HamburgerMenu
hirist

ISMS Manager - Security Architecture & Compliance

Eaglehires Hr Solutions
7 - 12 Years
Bangalore

Posted on: 17/09/2026

Job Description

The ISMS Manager is a senior practitioner responsible for delivering end-to-end information security management across four core functions : security architecture reviews, ISO 27001 and SOC 2 compliance, presales security engagements, and post-sales RFI/RFP support.

The role requires an individual review cloud architecture, managing audit cycles, briefing enterprise CISOs, and responding to client security questionnaires - operating with a high degree of independence and accountability.

Key Responsibilities :

1. Security Architecture Review :

- Conduct end-to-end security architecture reviews for product and platform offerings, covering application, API, cloud infrastructure, and data layers.

- Engage directly with engineering and product teams to embed security controls at the design stage - threat modelling, data flow validation, and trust boundary definition.

- Assess third-party integrations, vendor components, and new feature deployments for security risk prior to go-live.

- Maintain security architecture documentation including reference architecture, component-level controls mapping, and deviation/exception registers.

- Define and enforce secure SDLC practices in alignment with industry standards (OWASP, NIST, CIS).

2. Compliance - ISO 27001 & SOC 2 (BAU) :

- Own the information security management system (ISMS) and drive ongoing compliance for ISO 27001 and SOC 2 Type II - from BAU control maintenance through audit readiness and recertification.

- Manage the full evidence lifecycle: control testing, artefact collection, gap remediation, and liaison with external auditors and certification bodies.

- Drive remediation of audit findings in coordination with engineering, infrastructure, and operations teams.

- Maintain the risk register, asset inventory, incident response plan, business continuity provisions, and vendor risk assessment programme in alignment with ISO 27001 Annex A.

- Track changes in applicable regulations and standards, updating the control framework accordingly.

3. Presales - Security Architecture Briefings :

- Act as the security subject-matter expert during enterprise sales cycles - briefing CISOs, CIOs, and technical evaluators at prospective accounts on architecture, data residency, access controls, encryption, and compliance certifications.

- Develop and maintain standard presales security collateral: security overview decks, trust and compliance one-pagers, data processing summaries, and product security FAQs.

- Support sales and product teams in scoping security requirements during deal qualification, solution design, and contract negotiation stages.

- Represent the security function at client meetings and procurement panels as required.

4. Post-Sales Support - RFI / RFP Responses :

- Own end-to-end completion of security RFIs and RFPs from enterprise clients, including those in regulated sectors (BFSI, healthcare, government).

- Produce accurate, technically detailed responses covering penetration testing, cloud security, VAPT findings and remediation status, data privacy compliance, and third-party risk management.

- Build and maintain a structured RFI/RFP response library, keeping answers current with the evolving controls landscape and certification status.

- Manage client security questionnaires (SIG, CSA CAIQ, and bespoke sector questionnaires) within agreed SLA commitments.

- Serve as the primary point of contact for post-sales security queries, escalations, and due diligence reviews from enterprise accounts.

Required Qualifications & Experience :

Experience :

- 8 - 12 years of progressive information security experience, with at least 3 years in a senior security management or advisory capacity.

- Demonstrated end-to-end ownership of ISO 27001 and SOC 2 compliance programmes - from implementation through sustained BAU and certification cycles.

- Hands-on background in security architecture review for SaaS or cloud-native platforms; familiarity with API security, microservices, and multi-tenant architectures.

- Proven experience owning or significantly contributing to enterprise RFI/RFP security responses.

- Prior exposure to regulated industry sectors (BFSI, healthcare, or equivalent) - understanding of client security assessment dynamics and procurement-driven security requirements.

Technical Knowledge :

- Cloud security across AWS / Azure / GCP - IAM, network controls, encryption, logging, and CSPM concepts.

- Application and API security - OWASP Top 10, authentication mechanisms (OAuth 2.0, SAML, OpenID Connect), and secure SDLC practices.

- Data protection and privacy - DPDPA, GDPR concepts, data classification frameworks, DLP controls.

- Vulnerability management lifecycle - VAPT coordination, CVSS scoring, remediation tracking, and risk acceptance.

- Governance frameworks - ISO 27001, SOC 2, NIST CSF, CIS Controls; ability to map controls across multiple frameworks.

Certifications :

- CISSP or CISM - required.

- ISO 27001 Lead Auditor or Lead Implementer - strongly preferred.

- CCSP, AWS Security Specialty, or equivalent cloud security certification - preferred.

- CEH or equivalent offensive security certification - advantageous

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...