Overview
About the company
Consilio stands as the global leader in eDiscovery, document review, flexible legal talent, and legal advisory & transformation consulting services. With its Consilio Complete suite of capabilities, the company empowers multinational law firms and corporations using innovative software, cost-effective managed services, and deep legal and regulatory industryexpertise.
Job Role – Manager, Information Security (Privacy & Compliance)
Work Experience – 10+ years in Information Security, Governance, Risk, Compliance, Audit, Privacy, or related domains
Work Location – Hyderabad. (Hybrid) Working from office at least 3 days a week, or as per company policy
Employment Type: Full-time
Work Hours: IST / UK business hours, with flexibility to support global stakeholders and audits
Description:
- The candidate is expected to lead a team within Information Security, Privacy and Compliance vertical and manage internal, external, client, and certification audit requirements.
- The candidate is expected to manage enterprise security certification programs such as ISO 27001, ISO 27701, SOC 2 Type II, HITRUST, NIST 800-171, Cyber Essentials Plus, IRAP, and other applicable frameworks.
- The candidate is expected to lead compliance initiatives in a global organization by coordinating with Legal, IT, Privacy, Risk, Procurement, HR, Operations, Product, and business stakeholders.
- The candidate should be able to improve compliance operations through structured workflows, dashboards, reusable repositories, evidence readiness, responsible AI usage, and process automation wherever appropriate.
- The candidate is expected to bring strong team management skills, provide clear ownership, coach team members, improve quality, and build backup subject matter expertise across critical domains.
- The candidate should have excellent written and verbal communication skills, strong presentation ability, and the confidence to engage with auditors, clients, senior leaders, vendors, and global stakeholders.
- The candidate should be comfortable working in a fast-paced, deadline-driven, collaborative, and global environment with strong ownership and escalation discipline
Responsibilities
Governance, Risk & Compliance
- Lead Information Security governance and compliance activities aligned to global business operations and approved security policies.
- Assess security control effectiveness and provide practical recommendations for continual improvement.
- Maintain compliance trackers, audit calendars, risk summaries, dashboards, evidence repositories, and leadership-ready status updates.
Audit & Certification Management
- Plan, coordinate, and manage internal audits, client audits, certification audits, surveillance audits, assurance assessments, and remediation activities.
- Lead enterprise security certification programs including ISO 27001, ISO 27701, SOC 2 Type II, HITRUST, NIST 800-171, Cyber Essentials Plus, IRAP, and similar standards.
- Coordinate audit scope, evidence requests, control validation, walkthroughs, auditor interactions, management responses, findings, and closure evidence.
- Track audit observations and corrective actions through closure with clear ownership, timelines, risk visibility, and validation of final evidence.
Client Security Requests & Assurance
- Participate in complex client calls and explain security certifications, audit posture, data protection controls, incident management, AI governance, BC/DR, and compliance practices clearly.
Privacy Support
- Support privacy and data protection initiatives including DPIAs/PIAs, data handling reviews, records of processing, vendor privacy reviews, and audit support requirements.
- Contribute to compliance readiness for applicable laws and frameworks such as GDPR, HIPAA, CCPA, India DPDP Act, NIST, and other business-relevant requirements.
- Partner with Legal, Privacy, Risk, and business teams to support security and privacy impact assessments, remediation activities, and risk reporting.
Incident Response & Business InfoSec Support
- Provide oversight and governance support for enterprise incident management, including investigation tracking, reporting, remediation, legal summaries, and closure discipline.
- Support business unit security posture reviews through virtual or onsite walkthroughs, as deemed necessary.
- Assist in implementing or improving security and compliance processes in partnership with global security, local IT, regional IT, and business operations teams.
AI Governance & Responsible AI
- Lead the implementation and continual improvement of the organization's AI Governance Program.
- Support the development and maintenance of an AI Management System aligned with ISO/IEC 42001 requirements.
- Conduct AI risk assessments and AI impact assessments for internal and client-facing AI systems.
- Work with Legal, Privacy, Technology, Product, and Business teams to ensure responsible AI adoption.
- Establish governance requirements around transparency, accountability, human oversight, explainability, and model lifecycle management.
- Support compliance initiatives related to emerging AI regulations and industry requirements.
- Participate in AI Governance Council and related oversight committees to assess AI-related risks and opportunities.
- Develop AI policies, standards, procedures, and control frameworks aligned with business objectives
Team Management & Operational Excellence
- Lead, coach, and manage a team supporting audits, certifications, client requests, privacy, compliance, incident response, and risk activities.
- Set clear role expectations, delivery timelines, quality standards, escalation norms, and ownership models for the team.
- Build and maintain workflows, SOPs, knowledge repositories, dashboards, response libraries, and reusable artifacts for all areas of responsibility.
- Encourage proactive communication, documentation discipline, accountability, collaboration, and continuous improvement within the team.
Qualifications
Bachelor’s degree in computer science, Information Technology, Information Security, Information Assurance, or a related field.
- 10+ years of experience in information security, governance, risk, compliance, audit, privacy, or related domains.
- 3-5 years of people management or team leadership experience in a global organization or GCC environment.
- Proven experience leading or supporting internal audits, external audits, client audits, certification audits, evidence management, control testing, and findings remediation.
- Practical knowledge of cyber security and privacy frameworks and standards.
- Strong stakeholder management skills with the ability to work across Legal, IT, Privacy, Risk, Procurement, HR, Operations, Product, Client Services, and global leadership teams.
- Excellent written and verbal communication skills, including ability to explain complex security and compliance topics in a clear and business-friendly manner.
- Experience with GRC platforms, audit trackers, evidence repositories, reporting dashboards, workflow automation, or knowledge management tools is preferred.
- Ability to use AI-enabled productivity tools responsibly for drafting, summarization, response preparation, reporting, and operational efficiency while protecting confidentiality and accuracy.
Preferred Certifications:
- CISSP, CISM, CISA, ISO 27001 Lead Auditor / Lead Implementer, ISO 42001 Lead Auditor / Lead Implementer, CIPM /CIPP, HITRUST CCSFP, or equivalent audit, privacy, security, or risk certification.
Why Join Us:
Be part of a collaborative and innovative work environment.
Opportunity for professional growth and development.
Competitive salary and benefits package.
Contribute to shaping the future of our software development processes.
Consilio’s True North Values
- Client Experience| Listen for the "why".Clearly define success. Be accountable. Go the extra distance to create moments that matter.
- Collaboration| Treat everyone with respect. Welcome diverse views. Partner acrossgeography, generations, and teams. Rally around final decisions.
- Innovation| Always be curious (ABC).Challenge the statusquo. Experiment and fail forward.Buildfor the future.
- Grit| Focus on what matters. Work with passion and persistence. Think like an owner. Deliver resultsyou’reproudof.
Consilio, LLC isan EEO/Affirmative Action Employer and does not discriminateon the basis ofrace, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status,disabilityor any other legally protected status.