HamburgerMenu
hirist

AssetPlus - Information Security Officer

Valueplus Technologies Private Limited
Chennai
8 - 12 Years

Posted on: 09/09/2025

Job Description

About the Role :


We are looking for a seasoned Information Security Officer to lead our enterprise-wide information security and compliance initiatives. This role is critical in safeguarding sensitive data, ensuring regulatory compliance, and embedding a culture of security across the organization.

The ideal candidate brings deep technical expertise combined with a strong grasp of evolving legal and regulatory frameworks.

Key Responsibilities :

Regulatory & Compliance Oversight :

- Ensure compliance with DPDP Act, IT Act, SEBI, KRA, IRDAI, and ISO 27001 frameworks.

- Define and enforce data classification protocols for sensitive information (KYC, Aadhaar, financial records).

- Manage third-party/vendor risk assessments and oversee contractual compliance for data processors/controllers.

- Monitor regulatory changes and cybersecurity threats; implement proactive countermeasures.

Security Architecture & Operations :

- Design and enforce enterprise-wide security controls including credential management, multi-factor authentication, and privileged access.

- Oversee device and network protection mechanisms : MDM, VPN-only access, domain restrictions, USB lockdowns.

- Establish advanced logging and auditing frameworks (AAA - Authentication, Authorization, Accounting) for threat detection and incident tracing.

- Lead vulnerability management, penetration testing, and breach incident response.

Governance, Risk & Training :

- Develop and implement data security governance policies across business units.

- Act as the final escalation authority during breaches or compliance conflicts.

- Drive organization-wide security awareness, employee training, and certifications.

- Align security initiatives with business strategy while mitigating regulatory and reputational risks.

Qualifications & Skills :

- 8 - 12 years of progressive experience in Information Security, Cybersecurity, or IT Compliance.

- Strong command over data privacy and enterprise security standards (ISO 27001, SOC 2, NIST frameworks).

- Expertise in infrastructure security, access management, SIEM solutions, and endpoint/device controls.

- Strong analytical skills with the ability to balance regulatory enforcement and business enablement.

- Excellent stakeholder management, communication, and leadership skills


info-icon

Did you find something suspicious?