Information Security Manager

Cashify

Gurugram District

On-site

INR 2,500,000 - 4,500,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Cashify is seeking an execution-focused governance professional to maintain information security, privacy, and compliance posture across ISO 27001/27701, DPDPA, ITGC, and third-party risk. The role drives audit readiness, non-conformity closure, and DPIA/contract reviews, while coordinating with government bodies and ESG reporting.

The ideal candidate has 5–6 years in infoSec/compliance, with relevant certifications and experience in R2v3 and ESG reporting.

Qualifications

  • Bachelor's degree in CS/IT/ECE essential; advanced degrees preferred.
  • ISO 27001 Lead Auditor / Lead Implementer or privacy certifications preferred.
  • 5-6 years in infoSec/compliance with third-party risk exposure.

Responsibilities

  • Maintain ISO 27001/27701 documentation and records required for compliance.
  • Lead NC closure and audit readiness activities with internal teams.
  • Create, review, and monitor process documents, SOPs, and control records.
  • Coordinate regulatory/government engagements and DPA reviews.
  • Manage third-party risk assessments and due diligence processes.
  • Implement and monitor R2v3 requirements and data sanitisation controls.
  • Ensure audit-ready evidence and ESG reporting where applicable.

Skills

Information security
Privacy
Governance
Regulatory compliance

Education

B.E./B.Tech/B.Sc. in CS/IT/ECE
M.Tech/MCA/MBA-IT/M.Sc. Cybersecurity

Job description

Role Overview

Execution-focused governance role responsible for maintaining the organization's information security, privacy, and compliance posture across ISO 27001/27701, DPDPA, ITGC, third-party risk, and R2v3 requirements. The role owns documentation, audit readiness, and the timely closure of non-conformities, coordinates with internal and regulatory/government stakeholders, and supports contract/DPA reviews, awareness training, and ESG reporting.

Key Responsibility Areas
  • ISO 27001 / 27701 Documentation: Maintain the documentation, policies, procedures, processes, and records required for ISO 27001 and ISO 27701 compliance.
  • Audits & NC Closure: Conduct internal audits, support external audits, identify gaps, and track and drive the timely closure of Non-Conformities (NCs), observations, and audit findings.
  • Process & Control Documentation: Create, review, update, and monitor process documents, SOPs, policies, and control documentation, working with process owners to implement corrective actions.
  • Regulatory & Government Coordination: Coordinate with relevant stakeholders to implement new requirements, including those arising from engagements with government and regulatory bodies such as the Department of Telecommunications
  • Third-Party Risk Management: Manage third-party risk assessments and due diligence, including responding to questionnaires, coordinating evidence, and supporting third-party audits and site visits.
  • R2v3 Responsible Recycling: Implement and maintain R2v3 (R2 Responsible Recycling Standard) requirements, including downstream due diligence, data sanitisation, secure data wiping, and applicable environmental, factory, and operational controls.
  • Evidence & Audit Readiness: Maintain audit-ready evidence and documentation across applicable compliance and operational requirements.
  • Contract & DPA Review: Review contracts, Data Processing Agreements (DPAs), and other documents from an information security and privacy perspective, including redlining where required.
  • Awareness & Training: Conduct information security and privacy awareness training for employees and relevant stakeholders.
  • ESG Reporting: Prepare and maintain ESG-related metrics, policies, documentation, and reports in line with organisational requirements.
Key Performance Indicators

ISO 27001 / 27701 documentation kept current and audit-ready
Timely closure of NCs, observations, and audit findings within SLA
Third-party risk assessments and due diligence completed within agreed TATR2v3 downstream due diligence and data-sanitization compliance maintained
Contract / DPA reviews turned around within SLA Information security and privacy awareness training coverage and completion ESG metrics and reports prepared accurately and submitted on time

Qualifications & Experience

Education: B.E./B.Tech/B.Sc. in CS/IT/ECE (essential); M.Tech/MCA/MBA-IT/M.Sc. Cybersecurity (preferred). Relevant certifications such as ISO 27001 Lead Auditor / Lead Implementer, ISO 27701, CISA, or a recognised privacy / data-protection certification (preferred).
Experience: 5-6 years with at least 3-4 years in a hands-on InfoSec/compliance role and worked on third-party risk assessments. Exposure to R2v3 and ESG reporting is an advantage.
Should have been part of at least one full ISO 27001 certification cycle.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Deputy General Manager-GRC
Deputy General Manager-GRC

SupportFinity™ • Ahmedabad District

On-site
INR 1,200,000 - 2,000,000
Information Security Manager
Information Security Manager

Altraize • Mumbai

On-site
Manager - Information Security
Manager - Information Security

DS Group • Dadri

On-site
INR 2,800,000 - 5,400,000
Information Security Analyst
Information Security Analyst

ACL Digital • Chennai District, Bengaluru

On-site
INR 600,000 - 900,000
Information Security Manager
Information Security Manager

Shell Infotech • Hyderabad

On-site
INR 180,000 - 300,000
Information Security Manager
Information Security Manager

Focaloid Technologies • Ernakulam

On-site
INR 1,200,000 - 1,900,000
Senior Manager – IT Governance
Senior Manager – IT Governance

Concept Medical • Surat

On-site
INR 4,000,000 - 7,000,000
IT security and Compliance Administrator
IT security and Compliance Administrator

Commtel Networks Limited • Mumbai

On-site
INR 1,200,000 - 1,500,000
Director - Data Privacy & Information Security
Director - Data Privacy & Information Security

Indegene • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Comprehensive health insurance
Retirement benefits
Professional development opportunities
Information Security GRC Manager
Information Security GRC Manager

Mount Talent Consulting • Mumbai

On-site
INR 3,000,000 - 5,000,000