Information Security Manager

FCI CCM, Inc.

Dadri

On-site

INR 2,500,000 - 4,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Friends Color Images Pvt Ltd is seeking an Information Security Manager to lead governance, risk, and compliance across IT, cloud, product, and plant systems. The role demands hands-on ownership and collaboration with Engineering, DevOps, HR, Operations, and Management to deliver measurable security outcomes.

The candidate will drive ISO 27001, SOC 2, PCI DSS, and GDPR alignment, manage audits and CAPAs, and oversee security operations, IAM, cloud security, and secure SDLC practices within a

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related discipline.
  • 6–10 years of hands-on experience in information security, cybersecurity operations, and risk, compliance, and audits.
  • Experience handling client data and customer-driven security requirements; prior exposure to manufacturing/plant/OT is a plus.
  • Certifications such as CISSP / CISM and cloud security certifications are preferred.

Responsibilities

  • Develop and maintain information security governance, ISMS, and policies aligned with ISO 27001.
  • Lead enterprise risk assessments, audits, and regulatory compliance across IT, cloud, product, and plant systems.
  • Oversee security operations including SIEM, threat detection, and incident response; drive DR/BCP readiness.
  • Coordinate security testing, vulnerability management, secure SDLC, and product security for internal and third‑party systems.
  • Drive cloud security programs and certifications (ISO 27001, SOC 2) and ensure data protection across environments.

Skills

Information security governance
Risk management
Security operations
Incident response

Education

Bachelor’s degree in Computer Science or related field

Tools

ISO 27001
SOC 2
PCI DSS

Job description

Friends Color Images Pvt Ltd | Full time

  • Weekly Off 5 Day working with Saturday and Sunday off
  • Work Experience 6-8 Years
  • City Noida
  • Country India
  • Postal Code 201303
Job Description

Broad Function:

The Information Security Manager will be responsible for developing, implementing, and maintaining the organization’s information security strategy, risk framework, policies, and controls. This role requires deep expertise in cyber operations, audit management, risk evaluation, and compliance with security standards such as ISO 27001, SOC 2, and NIST. This is not a coordination-only role.
The role demands hands‑on ownershipto get things done end‑to‑endby working closely with Engineering, DevOps, IT, HR, Operations, and Management. The primary objective of this role is to deliver measurable security outcomes, including certifications, audit closures, hardened systems, and sustained compliance.

1. Information Security Governance & Policy Management:

  • Define, develop, implement, and continuously improve information security policies, standards, procedures, and guidelines.
  • Own and maintain the Information Security Management System (ISMS) aligned with ISO 27001.
  • Establish governance frameworks to ensure consistent security implementation across:
  • Corporate IT
  • Cloud infrastructure
  • Ensure alignment with ISO 27001, SOC 2, PCI DSS, GDPR, and client-specific security requirements.
  • Act as the primary point of contact for information security governance across business units.
2. Risk Management, Compliance & Audit Ownership:
  • Conduct periodic enterprise risk assessments, threat modeling, and vulnerability assessments across IT, cloud, product, and plant systems.
  • Maintain and continuously update:
  • Asset inventories
  • Control matrices
  • Lead and independently manage:
  • ISO 27001 certification and surveillance audits
  • PCI DSS compliance assessments
  • Client and partner security audits
  • Coordinate audit schedules, evidence collection, documentation, and stakeholder interactions.
  • Track, manage, and ensure timely closure of non‑conformities (NCs), observations, and CAPAs.
  • Ensure continuous compliance with regulatory, contractual, and customer‑driven security obligations.
3. Security Operations, Monitoring & Tooling:
  • Oversee day‑to‑day security operations including:
  • SIEM monitoring
  • Threat detection and alerting
  • Collaborate with IT and infrastructure teams to strengthen:
  • Network security
  • Identity and access management (IAM)
  • Cloud security posture
  • Evaluate, implement, and manage security tools such as:
  • Firewalls, IDS/IPS
  • EDR/antivirus solutions
  • DLP solutions
  • IAM, MFA, PAM
  • Vulnerability management tools
  • Define and monitor security KPIs and metrics for management reporting.
  • Develop, maintain, and test Incident Response Plans (IRP).
  • Lead investigation, containment, remediation, and root‑cause analysis of:
  • Security incidents
  • Data breaches
  • Coordinate incident response with internal teams, vendors, and external stakeholders when required.
  • Own and enhance Business Continuity Plans (BCP) and Disaster Recovery (DR) frameworks.
  • Conduct periodic BCP/DR drills, tabletop exercises, and cyber incident simulations.
  • Ensure readiness for ransomware, data breach, and operational disruption scenarios.
5. Product, Application & Secure SDLC:
  • Work closely with product engineering and development teams to embed security‑by‑design principles.
  • Define and enforce Secure SDLC practices, including:
  • Secure coding standards
  • Code reviews
  • Vulnerability scanning
  • Penetration testing coordination
  • Oversee application security for internally developed and third‑party products.
  • Manage vulnerability remediation lifecycle for product platforms.
  • Support customer security questionnaires, product security documentation, and assurance artifacts.
6. Cloud Security & Certifications:
  • Lead security initiatives for cloud‑hosted products and platforms (AWS / Azure/etc)
  • Drive cloud security compliance and certifications such as:
  • ISO 27001 for cloud scope
  • SOC 2 for SaaS platforms
  • Cloud‑specific best practices (CIS Benchmarks)
  • Implement and monitor:
  • Cloud IAM and least‑privilege access
  • Secure configuration baselines
  • Cloud logging and monitoring
  • Data protection and encryption controls
  • Partner with DevOps teams to integrate security into CI/CD pipelines
7. Internal Systems, Access & Data Protection:
  • Ensure secure configuration and access control for internal enterprise systems including:
  • Office 365 Suite
  • Other SaaS and internal applications
  • Conduct periodic:
  • User access reviews
  • Privileged access reviews
  • Segregation of duties (SoD) checks
  • Ensure strong data classification, handling, retention, and protection controls.
  • Support privacy and data protection requirements related to customer and employee data
8. Plant / OT Security (Where Applicable):
  • Collaborate with plant and operations teams to assess and improve OT / industrial system security.
  • Ensure basic cybersecurity controls for plant networks, devices, and access.
  • Align plant security controls with overall organizational security governance.
9. Training, Awareness & Security Culture:
  • Design and conduct periodic information security awareness programs for employees.
  • Develop training materials covering:
  • Phishing and social engineering prevention
  • Password and access hygiene
  • Data protection and privacy
  • Run simulated phishing exercises and track improvement metrics.
  • Foster a strong, organization‑wide security‑first culture
10. Strategy, Roadmap & Continuous Improvement:
  • Define and own the information security roadmap aligned with business and product strategy.
  • Track emerging cyber threats, vulnerabilities, regulatory updates, and industry trends.
  • Recommend and implement continuous improvements to security posture.
  • Lead evaluation and rollout of new security tools, technologies, and frameworks.
  • Provide regular security posture updates to senior management.
Requirements

