Manager - ISMS

Dash Technologies Inc.

Ahmedabad District

Hybrid

INR 1,800,000 - 3,200,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Dash Technologies Inc. seeks an experienced ISMS Manager to lead information security, privacy, risk, audit, AI governance, and compliance programs across ISO 27001, ISO 27701, ISO 42001, SOC 2, HITRUST and HIPAA.

You will own the ISMS, manage risk and audit activities, maintain evidence, oversee security questionnaires, and serve as primary contact for auditors, clients, and regulators.

Qualifications

  • 10+ years in information security, privacy, GRC, compliance, risk, or audit management.
  • Hands-on experience leading ISMS, risk, and audit programs.
  • Strong familiarity with ISO 27001, ISO 27701, ISO 42001, SOC 2, HITRUST, HIPAA.

Responsibilities

  • Own day-to-day operation and continual improvement of the ISMS and privacy program.
  • Develop and maintain security, privacy, AI governance, and compliance policies and procedures.
  • Maintain risk registers, control matrices, statements of applicability, compliance calendars, and audit-ready documentation.
  • Coordinate compliance activities across ISO 27001, ISO 27701, ISO 42001, SOC 2, HITRUST, and HIPAA.
  • Lead information security, privacy, AI, vendor, operational, and compliance risk assessments.
  • Coordinate internal and external audits, certification assessments, client assessments, and regulatory reviews.

Skills

ISMS management
Risk assessment
Audit coordination
Privacy program
GRC tooling
Regulatory compliance
Vendor management
Security questionnaires
ISO 27001
ISO 27701
SOC 2
AI governance
HITRUST
HIPAA
ISO 42001
ISO 9001/13485/cmmI

Education

Bachelor's degree in CS/IT/InfoSec

Tools

Vanta/Drata/Secureframe

Job description

Role Summary

Dash Technologies is seeking an experienced ISMS Manager to lead the company’s information security, privacy, risk, audit, AI governance, and compliance programs. The role will manage compliance across ISO 27001, ISO 27701, ISO 42001, SOC 2, HITRUST, and HIPAA, while coordinating with relevant teams supporting ISO 9001, ISO 13485, CMMI, IEC 62304, and ISO 14971 requirements. The successful candidate will own the ISMS, manage risk and audit activities, maintain compliance evidence, oversee security questionnaires, and act as the primary contact for auditors, certification bodies, clients, and regulatory stakeholders.

