Job Description
Acuity Analytics (the trading name of Acuity Knowledge Partners) is a global, tech-first organisation helping financial institutions and corporates make better decisions through research, data, analytics and AI-enabled solutions. We combine deep financial services expertise with strong engineering, digital and AI capabilities to solve complex, real-world problems.
Acuity Analytics (the trading name of Acuity Knowledge Partners) is a global, tech-first organisation helping financial institutions and corporates make better decisions through research, data, analytics and AI-enabled solutions. We combine deep financial services expertise with strong engineering, digital and AI capabilities to solve complex, real-world problems.
With a team of 7,200+ analysts, data specialists and technologists across 28 locations, we work with more than 800 organisations worldwide to drive efficiency, unlock insight and deliver measurable impact. Our success is built on the strength of our peopleby investing in talent, encouraging collaboration and creating room to grow, we enable our teams to do their best work for clients.
Acuity became an independent business in 2019 following its acquisition from Moodys Corporation by Equistone Partners Europe. In 2023, funds advised by global private equity firm Permira acquired a majority stake, with Equistone remaining a minority investor—supporting our continued growth and innovation.
For more information, visit www.acuityanalytics.com
Basic information
Position Title-Information Security Manager / Senior Manager
Experience Level-8-10 years
Department-Information Security
Location-Gurgaon
Job Purpose
- Lead practical information security, cloud security and GRC activities across business units, client accounts and corporate functions, with a strong focus on AI governance, cloud security, third-party risk, audit readiness and automation of repetitive compliance controls.
- Translate ISO 27001, SOC 2, applicable regulatory requirements, client security expectations and internal policies into business processes that are effective, auditable and operationally sustainable.
- Act as a hands‑on security professional who can assess technical risks, guide remediation, lead audits, manage risk exceptions and introduce AI‑enabled workflow automation to improve compliance efficiency.
- Role Design: 60% Technical Security and 40% GRC / Process Compliance
Cloud & Infrastructure
Hands‑on control assessment across Azure, AWS, Microsoft 365, IAM, endpoint, network, logging, monitoring, vulnerability management, conditional access, DLP, encryption and configuration governance.
Ensure cloud and infrastructure controls are mapped to ISO 27001, SOC 2, client contracts, internal policies and audit evidence expectations.
AI Governance & Automation
Assess AI‑related security, data protection and operational risks; support governance of AI tools, AI agents and GenAI use cases; identify opportunities for control automation.
Embed AI governance, human oversight, policy adherence, evidence retention and exception workflows into practical SOPs and business processes.
Third‑Party & Supply Chain Risk
Evaluate vendor security posture, cloud hosting, data handling, access management, resilience and subcontractor risk.
Run third‑party risk assessments, track remediation, manage exceptions, maintain GRC records and align vendor risk decisions with policy and client requirements.
Audit & Risk Management
Test technical control effectiveness and validate remediation for security findings across on‑premise, cloud and SaaS environments.
Lead internal audits, client audits, ISO 27001 audits, SOC 2 audits, risk registers, audit responses, corrective actions and management reporting.
Key Responsibilities
- Technical Security, Cloud and AI Governance Responsibilities
- Conduct hands‑on security risk assessments for cloud platforms, Microsoft 365, SaaS applications, identity and access management, network security, endpoint security, vulnerability management, logging, monitoring and data protection controls.
- Provide SME guidance on Azure and AWS security controls including IAM, privileged access, conditional access, encryption, key management, security posture management, logging, SIEM integration, backup, resilience and secure configuration baselines.
- Assess AI / GenAI use cases from security, privacy, governance, data leakage, model output reliability, third‑party dependency and human oversight perspectives.
- Help the AI Governance Function to design and operationalize AI governance controls, including approved use cases, secure AI usage guidance, prompt and output handling, evidence of human review, and AI risk acceptance workflows.
- Identify repetitive compliance activities that can be automated using workflow tools, scripts, dashboards or AI agents, while ensuring appropriate validation, access control, human oversight and audit evidence.
- Lead cybersecurity control testing across on‑premise and cloud environments to determine effectiveness, identify gaps and recommend pragmatic remediation actions.
- Support RFPs, client security questionnaires and technical security discussions by providing clear, evidence‑backed responses aligned with actual control implementation.
- GRC, Risk, Audit and Process Responsibilities
- Maintain and improve the organization’s ISO 27001 ISMS, ISO 42001 AIMS, SOC 2 control framework, risk management practices and applicable security compliance programs.
- Automate SOC2, ISO 27001 compliance monitoring via GRC tool.
- Help maintain the Privacy Governance Management System and conduct privacy risk assessments.
- Support implementation and ongoing operation of privacy governance controls aligned with GDPR, India’s DPDPA, client contractual requirements and internal privacy policies.
- Maintain privacy governance artefacts and evidence, including records of processing activities, data inventories and data‑flow inputs, privacy notices, consent or lawful‑processing records, retention requirements and cross‑border transfer documentation, in coordination with Legal, Privacy and business owners.
- Coordinate privacy impact assessments and data protection risk assessments for new or changed processes, applications, AI use cases, vendors and client engagements, and track identified actions to closure.
- Support data subject and data principal rights processes, including request intake, identity verification, internal coordination, response tracking, evidence retention and escalation within applicable timelines.
- Work with technology and business teams to implement privacy‑by‑design controls covering data minimisation, purpose limitation, access control, encryption, masking, retention and deletion, DLP, logging and secure handling of personal data.
- Support personal data breach governance by assessing privacy impact, coordinating evidence and stakeholder inputs, maintaining incident records and enabling timely escalation to Legal, Privacy and management for notification decisions.
- Assess privacy and data‑protection controls of third parties and subprocessors, including data location, onward transfers, retention, deletion, incident notification and contractual control requirements.
- Plan, coordinate and lead internal audits, client audits, external certification audits, SOC 2 audits and ISO 27001 audits, including evidence readiness, stakeholder coordination and closure of observations.
- Operate risk exception management by assessing business justification, compensating controls, risk exposure, expiry dates, approvals, evidence and periodic review requirements.
- Perform third‑party risk assessments for vendors, subcontractors and critical service providers, covering information security, privacy, cloud hosting, resilience, incident management and contractual control requirements.
- Conduct ISMS risk assessment and maintain risk registers, corrective action plans, control evidence, audit trackers, third‑party risk records, exceptions and Statement of Applicability updates in the GRC tool or approved system of record.
- Work with HR, Compliance, IT, Facilities, Procurement, Delivery Business Units and Client Account teams to embed security requirements into business processes without creating unnecessary operational overhead.
- Develop, review and maintain security policies, standards, procedures, guidelines and security awareness content relevant to cloud, AI governance, data protection, third‑party risk and audit compliance.
Functional Competencies
- Strong practical understanding of ISO 27001, SSAE 18 or ISAE 3000 SOC 2, ISO 31000 and 42001, NIST CSF / security best practices, CIS controls, cloud security benchmarks, data protection expectations and client security assurance requirements.
- Sound knowledge of GDPR, DPDPA and similar evolving global privacy laws, strong understanding of privacy technologist principles.
- Hands‑on experience of operationalizing GRC platforms to monitor compliance for SOC2, ISO 27001. Sound knowledge of GRC and Privacy Management tools like Archer, TrustArc, OneTrust, ServiceNow
- Hands‑on working knowledge of Azure, AWS and Microsoft 365 security controls, including IAM, MFA, SSO, conditional access