Manager - ISMS

Dash Technologies Inc

Ahmedabad District

On-site

INR 350,000 - 600,000

Full time

41 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Dash Technologies is seeking an experienced ISMS Manager to lead information security, privacy, risk, audit, AI governance, and compliance programs. The role will own the ISMS, manage risk and audit activities, maintain evidence, oversee security questionnaires, and serve as the primary contact for auditors, certification bodies, clients, and regulators.

The successful candidate will coordinate across ISO 27001, ISO 27701, ISO 42001, SOC 2, HITRUST, and HIPAA while aligning with ISO 9001, ISO

Qualifications

  • 10+ years in information security, privacy, GRC, risk, or audit management.
  • At least 5 years in an ISMS Manager, Information Security Manager, GRC Manager, or similar leadership role.
  • Hands-on experience with ISO 27001 and ISO 27701, and AI governance.
  • Experience supporting SOC 2, HITRUST, and HIPAA.
  • Familiarity with ISO 9001, ISO 13485, CMMI, IEC 62304, ISO 14971.
  • Proven experience managing external audits, certification assessments, evidence collection, remediation.
  • Excellent communication, documentation, and stakeholder-management skills.

Responsibilities

  • Own the day-to-day operation and continual improvement of the ISMS and privacy program.
  • Develop and maintain security, privacy, AI governance, and compliance policies and procedures.
  • Maintain risk registers, control matrices, statements of applicability, compliance calendars, and audit-ready documentation.
  • Coordinate compliance activities across ISO 27001, ISO 27701, ISO 42001, SOC 2, HITRUST, and HIPAA.
  • Lead information security, privacy, AI, vendor, operational, and compliance risk assessments.
  • Coordinate internal audits, external audits, certification assessments, client assessments, and regulatory reviews.
  • Manage audit findings, nonconformities, corrective actions, and preventive actions through closure.
  • Ensure evidence is complete, current, traceable, and mapped to applicable controls.
  • Lead the ISO 42001 AI governance program and data-governance practices.
  • Manage relationships with auditors, clients, and regulatory stakeholders.

Tools

Vanta
Drata
Secureframe

Job description

Dash Technologies is seeking an experienced ISMS Manager to lead the company’s information security, privacy, risk, audit, AI governance, and compliance programs. The role will manage compliance across ISO 27001, ISO 27701, ISO 42001, SOC 2, HITRUST, and HIPAA, while coordinating with relevant teams supporting ISO 9001, ISO 13485, CMMI, IEC 62304, and ISO 14971 requirements. The successful candidate will own the ISMS, manage risk and audit activities, maintain compliance evidence, oversee security questionnaires, and act as the primary contact for auditors, certification bodies, clients, and regulatory stakeholders.

