Talent.com
Information Security Manager

Information Security Manager

GGVnagpur, India
23 hours ago
Job description

Position Summary

The Information Security Lead will lead the enterprise security compliance agenda, ensuring full alignment with evolving regulatory frameworks such as ISO 27001, DPDP Act, CERT-IN, ITGC, and ISO / IEC 42001 (AI Governance) . This role is crucial in maintaining client trust, operational resilience, audit readiness, and risk posture across all firm systems, platforms, and third-party integrations.

Key Responsibilities

  • Implement ISO 27001 in all offices.
  • Lead and maintain ISO 27001 certification , including ISMS policy enforcement, risk treatment plans, SoA, internal audits, and management reviews.
  • Implement and monitor compliance with :
  • DPDP Act (India)
  • CERT-IN Guidelines (incident response, remote access, logging, reporting)
  • ITGC Controls (as part of statutory and internal audits)
  • ISO / IEC 42001 – AI Governance framework and AI risk registers
  • Build and maintain a firm-wide risk register for cyber, privacy, and technology controls.
  • Define and review Information Security Policies, Data Classification, Encryption Standards, Third-party Risk , etc.
  • Partner with Legal, Risk, and IT teams to map risk ownership and corrective action workflows.
  • Own and manage all client security assessments, and due diligence questionnaires .
  • Maintain a structured repository of pre-approved responses, certificates, and audit summaries.
  • Engage with clients’ cybersecurity teams and support InfoSec audits or certifications demanded during onboarding or renewals.
  • Lead GRC and access controls review across all IT systems and applications.
  • Lead cyber insurance renewals , manage exposure data, and maintain claim readiness documentation.
  • Define and test the incident response plan and conduct periodic tabletop exercises with senior leadership and external advisors.
  • Lead BCP for the firm, and ensure it’s regularly tested.
  • Ensure alignment with business continuity and disaster recovery strategies.
  • Define quarterly and annual Vulnerability Assessment & Penetration Testing (VAPT) plan with top-tier CERT-IN certified vendors.
  • Oversee closure of vulnerabilities and tracking of all red / amber findings.
  • Coordinate with IT Infrastructure and App teams for secure configuration baselines (servers, endpoints, cloud).
  • Track global trends and legal obligations in :
  • AI & Data Ethics (align to ISO / IEC 42001)
  • Cloud Security (including contractual obligations with SaaS providers)
  • Encryption & Logging requirements under CERT-IN
  • Draft internal advisories and update control frameworks accordingly.
  • Lead the firm’s cybersecurity awareness and phishing simulation program .
  • Conduct annual ISMS awareness campaigns and mandatory user certification programs.
  • Build a security-conscious culture by regularly engaging with Practice Heads, Partners, and Business Services.

Key Deliverables

  • ISO 27001 maintained with zero non-conformities
  • Full compliance with CERT-IN guidelines and DPDP readiness documentation
  • Quarterly VAPT assessments with remediation closure tracking
  • Quarterly internal reviews to maintain compliance
  • 100% client audit response turnaround within defined SLA
  • Annual cyber tabletop drill executed with report and improvements tracked
  • Internal and external audits passed with minimal observations
  • Cyber Insurance aligned to evolving risks and policy coverage verified
  • Conduct quarterly reviews to maintain all the compliance
  • Certifications Required

  • ISO 27001 Lead Implementer / Auditor
  • CISSP / CISM
  • DPDP Act / Privacy Certifications
  • ISO / IEC 42001 (AI Governance Awareness) – Preferred
  • ITIL v4 – Preferred
  • Education

  • B.E / B.Tech / M.Tech / Master in computer science
  • Leadership & Behavioral Competencies

  • Highly structured, audit-ready, and documentation-oriented
  • Strong stakeholder engagement with Partners, Clients, cross functional teams, and Auditors
  • Proactive risk identifier with a strong grasp of Indian and global compliance regimes
  • Calm under pressure with strong incident response instincts
  • Strategic mindset with tactical attention to operational control and reporting
  • Create a job alert for this search

    Information Security Manager • nagpur, India

    Related jobs
    • Promoted
    Information Security and Risk Manager

    Information Security and Risk Manager

    SCGNew Delhi, Republic Of India, IN
    SCG’s entry into India emphasizes.The Cybersecurity Officer safeguards SCG’s systems, data, and networks against threats, ensuring. Monitor security alerts, incidents, and system vulnerabilities.Imp...Show moreLast updated: 30+ days ago
    • Promoted
    Information Security Management Lead

    Information Security Management Lead

    DeloitteRepublic Of India, IN
    India’s impact on the global economy has increased at an exponential rate and Deloitte presents an opportunity to unleash and realize your potential amongst cutting edge leaders, and organisations ...Show moreLast updated: 30+ days ago
    • Promoted
    Information Security Architect

    Information Security Architect

    Purchasing PowerChennai, Republic Of India, IN
    We are the leading specialty e-retailer offering consumer products, vacations and online education services.Our customers love us because we make paying for their. The automatic payments help them t...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Senior Cloud Security Specialist

