Information Security Manager

Focaloid Technologies

Ernakulam

On-site

INR 1,200,000 - 1,900,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Focaloid Technologies in India seeks an Information Security Manager to own ISO/IEC 27001:2022 ISMS, strengthen technical security, and address customer security requirements.

You will drive audits, risk assessments, secure SDLC, and AI security, coordinating across IT, engineering and business teams, with hands-on responsibilities and stakeholder management.

Qualifications

  • 5–8+ years of relevant experience in Information Security, Cybersecurity, GRC, ISMS, or a closely related domain.
  • Strong hands‑on experience in ISO/IEC 27001:2022 implementation and ISMS operations.
  • Practical experience managing information security risk registers, risk assessments and treatment plans, SoA, internal audits, management reviews, corrective actions, and audit readiness.
  • Strong practical understanding of information security controls and their implementation within an organization.
  • Experience in VAPT, vulnerability management, remediation tracking, and security findings management.
  • Working knowledge of Microsoft 365 and Microsoft Entra ID security.
  • Good understanding of cloud security across AWS and/or Azure.
  • Experience coordinating information security incidents and response activities.
  • Experience in responding to customer security questionnaires, assessments, and security due diligence requests.
  • Good understanding of vendor and third‑party security risk assessments.
  • Understanding of Secure SDLC and application security practices.
  • Exposure to SAST, SCA, secret scanning, CI/CD security controls, or similar application security practices.
  • Awareness of emerging AI/LLM security risks.
  • Strong documentation, analytical, communication, stakeholder‑management, and problem-solving skills.

Responsibilities

  • Own and continuously operate the ISO/IEC 27001:2022 ISMS.
  • Manage policies, procedures, registers, risk assessments, SoA, and compliance obligations.
  • Drive risk identification, treatment, monitoring, escalation, and closure.
  • Define and track ISMS objectives, KPIs, corrective actions, and continuous improvement.
  • Coordinate Management Reviews, internal audits, surveillance/recertification audits, and audit readiness.
  • Drive security awareness, training, onboarding awareness, and phishing simulations.
  • Manage VAPT, vulnerability scanning, remediation, and retesting.
  • Review security configurations across Microsoft 365, Entra ID, AWS/Azure, and access controls.
  • Drive least privilege, patch compliance, and periodic access reviews.
  • Coordinate security incident triage, containment, RCA, corrective actions, and escalation.
  • Support CERT‑In reporting, security monitoring, threat intelligence, and control improvements.
  • Own customer security questionnaires, assessments, due diligence, and audits.
  • Conduct vendor and third‑party security risk assessments.
  • Review security requirements in NDAs, contracts, DPAs, and outsourcing arrangements.
  • Support Sales/AM teams in customer security discussions and pre‑sales engagements.
  • Maintain security evidence, certification information, and a reusable security questionnaire/evidence library.
  • Drive Secure SDLC, secure coding, and application security practices.
  • Support SAST, SCA, secret scanning, vulnerability management, and CI/CD security controls.
  • Partner with engineering teams on security findings, project risks, architecture, and access reviews.
  • Assess AI/LLM security risks, including prompt injection, data disclosure, excessive privileges, insecure outputs, and unauthorized access.
  • Promote recognized AI and application security best practices

Skills

ISMS implementation
ISO 27001:2022
VAPT
Microsoft 365 security
Entra ID security
AWS/Azure security
Incident response
Vendor risk assessments
Audit management
CI/CD security
SAST/SCA
AI security
GRC
Documentation

Tools

Microsoft 365
Entra ID
SIEM
Cloud security tools
Vulnerability scanners

Job description

About the Role

We are looking for a hands‑on and execution-oriented Information Security Manager to take end-to-end ownership of the organization's ISO/IEC 27001:2022 Information Security Management System (ISMS) while strengthening the organization's technical security, customer security assurance, Secure SDLC, and AI security practices.

This is not a purely compliance or documentation‑focused role. The successful candidate will be responsible for ensuring that information security controls are continuously implemented, monitored, measured, evidenced, and improved throughout the year.

The ideal candidate should be comfortable operating across GRC and technical security, independently driving security initiatives, managing audits and remediation, responding to customer security requirements, and translating security requirements into practical controls.

Key Responsibilities

1. ISMS & ISO 27001 Operations – 40%

  • Own and continuously operate the ISO/IEC 27001:2022 ISMS.
  • Manage policies, procedures, registers, risk assessments, SoA, and compliance obligations.
  • Drive risk identification, treatment, monitoring, escalation, and closure.
  • Define and track ISMS objectives, KPIs, corrective actions, and continuous improvement.
  • Coordinate Management Reviews, internal audits, surveillance/recertification audits, and audit readiness.
  • Drive security awareness, training, onboarding awareness, and phishing simulations.

2. Hands‑on Technical Security – 25%

  • Manage VAPT, vulnerability scanning, remediation, and retesting.
  • Review security configurations across Microsoft 365, Entra ID, AWS/Azure, and access controls.
  • Drive least privilege, patch compliance, and periodic access reviews.
  • Coordinate security incident triage, containment, RCA, corrective actions, and escalation.
  • Support CERT‑In reporting, security monitoring, threat intelligence, and control improvements.

