InfoSec Manager

Blankstate

Dadri

On-site

INR 3,500,000 - 6,500,000

Full time

45 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Private Health Insurance
Paid Time Off
Work From Home
Training & Development

Job summary

Blankstate is seeking an InfoSec Manager to run day-to-day Governance, Risk, and Compliance (GRC) activities under GDS, including security documentation, client security reviews, and enterprise InfoSec processes. Strategic direction sits with the Fractional CISO, while the Manager ensures that security and compliance processes are executed effectively across the business.

This role is the primary operational owner for InfoSec and GRC when enterprise clients request security reviews,

Qualifications

  • Strong understanding of GRC, security governance, and risk management.
  • Experience preparing, organizing, and presenting security evidence for enterprise clients and auditors.
  • Familiarity with ISO 27001, SOC 2 and data protection requirements.

Responsibilities

  • Own the full client-facing InfoSec process from initial security request through completion and approval.
  • Manage enterprise security questionnaires, vendor assessments, compliance forms, and evidence collection.
  • Drive ISO readiness, audit preparation, and maintain the ISMS on a day-to-day basis.
  • Own GDPR and data protection activities including DPAs and DPIAs; review security/privacy clauses in contracts.
  • Maintain security materials (trust page, policies, certifications, evidence) and create a central knowledge base.
  • Escalate high-risk findings to leadership with context and recommended actions.

Skills

GRC knowledge
Security documentation
Stakeholder management
Security governance
Risk assessment
Communication skills

Tools

GCP
ISMS

Job description

We are looking for an InfoSec Manager who will run the company's day-to-day Governance, Risk, and Compliance (GRC) activities under GDS, including security documentation, client security reviews, enterprise InfoSec processes, certifications, privacy requirements, and security readiness. Strategic security direction and oversight will sit with the Fractional CISO, while the InfoSec Manager will be responsible for ensuring that agreed security and compliance processes are executed effectively across the business.

This person will become the primary operational owner for InfoSec and GRC when enterprise clients request security reviews, questionnaires, vendor assessments, certifications, contractual security information, or compliance evidence.

This role is important because the company needs a strong but practical InfoSec foundation to build client trust, demonstrate reliability, and ensure security, compliance, documentation, certifications, and data protection requirements are professionally managed. The focus is on applying security and compliance intelligently and proportionately, avoiding unnecessary process overhead or procurement blockers while maintaining appropriate risk controls.

Key Responsibilities
  • Own the full client-facing InfoSec process from initial security request through completion and approval
  • Manage enterprise security questionnaires, vendor assessments, compliance forms, procurement security documents, evidence collection, and follow-up actions
  • Drive new ISO readiness, including coordinating evidence, controls, audit preparation, remediation activities, and maintaining the ISMS on a day-to-day basis
  • Own operational GDPR and data protection activities, including DPAs, DPIAs, privacy/security assessments, and reviewing security and privacy clauses within client and vendor contracts
  • Maintain all company security materials, including trust page content, data-room documents, policies, procedures, certifications, architecture diagrams, compliance evidence, and supporting security documentation
  • Build and maintain a central InfoSec knowledge base containing approved standard responses, reusable evidence, and guidance for common enterprise security and privacy questions
  • Join client security calls when required and work with technical/data infrastructure owners to accurately explain architecture, hosting, data flows, access control, encryption, backup, logging, monitoring, incident response, and secure development practices
  • Work with leadership, engineering, infrastructure, QA, legal/privacy stakeholders, and client-facing teams to ensure security and compliance responses are accurate, consistent, proportionate, and professionally managed
  • Support new certifications, renewals, audits, assessments, recurring compliance reviews, and ongoing security evidence requests
  • Propose practical and proportionate security and compliance improvements across software development, deployment, cloud infrastructure, access management, incident response, vendor management, and client onboarding
  • Apply security and compliance controls pragmatically so that risk is appropriately managed without creating unnecessary process, slowing procurement, or introducing avoidable blockers for clients, vendors, or internal teams
  • Coordinate with team to ensure deployment environments follow approved security and compliance standards
  • Coordinate with QA and engineering for security testing, access testing, permission validation, secure SDLC evidence, and other required assurance activities
  • Maintain an InfoSec action tracker covering client requests, risks, missing evidence, audit findings, certification tasks, remediation items, owners, and completion status
  • Escalate material or high-risk security and compliance findings to the Head of GDS, or senior leadership, providing clear context, risk assessment, and recommended actions
  • Work within the strategic security direction established by the Fractional CISO while owning the day-to-day execution and continuous improvement of GRC activities under GDS
Requirements
  • Strong hands‑on experience with ISO 27001 and SOC 2, including implementation, control operation, audit preparation, evidence collection, remediation, or certification readiness
  • Practical experience with GDPR, DPAs, DPIAs, data protection requirements, privacy/security contractual clauses, and associated compliance evidence
  • Strong experience completing enterprise security questionnaires, client security assessments, vendor‑risk reviews, procurement security requirements, and related evidence requests
  • Strong understanding of GRC, application security, cloud security, data protection, enterprise security reviews, and risk management
  • Working knowledge of cloud platforms such as GCP, sufficient to confidently support enterprise security assessments and client security discussions
  • Knowledge of access control, SSO, encryption, key management, logging, monitoring, backup and recovery, incident response, vulnerability management, and secure SDLC practices
  • Ability to read and understand architecture diagrams, API flows, data‑flow diagrams, infrastructure documentation, and technical security evidence
  • Experience preparing, organizing, and presenting security and compliance evidence for enterprise clients, auditors, and assessors
  • Strong documentation, stakeholder management, and communication skills, with the ability to translate technical and compliance topics into clear business responses
  • Ability to apply security and compliance requirements pragmatically, balancing risk reduction with commercial and operational needs
  • Relevant professional certifications such as ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, CISM, or equivalent security/GRC certifications are highly valued
Benefits
  • Private Health Insurance
  • Paid Time Off
  • Work From Home
  • Training & Development
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
GAIN Central IT - Information Security Manager
GAIN Central IT - Information Security Manager

GAIN • Maharashtra

On-site
INR 1,000,000 - 1,500,000
Cybersecurity Lead - Governance, Risk & Compliance
Cybersecurity Lead - Governance, Risk & Compliance

Scybers Inc • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Opportunities for professional development
Flexible work arrangements
Supportive team culture
Cybersecurity Lead - Governance, Risk & Compliance
Cybersecurity Lead - Governance, Risk & Compliance

Scybers • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Career Growth opportunities
Innovative Environment
Flexible work arrangements
Governance, Risk & Compliance (GRC) Manager
Governance, Risk & Compliance (GRC) Manager

TeamsWork.In • India

On-site
INR 1,500,000 - 2,100,000
Information Security Manager / GRC Lead
Information Security Manager / GRC Lead

Keka Technologies Private Limited • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
Information Security & Compliance Lead
Information Security & Compliance Lead

Infra360 Solutions Pvt. Ltd. • Haryana

On-site
INR 1,000,000 - 1,500,000
Information Security Manager / GRC Lead
Information Security Manager / GRC Lead

Flamapp • India

On-site
INR 1,500,000 - 2,100,000
Information Security and Data Privacy Manager
Information Security and Data Privacy Manager

Tiger Analytics • Chennai District

Hybrid
INR 2,500,000 - 6,000,000