Deputy General Manager-GRC

SupportFinity™

Ahmedabad District

On-site

INR 1,200,000 - 2,000,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

SupportFinity™ based in Ahmedabad, Gujarat is looking for an experienced Information Security Manager. The candidate will lead the implementation and continual improvement of the Information Security Management System (ISMS) as per ISO/IEC 27001 standards and manage internal/external audits.

Ideal applicants should have experience in conducting ISMS gap assessments, maintaining ISMS documentation, and ensuring compliance with regulatory standards. Strong analytical and risk-based decision-making skills are essential.

Qualifications

  • ISO/IEC 27001 Lead Implementer and/or Lead Auditor certifications required.
  • Strong documentation, policy drafting, and process definition skills are essential.
  • Excellent communication and cross-functional collaboration skills necessary.

Responsibilities

  • Lead the implementation and continual improvement of ISMS in line with ISO/IEC 27001 standards.
  • Conduct ISMS gap assessments and enterprise-wide cyber risk assessments.
  • Track implementation of security controls and support internal/external audits.
  • Maintain ISMS documentation, including risk registers and policies.
  • Identify control gaps and assess risk impacts.

Skills

ISO/IEC 27001 Lead Implementer
ISO/IEC 27001 Lead Auditor
CISA
CISM
CRISC
Documentation skills
Analytical skills
Audit planning
Stakeholder management
Communication skills

Job description

Overview

Lead the implementation, maintenance, and continual improvement of the Information Security Management System (ISMS) in line with ISO/IEC 27001 standards. Conduct ISMS gap assessments and enterprise-wide cyber risk assessments, and track implementation of security controls. Plan, manage, and support internal and external audits, including ISO 27001 Stage 1 and Stage 2 audits. Maintain and govern ISMS documentation, including policies, standards, procedures, risk registers, and the Statement of Applicability (SoA). Drive Information Security policy and process governance by drafting, reviewing, and updating policies, standards, and SOPs. Lead internal technology audits across IT infrastructure, cloud environments, SOC, IAM, PAM, vulnerability management, and other cyber domains. Identify control gaps, assess risk impact, track remediation actions, and validate the effectiveness of corrective measures. Oversee the complete cyber risk management lifecycle, including risk identification, analysis, treatment planning, and monitoring. Manage third-party and vendor security risk assessments and due diligence activities. Ensure compliance with applicable regulatory and statutory requirements such as ISO/IEC 27001, CERT-In, CEA, BCAS, DPDP Act, and other relevant regulations. Develop governance metrics, KPIs, and KRIs, and provide periodic risk and compliance reporting to senior management and audit committees. Monitor changes in regulatory and compliance requirements and collaborate with cross-functional teams to address gaps and audit observations.

Responsibilities
  • Lead the implementation, maintenance, and continual improvement of the Information Security Management System (ISMS) in line with ISO/IEC 27001 standards.
  • Conduct ISMS gap assessments and enterprise-wide cyber risk assessments, and track implementation of security controls.
  • Plan, manage, and support internal and external audits, including ISO 27001 Stage 1 and Stage 2 audits.
  • Maintain and govern ISMS documentation, including policies, standards, procedures, risk registers, and the Statement of Applicability (SoA).
  • Drive Information Security policy and process governance by drafting, reviewing, and updating policies, standards, and SOPs.
  • Lead internal technology audits across IT infrastructure, cloud environments, SOC, IAM, PAM, vulnerability management, and other cyber domains.
  • Identify control gaps, assess risk impact, track remediation actions, and validate the effectiveness of corrective measures.
  • Oversee the complete cyber risk management lifecycle, including risk identification, analysis, treatment planning, and monitoring.
  • Manage third-party and vendor security risk assessments and due diligence activities.
  • Ensure compliance with applicable regulatory and statutory requirements such as ISO/IEC 27001, CERT-In, CEA, BCAS, DPDP Act, and other relevant regulations.
  • Develop governance metrics, KPIs, and KRIs, and provide periodic risk and compliance reporting to senior management and audit committees.
  • Monitor changes in regulatory and compliance requirements and collaborate with cross-functional teams to address gaps and audit observations.
Qualifications
  • ISO/IEC 27001 Lead Implementer and/or Lead Auditor.
  • CISA, CISM, CRISC, or equivalent GRC-related certifications.
  • Strong documentation, policy drafting, and process definition skills.
  • Analytical and risk-based decision-making capabilities.
  • Audit planning, execution, and stakeholder management.
  • Ability to present risk and compliance insights to senior leadership.
  • Excellent communication and cross-functional collaboration skills.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Manager
Information Security Manager

Altraize • Mumbai

On-site
Information Security Officer
Information Security Officer

Indutch Composites Technology • Vadodara

On-site
INR 600,000 - 1,000,000
Senior Manager - IT GRC
Senior Manager - IT GRC

PNB Housing • Dadri

On-site
INR 1,200,000 - 1,800,000
Senior Security GRC & ISO 27001 Manager
Senior Security GRC & ISO 27001 Manager

UST • Thiruvananthapuram

On-site
INR 1,500,000 - 2,100,000
GAIN Central IT - Information Security Manager
GAIN Central IT - Information Security Manager

GAIN • Maharashtra

On-site
INR 1,000,000 - 1,500,000
Senior Security GRC & ISO 27001 Specialist
Senior Security GRC & ISO 27001 Specialist

UST • Ernakulam

On-site
INR 2,800,000 - 4,200,000
Information Security GRC Manager
Information Security GRC Manager

Mount Talent Consulting • Mumbai

On-site
INR 3,000,000 - 5,000,000
Senior Manager – IT Governance
Senior Manager – IT Governance

Concept Medical • Surat

On-site
INR 4,000,000 - 7,000,000
GRC Lead- Internal Audit & ISO Implementation
GRC Lead- Internal Audit & ISO Implementation

Mobileware Technologies • Mumbai

On-site
INR 1,500,000 - 2,100,000
Information Security - Manager
Information Security - Manager

Promaynov Advisory Services Pvt. Ltd • Delhi

On-site
INR 1,800,000 - 2,400,000