Information Security Manager

Focaloid Technologies Pvt. Ltd.

Ernakulam

On-site

INR 2,000,000 - 3,200,000

Full time

13 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Focaloid Technologies Pvt. Ltd. is seeking an Information Security Manager to own and operate the ISO/IEC 27001:2022 ISMS and strengthen security across technical and governance domains. You will drive security controls, audits, and customer assurance with cross-functional teams.

You will manage VAPT, cloud security (AWS/Azure), and secure SDLC practices, while evolving AI security and incident response capabilities to mitigate risks and protect data.

Qualifications

  • Experience implementing ISO/IEC 27001:2022 ISMS.
  • Experience managing risk registers, SoA, audits and remediation.
  • Ability to drive security controls across GRC and technical security.
  • Experience responding to customer security questionnaires and due diligence.

Responsibilities

  • Operate ISO/IEC 27001:2022 ISMS and drive continuous improvement.
  • Manage policies, risk assessments, SoA, audits, and audit readiness.
  • Lead VAPT, vulnerability management, remediation, and retesting.
  • Review security in MS 365, Entra ID, AWS/Azure; enforce least privilege.
  • Coordinate incident triage, RCA, and remediation actions.
  • Handle customer security questionnaires and third-party risk assessments.
  • Drive Secure SDLC, secure coding, SCA, and CI/CD security controls.

Skills

ISO/IEC 27001:2022
ISMS
VAPT
Microsoft 365 security
Entra ID security
AWS/Azure security
Incident response
Cloud security
Secure SDLC
AI security

Education

Bachelor's degree in IT/CS

Tools

Microsoft 365
Entra ID

Job description

We are looking for a hands-on and execution-oriented Information Security Manager to take end-to-end ownership of the organization's ISO/IEC 27001:2022 Information Security Management System (ISMS) while strengthening the organization's technical security, customer security assurance, Secure SDLC, and AI security practices.

This is not a purely compliance or documentation-focused role. The successful candidate will be responsible for ensuring that information security controls are continuously implemented, monitored, measured, evidenced, and improved throughout the year.

The ideal candidate should be comfortable operating across GRC and technical security, independently driving security initiatives, managing audits and remediation, responding to customer security requirements, and translating security requirements into practical controls.

Key Responsibilities
  • ISMS & ISO 27001 operations (40%) — own and continuously operate the ISO/IEC 27001:2022 ISMS.
  • Manage policies, procedures, registers, risk assessments, SoA, and compliance obligations.
  • Drive risk identification, treatment, monitoring, escalation, and closure.
  • Define and track ISMS objectives, KPIs, corrective actions, and continuous improvement.
  • Coordinate Management Reviews, internal audits, surveillance/recertification audits, and audit readiness.
  • Drive security awareness, training, onboarding awareness, and phishing simulations.
  • Hands-on technical security (25%) — manage VAPT, vulnerability scanning, remediation, and retesting.
  • Review security configurations across Microsoft 365, Entra ID, AWS/Azure, and access controls.
  • Drive least privilege, patch compliance, and periodic access reviews.
  • Coordinate security incident triage, containment, RCA, corrective actions, and escalation.
  • Support CERT-In reporting, security monitoring, threat intelligence, and control improvements.
  • Customer security assurance & third-party risk (20%) — own customer security questionnaires, assessments, due diligence, and audits.
  • Conduct vendor and third-party security risk assessments.
  • Review security requirements in NDAs, contracts, DPAs, and outsourcing arrangements.
  • Support Sales/AM teams in customer security discussions and pre-sales engagements.
  • Maintain security evidence, certification information, and a reusable security questionnaire/evidence library.
  • Secure SDLC & AI security (15%) — drive Secure SDLC, secure coding, and application security practices.
  • Support SAST, SCA, secret scanning, vulnerability management, and CI/CD security controls.
  • Partner with engineering teams on security findings, project risks, architecture, and access reviews.
  • Assess AI/LLM security risks, including prompt injection, data disclosure, excessive privileges, insecure outputs, and unauthorized access.
  • Promote recognized AI and application security best practices.
Required Skills
  • 5-8+ years of relevant experience in Information Security, Cybersecurity, GRC, ISMS, or a closely related domain.
  • Strong hands-on experience in ISO/IEC 27001:2022 implementation and ISMS operations.
  • Practical experience managing information security risk registers, risk assessments and treatment plans, Statement of Applicability (SoA), internal audits, management reviews, corrective actions, and audit readiness.
  • Strong practical understanding of information security controls and their implementation within an organization.
  • Experience in VAPT, vulnerability management, remediation tracking, and security findings management.
  • Working knowledge of Microsoft 365 and Microsoft Entra ID security.
  • Good understanding of cloud security across AWS and/or Azure.
  • Experience coordinating information security incidents and response activities.
  • Experience responding to customer security questionnaires, assessments, and security due diligence requests.
  • Good understanding of vendor and third-party security risk assessments.
  • Understanding of Secure SDLC and application security practices.
  • Exposure to SAST, SCA, secret scanning, CI/CD security controls, or similar application security practices.
  • Awareness of emerging AI/LLM security risks.
  • Strong documentation, analytical, communication, stakeholder-management, and problem-solving skills.
Good to Have
  • CISSP / CISM / ISO 27001 Lead Implementer / ISO 27001 Lead Auditor or equivalent certification.
  • Experience working in an IT services, software development, product engineering, or technology consulting organization.
  • Experience supporting enterprise customers during security audits and due-diligence exercises.
  • Knowledge of CERT-In and Indian information security compliance requirements.
  • Knowledge of security frameworks such as CIS Controls, NIST CSF, OWASP, and OWASP ASVS / Top 10.
  • Exposure to cloud security posture management and identity/security tools.
  • Experience with AI Security, GenAI Security, or LLM application security assessments.
  • Experience with enterprise security platforms, vulnerability management tools, SIEM, or security monitoring solutions.
Ideal Candidate