What You’ll Do
ISMS and Compliance Governance
  • Own the day-to-day operation and continual improvement of the ISMS and privacy program.
  • Develop and maintain security, privacy, AI governance, and compliance policies and procedures.
  • Maintain risk registers, control matrices, statements of applicability, compliance calendars, and audit-ready documentation.
  • Ensure controls align with business requirements, client commitments, regulatory obligations, and applicable standards.
  • Coordinate compliance activities across ISO 27001, ISO 27701, ISO 42001, SOC 2, HITRUST, and HIPAA.
Risk, Audit and Evidence Management
  • Lead information security, privacy, AI, vendor, operational, and compliance risk assessments.
  • Maintain risk-treatment plans, vulnerability dashboards, remediation trackers, and residual-risk reports.
  • Coordinate internal audits, external audits, certification assessments, client assessments, and regulatory reviews.
  • Manage audit findings, nonconformities, corrective actions, and preventive actions through closure.Ensure evidence is complete, current, traceable, and mapped to applicable controls.
AI Governance and Privacy
  • Lead the ISO 42001 Artificial Intelligence Management System program.
  • Maintain AI inventories, risk assessments, impact assessments, data-governance processes, and lifecycle controls.
  • Promote responsible AI principles, including transparency, explainability, human oversight, fairness, security, and privacy.
  • Manage privacy compliance under ISO 27701 and HIPAA.
  • Support PHI, PII, data flow, retention, access control, breach assessment, and cross-border data management activities.
SOC 2, HITRUST, and Security Questionnaires
  • Coordinate SOC 2 Type II control operation, evidence collection, and audit readiness.
  • Manage HITRUST readiness, control implementation, evidence preparation, and remediation.
  • Own enterprise security questionnaires and customer due-diligence requests.
  • Maintain an approved knowledge base of questionnaire responses and supporting evidence.
  • Coordinate responses with Sales, Legal, Engineering, Infrastructure, Delivery, HR, and leadership teams.
Quality and Medical Device Compliance Coordination
  • Coordinate with relevant teams supporting ISO 9001 and ISO 13485 requirements.
  • Support alignment with CMMI process requirements.Coordinate information security and privacy inputs for IEC 62304 software lifecycle activities.
  • Support security and product-risk alignment with ISO 14971.
  • Ensure security and privacy requirements are incorporated into development, change management, supplier management, release, and incident-management processes.
Training, Reporting and Stakeholder Management
  • Deliver security, privacy, compliance, and responsible AI awareness training.
  • Track training completion and maintain required records.
  • Prepare monthly and quarterly reports on risks, audits, incidents, control effectiveness, training, and remediation.
  • Lead management review meetings and recommend corrective and preventive actions.
  • Manage relationships with auditors, certification bodies, HITRUST assessors, SOC 2 firms, GRC vendors, legal counsel, and compliance consultants.
Your Impact
Success in the First 6–12 Months
  • All scheduled audits, assessments, renewals, and client responses completed on time.
  • Audit-ready policies, risk registers, control mappings, and evidence repositories maintained.
  • ISO 27001, ISO 27701, ISO 42001, SOC 2, HITRUST, and HIPAA programs operating effectively.
  • Monthly risk and compliance dashboard implemented for leadership.
  • Audit findings, client queries, and remediation actions closed within agreed timelines.
  • Security, privacy, compliance, and role-based training completed by 100% of employees.
  • Structured security-questionnaire process established with clear ownership.
  • ISO 42001 AI governance controls embedded into relevant products, services, and processes.
  • Effective coordination established across ISO 9001, ISO 13485, CMMI, IEC 62304, and ISO 14971 activities.
What You Bring — Must-Have
  • 10+ years of experience in information security, privacy, GRC, compliance, risk, or audit management.
  • At least 5 years in an ISMS Manager, Information Security Manager, GRC Manager, or similar leadership role.
  • Hands-on experience with multiple frameworks, including:
  • ISO 27001 and ISO 27701.
  • ISO 42001 or AI governance.
  • SOC 2 Type II.
  • HITRUST.
  • HIPAA.
  • Experience supporting ISO 9001, ISO 13485, CMMI, IEC 62304, or ISO 14971.
  • Proven experience managing external audits, certification assessments, evidence collection, and remediation.
  • Strong understanding of risk registers, control testing, audit tracking, compliance reporting, and security questionnaires.
  • Experience using GRC or compliance platforms such as Vanta, Drata, Secureframe, or similar tools.
  • Excellent communication, documentation, stakeholder-management, and problem-solving skills.
  • Willingness to work the 2:00–11:00 PM IST shift and provide occasional audit or incident-response coverage.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager - ISMS
Manager - ISMS

Dash Technologies Inc. • Ahmedabad District

Hybrid
INR 1,800,000 - 3,200,000
Deputy General Manager-GRC
Deputy General Manager-GRC

SupportFinity™ • Ahmedabad District

On-site
INR 1,200,000 - 2,000,000
Information Security and Data Privacy Manager
Information Security and Data Privacy Manager

Tiger Analytics • Chennai District

Hybrid
INR 2,500,000 - 6,000,000
Sr Security GRC & ISO 27001 Manager
Sr Security GRC & ISO 27001 Manager

UST • Thiruvananthapuram

On-site
INR 2,500,000 - 4,000,000
Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
Senior Associate, Security Governance, Risk & Compliance
Senior Associate, Security Governance, Risk & Compliance

Athena Executive Search And Consulting • Gurugram District, Bengaluru

Hybrid
INR 1,500,000 - 2,500,000
Medical insurance
Gratuity
Flexible work models
InfoSec Manager
InfoSec Manager

Blankstate • Dadri

On-site
INR 3,500,000 - 6,500,000
Private Health Insurance
Paid Time Off
Work From Home
+1
Information Security Manager
Information Security Manager

Shell Infotech • Hyderabad

On-site
INR 180,000 - 300,000
Sr. Consultant - Compliance
Sr. Consultant - Compliance

TAC Security • Delhi

On-site
INR 1,500,000 - 2,100,000
Security Governance, Risk & Compliance
Security Governance, Risk & Compliance

Confidential • India

On-site
INR 1,800,000 - 2,400,000
Medical insurance
Gratuity
Flexible work models