Manager — Information Security and Compliance

APEX Analytix

India

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

APEX Analytix is hiring a Manager for Information Security and Compliance. This role involves leading the information security and IT risk program while managing a team of analysts. You will be responsible for cloud security, compliance with US and EU regulations, and ensuring the overall security posture of the organization.

The ideal candidate has over 8 years of experience in information security and holds relevant certifications. APEX Analytix offers a dynamic environment with opportunities for professional growth.

Qualifications

  • 8+ years across information security, risk, and IT with people-management experience.
  • Deep hands-on Azure security experience including Defender and Sentinel.
  • Practical experience with Kubernetes and DevSecOps.

Responsibilities

  • Lead the information security and IT risk program.
  • Own Azure security and Microsoft 365 Defender operational aspects.
  • Drive vulnerability management and web application security testing.

Skills

Information Security Management
Azure Security
Kubernetes Security
Vulnerability Management
Regulatory Compliance
Incident Response
Team Leadership
Budget Management

Education

Bachelor's degree in Computer Science, Information Security or related field

Tools

Microsoft 365 Defender
Burp Suite
Tenable

Job description

Manager — Information Security and Compliance

At apexanalytix, we’re lifelong innovators! Since the date of our founding nearly four decades ago we’ve been consistently growing, profitable, and delivering the best procure-to-pay solutions to the world. We’re the perfect balance of established company and start‑up. You will find a unique home here.

And you’ll recognize the names of our clients. Most of them are on The Global 2000. They trust us to give them the latest in controls, audit and analytics software every day. Industry analysts consistently rank us as a top supplier management solution, and you’ll be helping build that reputation.

The Work
  • Lead the information security and IT risk program; report posture, KPIs, and incidents to the CIO and senior leadership.
  • Own Azure security — Defender for Cloud, Entra ID with Conditional Access policies (risk‑based sign‑in, device compliance, phishing‑resistant MFA / FIDO2 / passkeys, session controls, break‑glass hygiene) and PIM, Key Vault, and Azure Policy.
  • Drive the Microsoft 365 Defender suite (MDE, MDO, MDI, MDCA), Microsoft Purview (DLP, Information Protection), and Microsoft Sentinel (SIEM/SOAR).
  • Own Kubernetes and container security — admission control, image signing, runtime protection, secrets management — plus DevSecOps (SAST/DAST/SCA, IaC scanning, secure SDLC).
  • Run a comprehensive SBOM program (SPDX / CycloneDX, VEX) and supply‑chain controls aligned to SLSA and NIST SSDF.
  • Own vulnerability management on Tenable (Tenable.io / sc / WAS) — scan coverage, SLA‑driven remediation, EPSS / KEV‑based prioritization, exception workflow.
  • Drive web application security testing with Burp Suite Professional / Enterprise — authenticated scans, manual exploitation, API testing, and CI/CD integration; oversee external penetration testing engagements end‑to‑end (scoping, vendor management, finding triage, retesting, reporting).
  • Run SOC 1 / SOC 2 Type II programs end‑to‑end with external auditors.
  • Lead US regulatory compliance — SOX ITGC, HIPAA / HITECH, GLBA, CCPA / CPRA + state privacy laws, NYDFS Part 500; track FedRAMP / StateRAMP readiness.
  • Lead European compliance — EU and UK GDPR (DPIAs, ROPAs, SCCs / UK IDTA), NIS2, and DORA readiness for in‑scope clients.
  • Maintain alignment with NIST CSF 2.0, NIST 800‑53, CIS Controls v8, and PCI DSS v4.0 where relevant.
  • Own the vendor and client assurance function — TPRM, security questionnaires, RFPs, customer audits, and contract security clauses.
  • Lead incident response and manage breach‑notification timelines (SEC 8‑K Item 1.05, HIPAA, NYDFS 72‑hour, GDPR Article 33, NIS2).
  • Own the annual security budget — CapEx/OpEx planning, vendor negotiation, ROI tracking, and 12/24/36‑month capability roadmaps.
  • Champion innovation — pilot AI‑assisted SOC, autonomous pen testing, deception, ITDR, and CNAPP consolidation; run purple‑team and tabletop exercises.
  • Lead, coach, and grow a team of security and compliance analysts.
The Must‑Haves
  • 8+ years across information security, risk, and IT, with direct people‑management experience.
  • Deep hands‑on Azure security (Defender for Cloud, Entra ID Conditional Access design and tuning, PIM, Sentinel) and Microsoft 365 Defender / Purview.
  • Practical Kubernetes / container security and DevSecOps experience.
  • Hands‑on Tenable vulnerability management at scale, plus Burp Suite Professional for web app and API penetration testing.
  • SBOM and supply‑chain security experience (SPDX / CycloneDX, SLSA, NIST SSDF).
  • Track record leading SOC 1 / SOC 2 Type II and ISO 27001 cycles end‑to‑end.
  • Working command of US (SOX, HIPAA, GLBA, CCPA/CPRA, NYDFS Part 500) and EU/UK (GDPR, NIS2, DORA) frameworks.
  • Solid grounding in NIST CSF 2.0, NIST 800‑53, CIS v8, and MITRE ATT&CK.
  • Experience owning a security budget and negotiating with vendors.
  • Incident response leadership across multiple US and EU jurisdictions.
  • Strong executive communication — translating risk into business language.
  • Bachelor's degree in CS, InfoSec, or related field (or equivalent experience), plus CISSP, CISM, or CISA.
Preferred to Have
  • FedRAMP / StateRAMP or HITRUST CSF program experience.
  • Azure Security Engineer (AZ-500), Microsoft Cybersecurity Architect (SC-100), CCSP, or ISO 27001 Lead Auditor.
  • CNAPP, ITDR, or deception technology experience.
  • Familiarity with AI/ML governance (NIST AI RMF, ISO 42001, EU AI Act).
  • Exposure to procure-to-pay, fintech, or supplier‑data environments.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Vulnerability Manager
Threat Vulnerability Manager

Trekrecruit India. • Hyderabad

On-site
INR 3,500,000 - 7,000,000
Sr. Consultant - Azure Cloud Security Engineer Job
Sr. Consultant - Azure Cloud Security Engineer Job

YASH Technologies • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Principal Security Engineer
Principal Security Engineer

G1 GLOBAL • Hyderabad

On-site
INR 3,500,000 - 7,000,000
Security Engineering Manager
Security Engineering Manager

SmartStream • India

On-site
INR 4,000,000 - 6,000,000
Security Engineering Manager
Security Engineering Manager

Smartstream Limited • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Security Engineer
Security Engineer

ISA • Maharashtra

On-site
INR 1,500,000 - 2,300,000
Customer Success Project Manager
Customer Success Project Manager

Kaspersky Lab • Delhi

On-site
INR 2,000,000 - 3,000,000
Health Insurance
Professional Development Opportunities
Flexible Working Hours
Security Engineering Manager
Security Engineering Manager

Smartstream • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Information Technology - Infrastructure Head
Information Technology - Infrastructure Head

TerraPay Holdings Limited • India

On-site
INR 3,500,000 - 9,000,000
Cyber Security Specialist
Cyber Security Specialist

Terralogic • Bengaluru

On-site
INR 2,800,000 - 4,600,000