HamburgerMenu
hirist

Job Description

Officer - Information Security

Location : Mumbai

Experience : 5-10 Years

About the Opportunity :

Our client is a leading technology-driven organization operating in a highly regulated environment, serving enterprise customers across India. The organization is looking to strengthen its Information Security Governance, Risk & Compliance function and is seeking an experienced information security professional to support security governance, compliance management, risk assessments, third-party security reviews, and audit programs.

Key Responsibilities :

- Support and enhance the organization's Information Security Management System (ISMS).

- Develop, review, and maintain Information Security Policies, Standards, Procedures, and Guidelines.

- Conduct Information Security Risk Assessments across applications, infrastructure, cloud environments, and third-party ecosystems.

- Perform security control and infrastructure gap assessments against industry standards and regulatory requirements.

- Maintain risk registers and track remediation activities through closure.

- Review vulnerability assessment and penetration testing reports and coordinate remediation tracking.

- Monitor security remediation timelines and support governance reporting.

- Conduct third-party and vendor security assessments.

- Review security certifications, audit reports, and compliance documentation provided by external partners.

- Coordinate internal, external, customer, and regulatory audits.

- Track audit observations and ensure timely closure of findings.

- Prepare governance dashboards, risk reports, compliance metrics, and management updates.

- Present security posture and compliance updates to key stakeholders.

Desired Candidate Profile :

- 5-10 years of experience in Information Security Governance, Cyber Risk, Compliance, Security Assurance, IT Audit, or related domains.

- Strong understanding of Information Security Management Systems (ISMS).

- Experience with security frameworks and standards such as ISO 27001, SOC 2, PCI DSS, NIST CSF, or equivalent.

- Exposure to regulatory compliance requirements and audit management.

- Experience conducting risk assessments, control reviews, and remediation tracking.

- Understanding of vulnerability management and security control validation.

- Experience in vendor risk management and third-party security assessments.

- Strong stakeholder management, documentation, and communication skills.

Preferred Certifications :

- ISO 27001 Lead Auditor / Lead Implementer

- CISA

- CISSP

- CRISC

- PCI-related certifications

Why Consider This Opportunity ?

- Opportunity to work in a mature cybersecurity and governance environment.

- Exposure to enterprise-scale security, compliance, and risk programs.

- High visibility with senior stakeholders and business leadership.

- Opportunity to contribute to critical security and compliance initiatives in a regulated industry.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...