Manager - Information Security

Ashok Maheshwary & Associates

Gurugram District

Hybrid

INR 2,000,000 - 3,800,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Ashok Maheshwary & Associates seeks an Information Security Manager to lead the ISMS, align with ISO 27001/27002, SOC 2, HIPAA, and GDPR, and drive security across cloud and hybrid environments. You will work with leadership, auditors, and engineers to strengthen cybersecurity posture.

Location is Pan India with 5 days WFO/Hybrid work mode. The role requires collaboration with stakeholders and guidance on governance, risk, and compliance initiatives.

Qualifications

  • Requires strong ISMS background with hands-on experience in ISO 27001/27002 and related frameworks.
  • Experience leading audits and certifications (ISO 27001, SOC 2) and collaborating with auditors.
  • Excellent ability to translate security concepts to non-technical stakeholders.

Responsibilities

  • Lead the organization's information security program and ISMS improvements.
  • Ensure compliance with ISO 27001, 27002, SOC 2, HIPAA, GDPR and privacy laws.
  • Coordinate internal/external audits and close audit findings.
  • Manage cloud, on-premise, and hybrid security across technology functions.
  • Develop security policies, standards, procedures, and controls.
  • Mentor teams on governance, risk, and best practices.

Skills

ISMS management
ISO 27001/27002
SOC 2, HIPAA, GDPR
Cloud security (Azure, IaaS)
Governance & risk management
Stakeholder management
Communication skills

Education

Bachelor's degree in Information Security or related
Certifications such as CISSP/CISM/ISO 27001 Lead Implementer/Auditor/CISA/CCSP

Tools

Azure security tools
SOC auditing tools

Job description

Job Summary

The Information Security Manager will be responsible for managing and continuously improving the organizations Information Security Management System (ISMS), ensuring compliance with globally recognized security frameworks and regulatory requirements. The role requires a strong technical security background and hands-on experience with ISO 27001/27002, SOC 2, HIPAA, GDPR, and cloud security environments, including Azure and IaaS infrastructures.

The Manager will work closely with leadership, technology teams, auditors, business stakeholders, and clients to strengthen the overall cybersecurity posture while enabling secure and scalable product development and business growth for a leading US-based technology client.

Location and Work Mode

Location: Pan India

Work Mode: 5 days WFO/Hybrid

Responsibilities
Information Security Governance Compliance
  • Support the implementation, maintenance, and continuous improvement of the organizations cybersecurity program.
  • Manage and enhance the Information Security Management System (ISMS) in line with ISO 27001 requirements.
  • Develop, review, and maintain information security policies, standards, procedures, and controls.
  • Ensure compliance with information security regulations, frameworks, and certifications including ISO 27001, ISO 27002, SOC 2, HIPAA, GDPR, and applicable privacy laws.
  • Coordinate internal and external audits and act as the primary liaison with auditors and certification bodies.
  • Track remediation activities and ensure timely closure of audit findings and security gaps.
Security Operations Risk Management
  • Conduct risk assessments, control reviews, and security gap analyses across technology and business functions.
  • Identify, assess, and mitigate cybersecurity risks affecting business operations and customer environments.
  • Partner with technology teams to secure cloud, on-premise, and hybrid infrastructure environments.
  • Support incident management, vulnerability management, and security improvement initiatives.
  • Stay informed on emerging threats, cybersecurity trends, regulatory changes, and industry best practices.
Security Awareness Stakeholder Management
  • Manage and enhance the organizations security awareness and training programs.
  • Promote security culture across departments through regular communication, education, and awareness initiatives.
  • Collaborate closely with engineering, product, and operations teams to ensure security is integrated into processes and solutions.
  • Communicate security concepts, risks, and recommendations effectively to both technical and non-technical stakeholders.
  • Build strong working relationships with internal teams, external partners, customers, and auditors.
Documentation Reporting
  • Develop and maintain clear, practical, and user-friendly security documentation.
  • Prepare dashboards, compliance reports, risk assessments, and executive-level security updates.
  • Monitor security program effectiveness through metrics, KPIs, and continuous improvement activities.
Leadership Project Management
  • Lead information security initiatives and compliance projects across multiple business areas.
  • Drive organizational security objectives while balancing business growth and operational requirements, provide training and guidance to other IT audits team members.
  • Mentor and guide teams on security best practices, governance standards, and compliance requirements.
  • Support after-hours activities when required to address security incidents, audits, or global stakeholder requirements.
Qualifications
  • Bachelors degree in Information Security, Computer Science, Information Technology, Cybersecurity, or a related discipline.
  • Relevant certifications such as CISSP, CISM, ISO 27001 Lead Implementer/Auditor, CISA, CCSP, or equivalent are highly preferred.
Skills
  • Strong knowledge of ISO 27001, ISO 27002, SOC 2 Controls, HIPAA, GDPR (EU UK), and US privacy regulations.
  • Experience managing Information Security Management Systems (ISMS) Strong understanding of cloud security, particularly Azure and IaaS environments.
  • Knowledge of security governance, risk management, access control, security auditing, and cybersecurity best practices.
  • Excellent verbal and written communication skills explain technical concepts to non-technical audiences.
  • Strong analytical, problem-solving, and stakeholder management capabilities. Ability to manage multiple priorities in a fast-paced and evolving environment.
Experience
  • 6+ years of experience in Information Security, Cybersecurity, IT Risk, Governance, Risk Compliance (GRC), or related functions.
  • Demonstrated experience leading information security and compliance initiatives.
  • Experience working with global or international organizations.
  • Proven track record of supporting audits and certifications such as ISO 27001 and SOC 2.
  • Experience collaborating with engineering, product, and infrastructure teams in technology-driven environments.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Manager - Information Security
Manager - Information Security

DS Group • Dadri

On-site
INR 2,800,000 - 5,400,000
Manager - Information Security
Manager - Information Security

Infosys • Maharashtra

On-site
INR 1,500,000 - 2,100,000
Information Security Manager | JP Nagar, Bangalore | Fulltime
Information Security Manager | JP Nagar, Bangalore | Fulltime

Two95 International Inc. • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Senior Manager Information Security
Senior Manager Information Security

InterGlobe Enterprises • Gurugram District

On-site
INR 1,800,000 - 2,800,000
Information Security Manager
Information Security Manager

Shell Infotech • Hyderabad

On-site
INR 180,000 - 300,000
Information Security Manager
Information Security Manager

Altraize • Mumbai

On-site
Information Security Manager
Information Security Manager

Focaloid Technologies • Ernakulam

On-site
INR 1,200,000 - 1,900,000
Project Manager-Info Sec
Project Manager-Info Sec

Acuity Analytics • Gurugram District

On-site
INR 2,500,000 - 4,500,000
Information Technology Security Manager
Information Technology Security Manager

Advantmed India LLP • Pune District

Hybrid
INR 2,000,000 - 4,000,000
Information Systems Security Manager
Information Systems Security Manager

IDFC FIRST Bank • Navi Mumbai

On-site
INR 1,800,000 - 3,200,000