Job Title : Senior Manager - Risk Management and Information Security
Location : Bangalore only
Department : Risk Management - RAC
Reports To : ERM head
Experience Required : 15-20 years in Risk Management, Information Security, and Compliance roles
Job Summary :
We are seeking an experienced and proactive Senior Manager - Risk Mgmt and Information Security to lead and manage our global risk, compliance, incident response, and information security programs. This role will be instrumental in overseeing end-to-end security and risk functions, maintaining global compliance standards, and ensuring business continuity in a rapidly evolving threat landscape.
Key Responsibilities :
Incident & Risk Management :
- Manage org wide Enterprise Risk Register and keep updating and maintaining based on emerging risks
- Lead Incident Management including end-to-end ownership and resolution
- Manage and respond to issues related to Risks from Customers
- Own RCA-CAPA processes for all deviations, including customer-facing issues
- Conduct biannual Incident Simulations and ensure retraining and compliance for defaulters
- Manage and address all employee risks including those related to Physical security risks
Compliance & Audits :
Maintain ISMS ISO 27001, PIMS ISO 27701, SOC 2 Type 2 readiness, audit support, and NC tracking / closureRepresent Infosec in Customer Audits, SOC 2 Type 2, and other ISO assessmentsManage TPRM (Third Party Risk Management) support activities and compliance trackingEnsure timely completion of Cybervadis assessments and support Data Classification and other Privacy initiativesPolicy & Access Management :
Own annual SOP management and policy refresh cycles for InfoSecAdminister Exception Access Management for critical controls (USB, Gmail, Admin Access etc.,)Oversee Admin Access Management and enforce MDM / DLP policiesOversee IP inventory and ensure there are no IP violations.Security Monitoring & Tools :
Monitor threat landscape including Dark Web MonitoringLead Cybersecurity Attack Simulations, including SOP creation, documentation, and testingMaintain and optimize Forcepoint DLP policies and support MDM reviewsTraining & Awareness :
Lead Infosec Training Programs and ensure 98% compliance at any pointRefresh training materials for AUP, COE, ISMS annuallyConduct regular compliance follow-ups and retraining for defaultersMetrics & Reporting :
Define, publish, and manage IT Security Metrics dashboardsMaintain and update the Enterprise Risk TrackerStakeholder & Cross-Functional Collaboration :
Respond to and manage RFI / P (Request for Information / Proposal) documents for InfosecProvide Infosec support for various IT initiatives and new implementationsCoordinate with internal and external stakeholders for audits, assessments, and security operationsQualifications & Skills :
Bachelor's / Master's degree in Computer Science, or related fieldIndustry certifications such as CISSP, CISM, CISA, ISO 27001 LA, or equivalentIn-depth knowledge of ISMS, SOC 2, Privacy laws (including GDPR / DPDPA), and security best practicesExperience in tools like Forcepoint and creating risk dashboards with heat-mapsStrong stakeholder management, communication, and team leadership skillsAbility to work independently and manage global teams and vendorsPreferred Experience :
Experience in Pharma, Healthcare, or Regulated IndustriesPrior experience dealing with Customer AuditsKnowledge of emerging threats and technologies such as AI / ML in InfoSec(ref : iimjobs.com)