Get more replies from employers
Send a job-specific resume in minutes.
Promaynov Advisory Services Pvt. Ltd in New Delhi seeks a Manager - Information Security to establish and manage the information security framework, lead ISO 27001 certification, and oversee audits.
The role demands hands-on security operations experience, regulatory compliance, and strong collaboration with engineering and leadership. Responsibilities include ISO lifecycle management, audit coordination, and risk governance across cloud, APIs, and on-premises systems.
Department: Technology
Reporting To: SVP - Technology
Location: New Delhi
The Manager - Information Security will be responsible for establishing and managing the organization's information security framework. The role will lead ISO 27001 certification, drive information security operations, and manage internal and external audits while ensuring compliance with applicable regulatory requirements.
The ideal candidate will have strong experience in information security operations, compliance, ISO 27001 implementation, and audit management.
Own the end-to-end ISO 27001 ISMS implementation and certification lifecycle, from gap assessment through certification and surveillance audits.
Coordinate with certification bodies and internal stakeholders to ensure audit readiness.
Track and close non-conformities and maintain audit documentation and corrective action plans.
Ensure compliance with applicable regulations, including the IT Act, DPDP Act, and CERT-In advisories.
Manage day-to-day information security operations, including threat monitoring, incident response, and vulnerability management.
Administer security tools such as SIEM, Endpoint Protection, WAF, IAM, and DLP solutions.
Define and enforce security baselines across cloud infrastructure and API environments.
Collaborate with engineering teams to integrate security practices into the software development lifecycle (DevSecOps).
Conduct periodic risk assessments and maintain a risk register with mitigation plans.
Develop, review, and maintain information security policies, standards, and procedures.
Perform security assessments for third-party vendors and partners.
Report security metrics and risk posture to senior leadership.
Plan and execute internal information security audits across systems, processes, and integrations.
Coordinate with external auditors and regulatory bodies during audit engagements.
Maintain audit trails and compliance evidence repositories.
Prepare management review reports and security posture updates for leadership.
8-10 years of experience in Information Security, including hands-on ownership of ISO 27001 implementation and audit cycles.
Strong experience in security operations, including SOC management, incident response, and vulnerability management.
Good understanding of cloud security (AWS, Azure, or GCP) and API security principles.
ISO 27001 Lead Implementer or Lead Auditor.
CISSP and/or CISM certification preferred.
Strong communication and stakeholder management skills.
Ability to work effectively with both technical teams and senior leadership.
Strong analytical, governance, and risk management capabilities.