Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
SupportFinity™ based in Ahmedabad, Gujarat is looking for an experienced Information Security Manager. The candidate will lead the implementation and continual improvement of the Information Security Management System (ISMS) as per ISO/IEC 27001 standards and manage internal/external audits.
Ideal applicants should have experience in conducting ISMS gap assessments, maintaining ISMS documentation, and ensuring compliance with regulatory standards. Strong analytical and risk-based decision-making skills are essential.
Lead the implementation, maintenance, and continual improvement of the Information Security Management System (ISMS) in line with ISO/IEC 27001 standards. Conduct ISMS gap assessments and enterprise-wide cyber risk assessments, and track implementation of security controls. Plan, manage, and support internal and external audits, including ISO 27001 Stage 1 and Stage 2 audits. Maintain and govern ISMS documentation, including policies, standards, procedures, risk registers, and the Statement of Applicability (SoA). Drive Information Security policy and process governance by drafting, reviewing, and updating policies, standards, and SOPs. Lead internal technology audits across IT infrastructure, cloud environments, SOC, IAM, PAM, vulnerability management, and other cyber domains. Identify control gaps, assess risk impact, track remediation actions, and validate the effectiveness of corrective measures. Oversee the complete cyber risk management lifecycle, including risk identification, analysis, treatment planning, and monitoring. Manage third-party and vendor security risk assessments and due diligence activities. Ensure compliance with applicable regulatory and statutory requirements such as ISO/IEC 27001, CERT-In, CEA, BCAS, DPDP Act, and other relevant regulations. Develop governance metrics, KPIs, and KRIs, and provide periodic risk and compliance reporting to senior management and audit committees. Monitor changes in regulatory and compliance requirements and collaborate with cross-functional teams to address gaps and audit observations.