Posted on: 17/09/2026
The ISMS Manager is a senior practitioner responsible for delivering end-to-end information security management across four core functions : security architecture reviews, ISO 27001 and SOC 2 compliance, presales security engagements, and post-sales RFI/RFP support.
The role requires an individual review cloud architecture, managing audit cycles, briefing enterprise CISOs, and responding to client security questionnaires - operating with a high degree of independence and accountability.
Key Responsibilities :
1. Security Architecture Review :
- Conduct end-to-end security architecture reviews for product and platform offerings, covering application, API, cloud infrastructure, and data layers.
- Engage directly with engineering and product teams to embed security controls at the design stage - threat modelling, data flow validation, and trust boundary definition.
- Assess third-party integrations, vendor components, and new feature deployments for security risk prior to go-live.
- Maintain security architecture documentation including reference architecture, component-level controls mapping, and deviation/exception registers.
- Define and enforce secure SDLC practices in alignment with industry standards (OWASP, NIST, CIS).
2. Compliance - ISO 27001 & SOC 2 (BAU) :
- Own the information security management system (ISMS) and drive ongoing compliance for ISO 27001 and SOC 2 Type II - from BAU control maintenance through audit readiness and recertification.
- Manage the full evidence lifecycle: control testing, artefact collection, gap remediation, and liaison with external auditors and certification bodies.
- Drive remediation of audit findings in coordination with engineering, infrastructure, and operations teams.
- Maintain the risk register, asset inventory, incident response plan, business continuity provisions, and vendor risk assessment programme in alignment with ISO 27001 Annex A.
- Track changes in applicable regulations and standards, updating the control framework accordingly.
3. Presales - Security Architecture Briefings :
- Act as the security subject-matter expert during enterprise sales cycles - briefing CISOs, CIOs, and technical evaluators at prospective accounts on architecture, data residency, access controls, encryption, and compliance certifications.
- Develop and maintain standard presales security collateral: security overview decks, trust and compliance one-pagers, data processing summaries, and product security FAQs.
- Support sales and product teams in scoping security requirements during deal qualification, solution design, and contract negotiation stages.
- Represent the security function at client meetings and procurement panels as required.
4. Post-Sales Support - RFI / RFP Responses :
- Own end-to-end completion of security RFIs and RFPs from enterprise clients, including those in regulated sectors (BFSI, healthcare, government).
- Produce accurate, technically detailed responses covering penetration testing, cloud security, VAPT findings and remediation status, data privacy compliance, and third-party risk management.
- Build and maintain a structured RFI/RFP response library, keeping answers current with the evolving controls landscape and certification status.
- Manage client security questionnaires (SIG, CSA CAIQ, and bespoke sector questionnaires) within agreed SLA commitments.
- Serve as the primary point of contact for post-sales security queries, escalations, and due diligence reviews from enterprise accounts.
Required Qualifications & Experience :
Experience :
- 8 - 12 years of progressive information security experience, with at least 3 years in a senior security management or advisory capacity.
- Demonstrated end-to-end ownership of ISO 27001 and SOC 2 compliance programmes - from implementation through sustained BAU and certification cycles.
- Hands-on background in security architecture review for SaaS or cloud-native platforms; familiarity with API security, microservices, and multi-tenant architectures.
- Proven experience owning or significantly contributing to enterprise RFI/RFP security responses.
- Prior exposure to regulated industry sectors (BFSI, healthcare, or equivalent) - understanding of client security assessment dynamics and procurement-driven security requirements.
Technical Knowledge :
- Cloud security across AWS / Azure / GCP - IAM, network controls, encryption, logging, and CSPM concepts.
- Application and API security - OWASP Top 10, authentication mechanisms (OAuth 2.0, SAML, OpenID Connect), and secure SDLC practices.
- Data protection and privacy - DPDPA, GDPR concepts, data classification frameworks, DLP controls.
- Vulnerability management lifecycle - VAPT coordination, CVSS scoring, remediation tracking, and risk acceptance.
- Governance frameworks - ISO 27001, SOC 2, NIST CSF, CIS Controls; ability to map controls across multiple frameworks.
Certifications :
- CISSP or CISM - required.
- ISO 27001 Lead Auditor or Lead Implementer - strongly preferred.
- CCSP, AWS Security Specialty, or equivalent cloud security certification - preferred.
- CEH or equivalent offensive security certification - advantageous
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1672312