GAIN Central IT - Information Security Manager

GAIN

Maharashtra

On-site

INR 1,000,000 - 1,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading IT Services provider is seeking an experienced Information Security Manager to lead the Information Security Management System and drive risk reduction and maturity. The ideal candidate has over 5 years in information security, ISO 27001 ISMS experience, and strong communication skills. This position offers a full-time opportunity for a mid-senior level role in Maharashtra, India.

Qualifications

  • 5+ years in information security with hands-on ISO 27001 ISMS experience.
  • Strong grasp of ISO/IEC 27001:2022 & 27002:2022 controls.
  • Able to translate security risk into business impact.

Responsibilities

  • Own the Statement of Applicability (SoA) and controls mapping.
  • Plan and coordinate audits and manage corrective actions.
  • Maintain the policy framework with document control.

Skills

ISO 27001 ISMS ownership
Cyber Essentials Plus delivery
Stakeholder influence
Risk management
Problem solving

Education

ISO27001 Lead Implementer or Lead Auditor certification
CISSP certification
CISM certification

Job description

GAIN Central IT - Information Security Manager

Overview: The Information Security Manager is responsible for proactively managing and improving our Information Security Management System driving risk reduction and security maturity across the organisation, partnering with IT, Engineering, Legal, Procurement, and senior leadership.

Responsibilities
  • Own the Statement of Applicability (SoA), mapping controls to Annex A and ensuring evidence of control design and operating effectiveness.
  • Plan and execute the internal audit programme; coordinate surveillance and recertification audits; manage corrective and preventive actions.
  • Maintain the policy framework (classification, access control, cryptography, secure development, change, supplier security, etc.) with robust document control.
  • Own the risk management cycle: identification, assessment, treatment plans, residual risk acceptance, and risk register maintenance.
  • Manage the communication of the ISMS with all interested parties including training, processes and documentation to employees, effective reporting of measurement against objectives to senior leadership and responding to client information security questionnaires.
  • Play a key role in the assessment, review and continuous monitoring of supplier organisations and technology partners.
  • Maintain the Incident Response Plan and runbooks; lead incident handling, forensics coordination, and postincident reviews.
  • Align security with Business Continuity and Disaster Recovery e.g., RPO/RTO requirements, backup/restore testing, resilience of critical suppliers.
  • Define and report security KPIs to the Information Security committee e.g., patch compliance, incidents, risks, phishing fail rate, incident metrics, control coverage, audit findings.
  • Work with IT, Operations, Engineering and wider business units to help identify risks and to scale good practice.
Professional skills / experience
  • 5+ years in information security with handson ownership of an ISO 27001 ISMS.
  • Proven experience delivering Cyber Essentials Plus from scoping through remediation and assessment with an IASME accredited assessor.
  • Industry certification such as ISO27001 Lead Implementer or Lead Auditor, CISSP, CISM, CCSP, NCSC CCP.
  • Strong grasp of ISO/IEC 27001:2022 & 27002:2022 controls, risk management, internal audit, and management review.
  • Able to translate security risk into business impact and influence stakeholders at all levels.
Personal Qualities
  • Problem solver.
  • Great with people, can build trust and rapport across the entire organisation.
  • Good communicator with clients and internally.
  • Team player commitment and flexible.
  • Ability to prioritise and quickly resolve issues.
  • Attention to detail.
Seniority level
  • Mid-Senior level
Employment type
  • Full-time
Job function
  • Other
Industries
  • IT Services and IT Consulting
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Manager
Information Security Manager

Altraize • Mumbai

On-site
Deputy General Manager-GRC
Deputy General Manager-GRC

SupportFinity™ • Ahmedabad District

On-site
INR 1,200,000 - 2,000,000
Information Security Manager
Information Security Manager

Rahi Platform Technologies • Pune District

On-site
INR 1,000,000 - 1,500,000
ISMS Compliance - Manager
ISMS Compliance - Manager

Quest Global • Bengaluru

On-site
INR 2,800,000 - 4,200,000
Manager - Information Security
Manager - Information Security

Infosys • Maharashtra

On-site
INR 1,800,000 - 3,400,000
Manager - Information Security
Manager - Information Security

Infosys • Pune District

On-site
INR 1,000,000 - 1,500,000
Technical Architect
Technical Architect

ESP Engineered • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Information Security - Manager
Information Security - Manager

Promaynov Advisory Services Pvt. Ltd • Delhi

On-site
INR 3,500,000 - 5,500,000
InfoSec Manager
InfoSec Manager

Blankstate • Dadri

On-site
INR 3,500,000 - 6,500,000
Private Health Insurance
Paid Time Off
Work From Home
+1
InfoSec Executive
InfoSec Executive

QualityKiosk Technologies • Navi Mumbai

On-site
INR <4,500,000