with AWS cloud, SIEM tools, endpoint protection, patching cycles
- Working knowledge of SDLC and DevSecOps frameworks
- Comfortable working cross-functionally with Tech, HR, Admin, Vendors, and Legal teams
- Strong command over Excel trackers, file documentation, and policy drafting

Bonus Skills:

- Knowledge of Indian regulatory requirements (CICRA, RBI Circulars)
- Experience in fintech or BFSI domain
- Familiarity with VAPT report analysis and remediation tracking

Pay: ₹33,602.64 - ₹80,000.00 per month

Schedule:

- Day shift

Work Location: Hybrid remote in Mumbai Suburban, Maharashtra



  • Mumbai, Maharashtra, India BookMyShow Full time

    **Your Role**: BookMyShow is looking for a skilled information security analyst to be part of our InfoSec team. As information security engineer, you will be responsible for monitoring, fixing the security issues, interacting with different teams regarding security issues, and documenting security incidents. 1. Conduct Vulnerability Assessments, Penetration...


  • Mumbai, Maharashtra, India Prakhar Software Solutions Pvt Ltd Full time

    **Experience: fresher** **Notice period: immediate** **Budget: 18k monthly** **Loctaion: Mumbai (Mulund)** **Qualifications**: Bachelor's degree in Computer Science, Information Security, or a related field. A master's degree or equivalent experience is a plus. **Key Responsibilities**: **Security Management**: Develop, implement, and manage information...


  • Mumbai, Maharashtra, India Percipere Full time

    **Job Title**:Information Security Convenor **Department**: Information Security **Location**: Mumbai **Requirement**: - Understanding and atleast 2-3 years experience in the Information Security space - Certified as Information Security Implementer will be an added advantage **Job Description-** - You will be responsible for assisting and driving the...


  • Mumbai, Maharashtra, India Percipere Full time

    **Job Title**:Information Security Convenor **Department**: Information Security **Location**: Mumbai **Requirement**: - Understanding and atleast 2-3 years experience in the Information Security space - Certified as Information Security Implementer will be an added advantage **Job Description-** - You will be responsible for assisting and driving the...

  • Security Researcher

    2 weeks ago


    Kandivali, Mumbai, Maharashtra, India Security Brigade Full time

    **Job Information**: Industry - Software DevelopmentWork Experience - 1-3 yearsCity - Kandivali EastState/Province - MaharashtraCountry - IndiaZip/Postal Code - 400101Security Brigade is looking for a Security Researcher who will be working with ShadowMap tool which is an internal security tool & manage on-site clients for long-term.- Assist clients by...


  • Mumbai, India Morpheus Consultant Full time

    Job Title: Information Security Responsible for adhering to RBI guidelines on Cyber & IT governance. Day to day management of IT Security & Compliance. Job Responsibilities - Responsible for creating and maintaining information security policies and procedures, selecting, and implementing new information security technologies, creating information security...

  • Information Security

    2 weeks ago


    Vashi, Navi Mumbai, Maharashtra, India Anzen Technologies Private Limited Full time

    **Job Description for Information Security Consultant**: - **Technical / job functional knowledge** - Understanding and working knowledge of control frameworks based on industry best practices such as ISO27001, PCI-DSS, GDPR. - Responsible for conducting timely security assessments of third-party suppliers, recording results accurately and initiating...

  • Information Security

    2 weeks ago


    Mumbai, India Morpheus Human Consulting Full time

    Reference Code: - 321-31 - Job Title: **Information Security - IT Industry - Mumbai** - Category: - IT Enabled Services - Job Description: - Job Title: Information Security - IT Industry - Mumbai - Responsible for adhering to RBI guidelines on Cyber & IT governance. Day to day management of IT Security & Compliance. - Job Responsibilities - Responsible...

  • Information Security

    20 hours ago


    Mumbai, Maharashtra, India Kotak Life Insurance Full time ₹ 1,04,000 - ₹ 1,30,878 per year

    DEPARTMENTInformation SecurityREPORTING POSITIONCISOKEY RESPONSIBILITIESSecurity Engineering:Experience in review and /or implementation of technology components like networks, Infrastructure, security solutions like DLP, AD, end point security tools, Email Security, mobile device Security, proxy, firewall etc.Review effectiveness of IT architecture, Data...


  • Mumbai, Maharashtra, India Hyrmus Full time

    **Job Title**: Information Security & Compliance Officer (Alternate Title: Infosec Auditor & Governance Manager) **Location**: Mumbai (or Hybrid as per business need) **Reporting To**: Chief Information Security Officer (CISO) / Head of Technology **Purpose of the Role**: To manage and coordinate all Information Security audits, respond to auditor/banker...