Role: IT Compliance - Lead ( Infrastructure, Applications & ISO Governance)
We are seeking a driven and experienced IT Security & Governance professional to strengthen security, risk management, and operational oversight across IT Infrastructure and Application domains. The role focuses on defining and tracking meaningful KPIs, improving security posture, and ensuring alignment with industry standards and best practices while enabling resilient and efficient IT operations.
The ideal candidate will have a strong foundation in IT infrastructure and application environments, including data centers, cloud platforms, networks, patch management, and enterprise systems. This role emphasizes proactive risk identification, continuous improvement, and research-driven adoption of evolving security practices, rather than audit-heavy execution.
The candidate should be capable of translating governance requirements into practical, scalable controls, driving measurable improvements across IT security, infrastructure performance, and application reliability while maintaining a balanced approach between security, compliance, and business agility.
Roles & Responsibility:
IT Security Governance & Research
- Establish and continuously evolve IT security governance frameworks aligned with ISO 27001, NIST, and CIS, with a focus on practical implementation over audit formality.
- Proactively research emerging cybersecurity threats, technologies, and best practices; translate insights into actionable security controls and improvements.
- Drive security-by-design principles across infrastructure and application landscapes.
- Partner with CIO and Regional IT leadership to embed risk-based decision making into operations.
Security Compliance & Risk Management
- Lead internal security assessments and readiness programs with a focus on risk identification and control effectiveness, not just audit closure.
- Maintain and enhance ISMS policies and standards to ensure scalability, usability, and business alignment.
- Identify gaps across infrastructure and applications and drive risk-based remediation plans.
- Oversee implementation of corrective and preventive actions (CAPA) with measurable impact on security posture.
- Act as a trusted advisor for security risk, compliance obligations, and governance strategy.
IT Infrastructure Compliance & KPI Management
- Define, monitor, and report on infrastructure KPIs across with emphasis on IT Control Failures, process deviations and policy violations,
- Data Centers Availability, uptime, environmental and operational compliance.
- Servers Performance metrics, patch levels, access control.
- Cloud Services Usage metrics, SLA adherence, cost governance, security posture.
- Backup Schedule compliance, data retention, and restoration testing.
- Network Availability, latency, throughput, firewall and switch compliance.
- Patching – OS and application patch compliance across environments.
- Vendor Contracts – Review and track compliance clauses, renewals, and SLAs.
IT Applications Compliance & KPI Oversight
- Monitor and report KPIs for business-critical applications including uptime, support SLAs, patching cadence, and performance benchmarking.
- Work with application teams to ensure data governance and secure SDLC practices.
Certifications
- Certifications such as CISSP, CISM, CISA, or CCSP or Similar IT Security related
Referred Attributes
- Experience working in mid-to-large enterprises (3000-5000 employees) with moderate to complex Global IT landscapes in Hitech or Product companies.
- Ability to effectively collaborate with global IT leadership across regions including the US, Germany, Brazil, Greece and Portugal etc
- Familiarity with NIST, CIS, ISO 27001 lifecycle, risk management principles, and internal control frameworks.
Desired Profile:
- Strongpresentation and reportingskills for technical and executive-level stakeholders.
- Excellentwritten and verbal communication.
- Highlyself-motivated and self-driven, with the ability to independently assess and remediate IT operational and compliance gaps.
- Ability to stay current withemerging technologies and regulatory trends (EU AI Act etc).
Technical skills:
Hands-on exposure to:
- IT infrastructure (Data Centers, Cloud, Network, Backup)
- Security tools (vulnerability management, SIEM, EDR, IAM)
- Familiarity with GRC platforms and ITSM tools (ServiceNow, JIRA, etc.)
- Proven ability to improve security posture while maintaining operational KPIs
Work Experience:
8–12 years of relevant experience in IT governance, compliance, or audit functions.
Educational Qualification:
Bachelor’s degree in computer science, Information Systems, or a related field.
Location:
Bangalore