Information Security Manager at CyberNX Technologies · Bengaluru (Bangalore) · 4 - 8 years · ₹9L - ₹15L / yr · Profitable · Posted 3 Oct 2023

Information Security Manager shall be primarily responsible to :
- Run and manage the BAU security infosec operations
- Create and maintain ISMS Policy and Process documents
- Ensure Infosec compliance with RBI and other regulatory agencies
- Participate in IT / Infosec Audits and ensure closure of observations within given timeliness
- Conduct regular VAPT (Vulnerability Assessments) and track closure of open observations
- Identifying and evaluating new IT security technologies and services and implementing it
- Ensure cyber security related polices and technologies are in place
- Conducting regular Inforsec Awareness within users in the organization
- The person needs to work closely with the CISO and other stakeholders – Risk, IT and Audit teams.
Key Accountability:
- Ensuring adequate security controls are in place & working effectively within the organization for information & cyber security
- Ensuring effectiveness of all IT controls to prevent any unauthorized access or activities at a system administration level
- Identify potential security weaknesses through vulnerability assessments and track them to closure within the timeliness
- Tracking and reporting key risk indicators defined for IT processes
- Create and maintain the documentation for information system audits in accordance with regulatory and compliance requirements
- Create / Review ISMS policy and process
- Implement Strategic IT Infosec projects to strengthen the overall IT Security posture

About CyberNX Technologies
About
Similar jobs (2)
We are seeking an experienced Governance, Risk & Compliance (GRC) Lead to spearhead the
design, implementation, and maintenance of our ISO 27001 Information Security Management
System (ISMS). This is a hands-on leadership role responsible for establishing a robust security
governance framework, achieving ISO 27001 certification, and embedding a culture of
continuous security improvement across the organization.
Key Responsibilities
● ISMS Implementation & Certification: Lead end-to-end ISO 27001 implementation
from gap analysis through to successful Stage 1 and Stage 2 certification audits;
manage external auditor relationships
● Risk Management: Develop and operationalize the information security risk
management framework; conduct risk assessments, treatment planning, and risk
acceptance processes.
● Policy & Governance : Author, approve, and maintain the Statement of Applicability
(SoA), information security policies, standards, and procedures aligned with ISO 27001
Annex A controls.
● Control Implementation: Translate ISO 27001 Annex A controls into operational
security measures; coordinate with IT, Accounts, HR, Backoffice, and business units to
implement and validate controls.
● Compliance Monitoring: Establish continuous monitoring, internal audit programs, and
KPIs/KRIs to measure ISMS effectiveness; manage non-conformities and corrective
actions.
● Third-Party Risk: Oversee vendor security assessments and ensure supply chain
security controls meet organizational and ISO 27001 standards.
● Stakeholder Management: Report ISMS performance, risks, and compliance status to
senior leadership and the board; act as primary liaison for external auditors and
regulators.
Required Qualifications
● 5+ years of experience in information security governance, risk, and compliance
● Proven track record of leading at least one full ISO 27001:2022 certification cycle (gap
analysis → certification)
● Deep expertise in ISO 27001:2022 standard, Annex A controls, and ISMS
documentation requirements
● Strong understanding of risk assessment methodologies (e.g., ISO 27005, NIST RMF,
OCTAVE, FAIR)
● Familiarity with internal audit practices and managing external certification bodies
● Excellent stakeholder management and ability to influence across technical and non-
technical teams
● Strong documentation and communication skills — able to translate complex standards
into actionable guidance
Preferred Qualifications
● Experience implementing ISMS in fintech, healthcare, or regulated industries
● Experience with SOC 2, GDPR, NIST CSF, PCI-DSS, or other compliance frameworks
● Background in cloud security (AWS, Azure, GCP) and DevSecOps environments
● Knowledge of automation for compliance evidence collection and control testing
● Certifications: CISM, CRISC, CISA, ISO 27001 Lead Auditor, or ISO 27001 Lead
Implementer
Why Join Us
● Opportunity to build the security governance function from the ground up
● High-visibility role with direct impact on customer trust and market differentiation
● Collaborative environment that values security as a business enabler, not a blocker
Company Profile:
We are a one-stop financial services shop, widely known for quality of its advice, personalized
service and cutting-edge technology. We started our journey in 2008. Currently we are serving
more than 50,000 investors with a team of 100 members. Our core product offering is mutual
fund, FD, Govt. Bonds, Debenture, etc.
The recruiter has not been active on this job recently. You may apply but please expect a delayed response.
Location: Jaipur, Rajasthan (Work From Office)
Experience: 5+ Years
Job Type: Full-Time
We're looking for an IT Compliance Officer to lead information security and compliance initiatives across our SaaS products and IT infrastructure. You'll ensure compliance with industry standards while strengthening our security and governance framework.
Key Responsibilities
- Manage compliance for SOC 2, ISO 27001, GDPR, and ITGC.
- Coordinate security audits, VAPT, and risk assessments.
- Develop and maintain security policies, SOPs, and compliance documentation.
- Ensure data protection, access control, and incident response best practices.
- Collaborate with IT, Development, QA, and Product teams to improve security controls.
- Conduct compliance training and stay updated on cybersecurity regulations.
Requirements
- 5+ years of experience in IT Compliance, Information Security, or IT Audit (preferably in a SaaS/Product company).
- Strong knowledge of SOC 2, ISO 27001, ITGC, VAPT, Risk Management, and Compliance Audits.
- Experience with security documentation, audit processes, and risk assessments.
- Excellent analytical, communication, and documentation skills.
Preferred: ISO 27001 Lead Auditor, CISA, CISM, CompTIA Security+, or Six Sigma certification.
Apply Now
Application Form: https://zfrmz.com/pAKb2ynfomIsuNwRfRbV?utm_source=cutshort






