InfoSec Executive

QualityKiosk Technologies

Navi Mumbai

On-site

INR 2,500,000 - 4,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

QualityKiosk Technologies is seeking an Information Security Executive to oversee and manage information security programs, including ISO 27001, PIMS, and SOC 2 compliance. The role involves leading audits, enhancing employee awareness, and ensuring the protection of critical data and systems.

The ideal candidate holds ISO 27001:2022 Lead Auditor or Lead Implementer certification, plus credentials such as CISSP/CISM/CISA, and can guide cross-functional teams in risk-based security initiatives.

Qualifications

  • Minimum of 3 years of information security experience.
  • Experience in ISO 27001, PIMS, and SOC 2 programs.
  • ISO 27001:2022 Lead Auditor (LA) or Lead Implementer (LI) certification is required.
  • CISSP, CISM, or CISA certifications preferred.

Responsibilities

  • Manage ISO 27001 ISMS development, implementation and audits.
  • Oversee PIMS implementation and privacy compliance.
  • Lead SOC 2 program development and coordinate audits.
  • Develop and deliver information security awareness training.
  • Plan and conduct internal audits and report non-compliance.
  • Lead incident response and post-incident reviews.
  • Develop and maintain Third-Party Risk Management framework.
  • Ensure OWASP and secure SDLC practices in application security reviews.

Skills

Information security principles
Leadership
Cross-functional collaboration
Security training

Job description

Job Summary:

We are seeking an Information Security Executive to oversee and manage our organization's information security programs, including ISO 27001, PIMS, and SOC 2 compliance. The ideal candidate will be responsible for conducting internal audits, enhancing employee awareness, and ensuring the security of our information systems. The candidate must be certified as an ISO 27001 Lead Auditor (LA) or Lead Implementer (LI).

Key Responsibilities:

1) ISO 27001 Management:

  • Develop, implement, and maintain the ISO 27001 Information Security Management System (ISMS).
  • Conduct regular risk assessments and ensure compliance with ISO 27001 standards.
  • Lead the preparation and execution of ISO 27001 certification and surveillance audits.

2) PIMS (Privacy Information Management System):

  • Oversee the implementation and management of PIMS in accordance with relevant privacy regulations.
  • Ensure the protection of personal data and compliance with data privacy laws.

3) SOC 2 Compliance:

  • Manage the SOC 2 compliance program, including the development and maintenance of controls.
  • Coordinate with external auditors for SOC 2 Type I and Type II audits.

4) Employee Awareness:

  • Develop and deliver information security awareness training programs for employees.
  • Promote a culture of security awareness and best practices across the organization.

5) Internal Audits:

  • Plan and conduct internal audits to assess the effectiveness of the ISMS and other security controls.
  • Identify and report on areas of non-compliance and recommend corrective actions.
  • Lead the incident response team in identifying, managing, and mitigating security incidents.
  • Conduct post-incident reviews and implement lessons learned.

7) Third-Party Risk Management (TPRM):

  • Develop and maintain a TPRM framework to assess and monitor vendor security posture.
  • Conduct due diligence and risk assessments for new and existing third-party vendors.

8) Application Security Review:

  • Ensure compliance with OWASP standards and secure SDLC practices.
  • Conduct due diligence and risk assessments for new and existing third-party vendors.
Experience:
  • Minimum of 3 years of experience in information security role
  • Experience in managing ISO 27001, PIMS, and SOC 2 compliance programs.
Skills & Certifications:
  • Strong knowledge of information security principles, practices, and technologies.
  • Excellent communication and leadership skills.
  • Ability to work collaboratively with cross-functional teams.
  • ISO 27001:2022 Lead Auditor (LA) or Lead Implementer (LI) certification is required.
  • Additional certifications such as CISSP, CISM, or CISA are preferred.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

InfoSec Executive
InfoSec Executive

Qualitykiosk Technologies • Thane, Mumbai

On-site
INR 1,500,000 - 2,500,000
Admin
Admin

OneMetric • Gurugram District

On-site
INR 800,000 - 1,200,000
Information Security Manager
Information Security Manager

Altraize • Mumbai

On-site
Information Security Manager
Information Security Manager

Rahi Platform Technologies • Pune District

On-site
INR 1,000,000 - 1,500,000
Information Security Officer
Information Security Officer

Indutch Composites Technology • Vadodara

On-site
INR 600,000 - 1,000,000
Information Security - Manager
Information Security - Manager

Promaynov Advisory Services Pvt. Ltd • Delhi

On-site
INR 1,800,000 - 2,400,000
Deputy General Manager-GRC
Deputy General Manager-GRC

SupportFinity™ • Ahmedabad District

On-site
INR 1,200,000 - 2,000,000
Security, Risk & Compliance Lead
Security, Risk & Compliance Lead

RedDoorz • Dadri

On-site
INR 2,400,000 - 4,800,000
Compliance Associate - (ISO- Implementation)
Compliance Associate - (ISO- Implementation)

Iamops • Surat, Pune District

On-site
INR 600,000 - 900,000
Technical Architect
Technical Architect

ESP Engineered • Hyderabad

On-site
INR 1,000,000 - 1,500,000