    Senior Cloud Security Specialist

    ACL Digitalnagpur, maharashtra, in
    We are a leading organization in the field of information security, dedicated to protecting our clients' data and ensuring their digital safety. Our mission is to provide innovative security solutio...Show moreLast updated: 17 hours ago
    • Promoted
    Head of Information Security

    Head of Information Security

    HotelTrader LodgIQ (India) Pvt. Ltd.Nagpur, IN
    Hotel Trader is a 100% automated & cloud-based distribution management company providing the tools necessary for hotels to seamlessly connect to global demand with the click of a button.We fully em...Show moreLast updated: 30+ days ago
    • Promoted
    Information Security Analyst I

    Information Security Analyst I

    Airtel DigitalNew Delhi, Republic Of India, IN
    The Security Operation Centre (SOC) Information Security Analyst is the first level of monitoring in the SOC.The position monitors and responds to security events from managed customer security sys...Show moreLast updated: 23 days ago
    • Promoted
    • New!
    Cyber Security Manager

    Cyber Security Manager

    CareerUS SolutionsNagpur, IN
    The Cyber Security Manager is responsible for.The Cyber Security Manager also leads a team of security professionals and collaborates across departments to strengthen the company’s overall.Develop,...Show moreLast updated: 20 hours ago
    • Promoted
    Head of Information Security

    Head of Information Security

    Cube Consultancy ServicesIndia, India
    We are seeking a highly skilled and adaptable business analyst who focuses on technology and B2B distribution.This role involves working closely with both internal development teams and external cl...Show moreLast updated: 1 day ago
    Information Security Manager

    Information Security Manager

    MonetaGo Inc.IN
    Quick Apply
    Educational Qualifications : Certifications : Professional certifications such as Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), Certified ...Show moreLast updated: 2 days ago
    • Promoted
    Manager, Information Security and Governance

    Manager, Information Security and Governance

    DeloitteRepublic Of India, IN
    India’s impact on the global economy has increased at an exponential rate and Deloitte presents an opportunity to unleash and realize your potential amongst cutting edge leaders, and organisations ...Show moreLast updated: 30+ days ago
    • Promoted
    Information Security Specialist

    Information Security Specialist

    InCred CapitalRepublic Of India, IN
    We are seeking a highly motivated and independent Information Security Engineer to join.The ideal candidate will possess a broad range of technical and compliance expertise across various informati...Show moreLast updated: 23 days ago
    • Promoted
    Illumio- Zero Trust Microsegmentation

    Illumio- Zero Trust Microsegmentation

    CareerXperts Consultingnagpur, maharashtra, in
    Hiring : Manager - Zero Trust Microsegmentation.Bengaluru | 💼 5+ Years Experience.Lead Illumio microsegmentation implementations. Design & deploy Zero Trust policies.Analyze network infrastructure &...Show moreLast updated: 12 days ago
    • Promoted
    Information Security Engineer

    Information Security Engineer

    InCred CapitalRepublic Of India, IN
    We are seeking a highly motivated and independent Information Security Engineer to join.The ideal candidate will possess a broad range of technical and compliance expertise across various informati...Show moreLast updated: 23 days ago
    • Promoted
    Regional Cyber Governance & Compliance Manager

    Regional Cyber Governance & Compliance Manager

    StellantisChennai, Republic Of India, IN
    The Regional Information Security Officer (RISO) serves as the key cybersecurity and data protection leader within the region, acting as a strategic liaison between the Global CISO organization and...Show moreLast updated: 12 days ago
    • Promoted
    Information Security Manager

    Information Security Manager

    ConfidentialIndia
    Duration : 12 months + long term.Candidate must be comfortable to work as per US time 5 PM- 1 AM IST.Job Title : Manager, Cyber Operations. Department : Digital Security Group.Apply your knowledge of I...Show moreLast updated: 5 days ago
    • Promoted
    Senior Manager Information Security

    Senior Manager Information Security

    Ocwen Financial Solutions Pvt. Ltd. - APACPune, Republic Of India, IN
    The Incumbent would be responsible to manage the information security governance, risk, and compliance process.Standardize GRC policies, evaluate their impacts, and implement the relevant measure.L...Show moreLast updated: 1 day ago
    • Promoted
    Information Security Engineer

    Information Security Engineer

    Centrico India Private LtdChennai, Republic Of India, IN
    As a Cyber Security Specialist you would be involved in one or more of the following activities : .Monitors, identify, investigate and analyze all activities related to cyber security.Identify securi...Show moreLast updated: 12 days ago
    • Promoted
    Information Security Architect

    Information Security Architect

    Tata Consultancy ServicesRepublic Of India, IN
    We are looking for Expert level technical experience with Cyber Security Skills.Required Infrastructure Skills : .Own the design and implementation phases of new and innovative Security architecture...Show moreLast updated: 20 days ago