Desired Qualifications & Experience:

Education:

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related discipline.
Experience:
  • 6–10 years of hands‑on experience in:
  • Information security
  • Cybersecurity operations
  • Risk, compliance, and audit management
  • Strong experience working in product/SaaS organizations.
  • Experience handling client data and customer‑driven security requirements.
  • Prior exposure to manufacturing/plant or OT environments is a plus
Certifications (Preferred):
  • CISSP / CISM
  • ISO 27001 Lead Implementer or Lead Auditor
  • Cloud security certifications (AWS Security Specialty, Azure Security Engineer, etc.) – good to have
  • CEH (Certified Ethical Hacker)/ CompTIA Security+ ( good to have)
Technical & Functional Expertise:
  • Information security governance and ISMS
  • ISO 27001, SOC 2, PCI DSS frameworks
  • Risk assessment and mitigation
  • Security audits and compliance operations
  • Application, network, endpoint, and cloud security
  • Incident response and BCP/DR
  • Secure SDLC and product security
Soft Skills:
  • Strong communication and documentation skills
  • Ability to work cross‑functionally with IT, product, engineering, and business teams
  • Proven ability to manage audits independently and external stakeholders
  • Strong analytical, problem‑solving, and decision‑making skills
The company offers a range of employee benefits including:
  • Cashless medical insurance for employees, spouses, and children
  • Accidental insurance coverage
  • Life insurance coverage
  • Retirement benefits including Provident Fund (PF) and Gratuity
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager - OT Cyber CoE
Manager - OT Cyber CoE

diageo • India

On-site
INR 2,500,000 - 4,500,000
Senior Cyber Security Admin- L2
Senior Cyber Security Admin- L2

VIRGINIA TRANSFORMER INDIA PVT. LTD. • Delhi

On-site
INR 7,226,000 - 10,841,000
SOC Engineer
SOC Engineer

Mintskill HR Solutions LLP • Mumbai

On-site
INR 600,000 - 1,000,000
OT Security Operations Manager
OT Security Operations Manager

Diageo • Bengaluru

On-site
INR 400,000 - 700,000
IN_Manager_OT Cybersecurity_Cyber in Emerging Technology_Advisory_Bangalore
IN_Manager_OT Cybersecurity_Cyber in Emerging Technology_Advisory_Bangalore

PwC India • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Information Security Manager
Information Security Manager

Rahi Platform Technologies • Pune District

On-site
INR 1,000,000 - 1,500,000
Information Technology Security Manager
Information Technology Security Manager

Accops • Pune District

On-site
INR 4,000,000 - 6,500,000
Senior Cybersecurity Specialist
Senior Cybersecurity Specialist

BCE Global Tech • Bengaluru

On-site
INR 300,000 - 600,000
Assistant Manager - OT Security
Assistant Manager - OT Security

Data Security Council of India • India

On-site
INR 800,000 - 1,200,000
Information Security - Manager
Information Security - Manager

Promaynov Advisory Services Pvt. Ltd • Delhi

On-site
INR 3,500,000 - 5,500,000