Posted on: 31/07/2026
Officer - Information Security
Location : Mumbai
Experience : 5-10 Years
About the Opportunity :
Our client is a leading technology-driven organization operating in a highly regulated environment, serving enterprise customers across India. The organization is looking to strengthen its Information Security Governance, Risk & Compliance function and is seeking an experienced information security professional to support security governance, compliance management, risk assessments, third-party security reviews, and audit programs.
Key Responsibilities :
- Support and enhance the organization's Information Security Management System (ISMS).
- Develop, review, and maintain Information Security Policies, Standards, Procedures, and Guidelines.
- Conduct Information Security Risk Assessments across applications, infrastructure, cloud environments, and third-party ecosystems.
- Perform security control and infrastructure gap assessments against industry standards and regulatory requirements.
- Maintain risk registers and track remediation activities through closure.
- Review vulnerability assessment and penetration testing reports and coordinate remediation tracking.
- Monitor security remediation timelines and support governance reporting.
- Conduct third-party and vendor security assessments.
- Review security certifications, audit reports, and compliance documentation provided by external partners.
- Coordinate internal, external, customer, and regulatory audits.
- Track audit observations and ensure timely closure of findings.
- Prepare governance dashboards, risk reports, compliance metrics, and management updates.
- Present security posture and compliance updates to key stakeholders.
Desired Candidate Profile :
- 5-10 years of experience in Information Security Governance, Cyber Risk, Compliance, Security Assurance, IT Audit, or related domains.
- Strong understanding of Information Security Management Systems (ISMS).
- Experience with security frameworks and standards such as ISO 27001, SOC 2, PCI DSS, NIST CSF, or equivalent.
- Exposure to regulatory compliance requirements and audit management.
- Experience conducting risk assessments, control reviews, and remediation tracking.
- Understanding of vulnerability management and security control validation.
- Experience in vendor risk management and third-party security assessments.
- Strong stakeholder management, documentation, and communication skills.
Preferred Certifications :
- ISO 27001 Lead Auditor / Lead Implementer
- CISA
- CISSP
- CRISC
- PCI-related certifications
Why Consider This Opportunity ?
- Opportunity to work in a mature cybersecurity and governance environment.
- Exposure to enterprise-scale security, compliance, and risk programs.
- High visibility with senior stakeholders and business leadership.
- Opportunity to contribute to critical security and compliance initiatives in a regulated industry.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1659374