What You’ll Do
ISMS and Compliance Governance
  • Own the day-to-day operation and continual improvement of the ISMS and privacy program.
  • Develop and maintain security, privacy, AI governance, and compliance policies and procedures.
  • Maintain risk registers, control matrices, statements of applicability, compliance calendars, and audit-ready documentation.
  • Ensure controls align with business requirements, client commitments, regulatory obligations, and applicable standards.
  • Coordinate compliance activities across ISO 27001, ISO 27701, ISO 42001, SOC 2, HITRUST, and HIPAA.
Risk, Audit and Evidence Management
  • Lead information security, privacy, AI, vendor, operational, and compliance risk assessments.
  • Maintain risk-treatment plans, vulnerability dashboards, remediation trackers, and residual-risk reports.
  • Coordinate internal audits, external audits, certification assessments, client assessments, and regulatory reviews.
  • Manage audit findings, nonconformities, corrective actions, and preventive actions through closure.
  • Ensure evidence is complete, current, traceable, and mapped to applicable controls.
AI Governance and Privacy
  • Lead the ISO 42001 Artificial Intelligence Management System program.
  • Maintain AI inventories, risk assessments, impact assessments, data-governance processes, and lifecycle controls.
  • Promote responsible AI principles, including transparency, explainability, human oversight, fairness, security, and privacy.
  • Manage privacy compliance under ISO 27701 and HIPAA.
  • Support PHI, PII, data flow, retention, access control, breach assessment, and cross-border data management activities.
SOC 2, HITRUST, and Security Questionnaires
  • Coordinate SOC 2 Type II control operation, evidence collection, and audit readiness.
  • Manage HITRUST readiness, control implementation, evidence preparation, and remediation.
  • Own enterprise security questionnaires and customer due-diligence requests.
  • Maintain an approved knowledge base of questionnaire responses and supporting evidence.
  • Coordinate responses with Sales, Legal, Engineering, Infrastructure, Delivery, HR, and leadership teams.
Quality and Medical Device Compliance Coordination
  • Coordinate with relevant teams supporting ISO 9001 and ISO 13485 requirements.
  • Support alignment with CMMI process requirements.
  • Coordinate information security and privacy inputs for IEC 62304 software lifecycle activities.
  • Support security and product-risk alignment with ISO 14971.
  • Ensure security and privacy requirements are incorporated into development, change management, supplier management, release, and incident-management processes.
Training, Reporting and Stakeholder Management
  • Deliver security, privacy, compliance, and responsible AI awareness training.
  • Track training completion and maintain required records.
  • Prepare monthly and quarterly reports on risks, audits, incidents, control effectiveness, training, and remediation.
  • Lead management review meetings and recommend corrective and preventive actions.
  • Manage relationships with auditors, certification bodies, HITRUST assessors, SOC 2 firms, GRC vendors, legal counsel, and compliance consultants.
Your Impact
Success in the First 6–12 Months
  • All scheduled audits, assessments, renewals, and client responses completed on time.
  • Audit-ready policies, risk registers, control mappings, and evidence repositories maintained.
  • ISO 27001, ISO 27701, ISO 42001, SOC 2, HITRUST, and HIPAA programs operating effectively.
  • Monthly risk and compliance dashboard implemented for leadership.
  • Audit findings, client queries, and remediation actions closed within agreed timelines.
  • Security, privacy, compliance, and role-based training completed by 100% of employees.
  • Structured security-questionnaire process established with clear ownership.
  • ISO 42001 AI governance controls embedded into relevant products, services, and processes.
  • Effective coordination established across ISO 9001, ISO 13485, CMMI, IEC 62304, and ISO 14971 activities.
What You Bring — Must-Have
  • 10+ years of experience in information security, privacy, GRC, compliance, risk, or audit management.
  • At least 5 years in an ISMS Manager, Information Security Manager, GRC Manager, or similar leadership role.
  • Hands-on experience with multiple frameworks, including:
  • ISO 27001 and ISO 27701.
  • ISO 42001 or AI governance.
  • SOC 2 Type II.
  • HITRUST.
  • HIPAA.
  • Experience supporting ISO 9001, ISO 13485, CMMI, IEC 62304, or ISO 14971.
  • Proven experience managing external audits, certification assessments, evidence collection, and remediation.
  • Strong understanding of risk registers, control testing, audit tracking, compliance reporting, and security questionnaires.
  • Experience using GRC or compliance platforms such as Vanta, Drata, Secureframe, or similar tools.
  • Excellent communication, documentation, stakeholder-management, and problem-solving skills.
  • Willingness to work the 2:00–11:00 PM IST shift and provide occasional audit or incident-response coverage.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Manager
Information Security Manager

Rahi Platform Technologies • Pune District

On-site
INR 1,000,000 - 1,500,000
Deputy General Manager-GRC
Deputy General Manager-GRC

SupportFinity™ • Ahmedabad District

On-site
INR 1,200,000 - 2,000,000
Admin
Admin

OneMetric • Gurugram District

On-site
INR 800,000 - 1,200,000
Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
Sr. Consultant - Compliance
Sr. Consultant - Compliance

TAC Security • Delhi

On-site
INR 1,500,000 - 2,100,000
InfoSec Manager
InfoSec Manager

Blankstate • Dadri

On-site
INR 3,500,000 - 6,500,000
Private Health Insurance
Paid Time Off
Work From Home
+1
InfoSec Manager
InfoSec Manager

Blankstate • Delhi

On-site
INR 2,500,000 - 4,200,000
Private Health Insurance
Paid Time Off
Work From Home
+1
Information Security and Data Privacy Manager
Information Security and Data Privacy Manager

Tiger Analytics • Chennai District

Hybrid
INR 2,500,000 - 6,000,000
Senior Associate, Security Governance, Risk & Compliance
Senior Associate, Security Governance, Risk & Compliance

Athena Executive Search And Consulting • Gurugram District, Bengaluru

Hybrid
INR 1,500,000 - 2,500,000
Medical insurance
Gratuity
Flexible work models
IT security and Compliance Administrator
IT security and Compliance Administrator

Commtel Networks Limited • Mumbai

On-site
INR 1,200,000 - 1,500,000