3. Customer Security Assurance & Third‑Party Risk – 20%

  • Own customer security questionnaires, assessments, due diligence, and audits.
  • Conduct vendor and third‑party security risk assessments.
  • Review security requirements in NDAs, contracts, DPAs, and outsourcing arrangements.
  • Support Sales/AM teams in customer security discussions and pre‑sales engagements.
  • Maintain security evidence, certification information, and a reusable security questionnaire/evidence library.

4. Secure SDLC & AI Security – 15%

  • Drive Secure SDLC, secure coding, and application security practices.
  • Support SAST, SCA, secret scanning, vulnerability management, and CI/CD security controls.
  • Partner with engineering teams on security findings, project risks, architecture, and access reviews.
  • Assess AI/LLM security risks, including prompt injection, data disclosure, excessive privileges, insecure outputs, and unauthorized access.
  • Promote recognized AI and application security best practices

Mandatory Qualifications & Experience

  • 5–8+ years of relevant experience in Information Security, Cybersecurity, GRC, ISMS, or a closely related domain.
  • Strong hands‑on experience in ISO/IEC 27001:2022 implementation and ISMS operations.
  • Practical experience managing information security risk registers, risk assessments and treatment plans, Statement of Applicability (SoA), internal audits, management reviews, corrective actions, and audit readiness.
  • Strong practical understanding of information security controls and their implementation within an organization.
  • Experience in VAPT, vulnerability management, remediation tracking, and security findings management.
  • Working knowledge of Microsoft 365 and Microsoft Entra ID security.
  • Good understanding of cloud security across AWS and/or Azure.
  • Experience coordinating information security incidents and response activities.
  • Experience in responding to customer security questionnaires, assessments, and security due diligence requests.
  • Good understanding of vendor and third‑party security risk assessments.
  • Understanding of Secure SDLC and application security practices.
  • Exposure to SAST, SCA, secret scanning, CI/CD security controls, or similar application security practices.
  • Awareness of emerging AI/LLM security risks.
  • Strong documentation, analytical, communication, stakeholder‑management, and problem-solving skills.

Good to Have

  • CISSP / CISM / ISO 27001 Lead Implementer / ISO 27001 Lead Auditor or equivalent certification.
  • Experience working in an IT services, software development, product engineering, or technology consulting organization.
  • Experience supporting enterprise customers during security audits and due‑diligence exercises.
  • Knowledge of CERT‑In and Indian information security compliance requirements.
  • Knowledge of security frameworks such as CIS Controls, NIST CSF, OWASP, and OWASP ASVS / Top 10.
  • Exposure to cloud security posture management and identity/security tools.
  • Experience with AI Security, GenAI Security, or LLM application security assessments.
  • Experience with enterprise security platforms, vulnerability management tools, SIEM, or security monitoring solutions.
  • What We Are Looking For
  • Hands‑on and execution-oriented, rather than purely documentation‑focused.
  • Comfortable working across both GRC and technical security.
  • Capable of independently driving security actions with IT, Engineering, Cloud, and Business teams.
  • Confident interacting directly with enterprise customers and external auditors.
  • Comfortable managing audits, evidence, remediation, risks, and deadlines throughout the year.
  • Able to translate security and compliance requirements into practical and measurable controls.
  • Strong in stakeholder management and cross‑functional collaboration.
  • Analytical, structured, detail‑oriented, and capable of identifying security gaps proactively.
  • Curious about emerging security risks, particularly cloud, applications, and AI security.
  • Comfortable taking ownership rather than waiting for instructions.
  • Why Join Us?
  • This is an opportunity to take end‑to‑end ownership of an established ISO/IEC 27001:2022 ISMS and play a key role in strengthening the organization’s overall information security maturity.
  • The role provides exposure across ISMS, GRC, technical security, cloud security, application security, customer assurance, third‑party risk, Secure SDLC, and emerging AI security, making it an ideal opportunity for a security professional looking to build a broad and impactful information security profile.
  • If you enjoy turning security requirements into real‑world controls, driving continuous improvement, and working closely with both technology and business teams, this role offers significant ownership and visibility.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Officer
Information Security Officer

Indutch Composites Technology • Vadodara

On-site
INR 600,000 - 1,000,000
Information Security Manager
Information Security Manager

Altraize • Mumbai

On-site
Compliance Associate - ISO 27001 Implementation
Compliance Associate - ISO 27001 Implementation

IAMOPS | Growth Fanatics DevOps • Pune District

On-site
INR 800,000 - 1,400,000
GRC Analyst
GRC Analyst

AiVantage Inc (Global) • Ahmedabad District

On-site
INR 800,000 - 1,200,000
Information Security Manager
Information Security Manager

FCI CCM, Inc. • Dadri

On-site
INR 2,500,000 - 4,000,000
Group Head of Information Security
Group Head of Information Security

Davies Group • Pune District

On-site
INR 4,000,000 - 7,000,000
Information Security Manager / GRC Lead
Information Security Manager / GRC Lead

Keka Technologies Private Limited • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Group Head of Information Security
Group Head of Information Security

Davies • Pune District

On-site
INR 400,000 - 750,000
GAIN Central IT - Information Security Manager
GAIN Central IT - Information Security Manager

GAIN • Maharashtra

On-site
INR 1,000,000 - 1,500,000
Deputy General Manager-GRC
Deputy General Manager-GRC

SupportFinity™ • Ahmedabad District

On-site
INR 1,200,000 - 2,000,000