The ideal candidate is hands-on and execution-oriented rather than purely documentation-focused, comfortable working across both GRC and technical security, and capable of independently driving security actions with IT, Engineering, Cloud, and Business teams. They are confident interacting directly with enterprise customers and external auditors, comfortable managing audits, evidence, remediation, risks, and deadlines throughout the year, and able to translate security and compliance requirements into practical, measurable controls.

They are strong in stakeholder management and cross-functional collaboration; analytical, structured, and detail-oriented, identifying security gaps proactively; curious about emerging security risks across cloud, applications, and AI; and comfortable taking ownership rather than waiting for instructions.

What we offer
  • End-to-end ownership of an established ISO/IEC 27001:2022 ISMS, and a key role in strengthening the organization's overall information security maturity.
  • Exposure across ISMS, GRC, technical security, cloud security, application security, customer assurance, third-party risk, Secure SDLC, and emerging AI security — a broad and impactful information security profile.
  • Significant ownership and visibility if you enjoy turning security requirements into real-world controls, driving continuous improvement, and working closely with both technology and business teams.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Manager
Information Security Manager

Focaloid Technologies • Ernakulam

On-site
INR 1,200,000 - 1,900,000
Information Security Officer
Information Security Officer

Indutch Composites Technology • Vadodara

On-site
INR 600,000 - 1,000,000
Information Security Manager
Information Security Manager

Altraize • Mumbai

On-site
GAIN Central IT - Information Security Manager
GAIN Central IT - Information Security Manager

GAIN • Maharashtra

On-site
INR 1,000,000 - 1,500,000
Compliance Associate - ISO 27001 Implementation
Compliance Associate - ISO 27001 Implementation

IAMOPS | Growth Fanatics DevOps • Pune District

On-site
INR 800,000 - 1,400,000
Deputy General Manager-GRC
Deputy General Manager-GRC

SupportFinity™ • Ahmedabad District

On-site
INR 1,200,000 - 2,000,000
Technical Architect
Technical Architect

ESP Engineered • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Senior Manager Information Security
Senior Manager Information Security

InterGlobe Enterprises • Gurugram District

On-site
INR 1,800,000 - 2,800,000
Information Security Manager / GRC Lead
Information Security Manager / GRC Lead

Keka Technologies Private Limited • Bengaluru

On-site
INR 1,200,000 - 1,800,000
IT Security & Compliance Engineer
IT Security & Compliance Engineer

Rapyuta Robotics Co. • Chennai District

On-site
INR 2,000,000 - 4,000,000
Competitive salary
Great team culture
Challenging projects