Role : Senior Manager - Information Security
Job Summary :
We are looking for an immediate joiner for the role of Senior Manager of Information Security. The ideal candidate will be a strategic leader responsible for the comprehensive information security strategy at Solytics Partners, a global analytics firm. This role involves developing, implementing, and managing our security posture to protect data and technology assets from evolving cyber threats. You'll lead the InfoSec function, ensuring all security policies and practices align with our business objectives and key industry / regulatory standards like GDPR, CCPA, and ISO 27001. A proven track record of implementing robust security frameworks and a deep understanding of the security landscape are essential.
Key Responsibilities :
Information Security Strategy :
- Develop and execute a comprehensive security strategy that aligns with business objectives.
- Provide expert advice to the executive team on cybersecurity vulnerabilities, threats, and emerging trends.
- Establish and maintain security policies, standards, and guidelines to ensure the confidentiality, integrity, and availability of company data.
Risk Management and Compliance :
Identify, assess, and prioritize security risks across the organization.Develop and implement mitigation strategies. Ensure compliance with industry standards and regulations, including GDPR, CCPA, and ISO 27001.Oversee internal and external security audits, vulnerability assessments, and penetration testing.Security Operations :
Lead the implementation and management of security technologies like firewalls, spam / malware protection, intrusion detection systems, and encryption.Monitor and respond to security incidents, ensuring effective and timely resolution.Develop and maintain comprehensive incident response plans.Security Architecture and Engineering :
Collaborate with technology teams to design and implement secure network, application, and cloud architectures.Evaluate and recommend new security technologies.Oversee the secure development lifecycle (SDLC) to embed security into every phase of product development.Team Leadership and Development :
Build and lead a high-performing information security team.Foster a culture of security awareness through continuous training and communication.Collaborate with IT and DevOps teams to integrate security best practices into all business aspects.Stakeholder Engagement and Reporting :
Communicate security risks, incidents, and strategies to the executive team and Board of Directors. Prepare and deliver regular reports on the company's security posture.Engage with customers, partners, and regulators to demonstrate a strong commitment to data protection.Required Skills & Qualifications :
Proven experience in cybersecurity and information security management.In-depth expertise with Microsoft security tools, including Sentinel, Intune, Purview, Defender, and Entra ID.Comprehensive knowledge of ISO 27001 standards and hands-on experience in managing compliance and audits.Hands-on SOC 2 Type 2 experience, including scoping, implementing controls, and preparing audit evidence.Proficiency in managing SIEM tools like Splunk, Azure Sentinel, or QRadar.Experience in overseeing Security Operations Center (SOC) processes, including incident response.Expertise in email security and anti-phishing measures.Strong background in endpoint security management, including Microsoft Defender.Skilled in firewall management and network security protocols.Strategic thinker with the ability to assess security risks and develop mitigation plans.Excellent leadership and communication skills, with experience in mentoring security teams and managing cybersecurity initiatives effectively.(ref : hirist.tech)