Cutshort logo
Marketwick logo
Information Security Manager
Information Security Manager
Marketwick's logo

Information Security Manager

Nirupama KM's profile picture
Posted by Nirupama KM
7 - 10 yrs
₹10L - ₹30L / yr
Gurugram
Skills
Information security management system
IT security
ISO/IEC 27000-series
ISO 9000
Internal audit
DPDPA
CISM
Compliance

Job description:

Company: Glan Management Consultancy

Location: Gurgaon

Experience: 7-15 year

Salary:

Employment Type:

Job Description:

Job Title: Manager Information Security – ITJob Purpose: Acting in a key technical management & execution capacity to provide a conduit between IT teams and key business stakeholders in your functional area of IT Security to ensure information technology needs are managed consistently, following professional IT and global standards, and delivered with a high level of quality and customer satisfaction.Reward level: Middle ManagementJob Location GurgaonExperience 10+ yearsRelevant Experience 7+ yearsReporting to: General ManagerQualification: Bachelor degree in ITKey Deliverables:

  • Provide support as Lead auditor towards ISMS and PIMS policies, procedures, and guidelines and perform regular review and update.
  • Perform deep assessment to gather evidence of continuous compliance with ISO 27001:2022 and ISO 27701:2019, DPDPA, IT Act and Cert In Regulation including audit logs, records of reviews, timely closure of open audit and risks and sharing the report with management.
  • Conduct regular, documented information security and privacy risk assessments identifying assets, threats, vulnerabilities, likelihood, and impact with stakeholders.
  • Prioritize identified vulnerabilities, detailed findings, remediation recommendations, trending reports on vulnerability posture towards closure with stakeholders.
  • Development and implementation of a comprehensive, ongoing security awareness and training program for all employees.
  • Encourage secure behaviours among colleagues and reinforce the importance of information security and privacy in daily operations.
  • Prepare regular report on overall information security posture, GRC maturity, and risk landscape to relevant stakeholders
  • Ability to collect lessons learned from incidents, audits, and assessments to drive continuous improvement in ISMS/PIMS and security processes.
  • Key Relationships
  • Internal IT and business customers.
  • Global IT Vendor, market and global (HQ) colleagues, Local vendor partners
  • Internal staff - direct reports (where applicable)IT vendors, contractors (where applicable)
  • Knowledge Skills and Abilities:
  • Must possess and demonstrate ISO 27001 Lead Implementer/Auditor and ISO 27701 Lead Implementer/Auditor certifications and knowledge.
  • In depth understanding of IT Act, DPDPA, Cert In regulations, CIS Controls as well as UK DPA and ISO 31000
  • Good to have certification on CISM (Certified Information Security Manager), CISSP (Certified Information Systems Security Professional) and Cloud Security certifications (e.g., CCSK, CCSP, vendor-specific like AWS Security Specialty)
  • Familiarity with common vulnerability scanning tools like Qualys (features, reporting, agent-based vs. network scans) and Cloud Security Posture Management (CSPM) tools like Wiz (cloud service provider configurations, misconfigurations, compliance checks in AWS, Azure, GCP).
  • Understanding of various penetration testing types (e.g., network, web application, API, mobile, cloud) and methodologies
  • Knowledge of common attack vectors and exploitation techniques like MITRE ATTACK and DEFEND framework.
  • Basic to intermediate knowledge of common security controls and technologies (e.g., firewalls, EDR, Cloud Security, VAPT tools, SIEM, WAF, DLP, encryption).
  • Understanding of network protocols, operating systems (Windows, Linux), and common application architectures.
  • Knowledge of audit principles and practices (internal and external audits).
  • Understanding of corrective action planning and non-conformity management.
  • Understanding of third-party risk management principles and vendor due diligence processes.
  • Excellent technical writing skills for creating clear, concise, and comprehensive security policies, standards, and procedures.
  • Ability to analyse complex risk data and present actionable insights.
  • Hands-on experience with Qualys for configuring scans, analysing reports, and managing vulnerabilities.
  • Hands-on experience with Wiz CSPM for monitoring cloud environments, identifying misconfigurations, and generating compliance reports.
  • Proficiency with GRC platforms or tools for managing policies, risks, and controls
  • Exceptional verbal and written communication skills to articulate complex security concepts to technical and non-technical stakeholders
  • Ability to build strong relationships and collaborate effectively with diverse teams (IT, Legal, HR, Development, Business Units).
  • Skills in influencing behaviour and driving change across the organization to improve security posture.
  • Strong analytical skills to diagnose security issues, identify root causes, and develop effective solutions.
  • Ability to critically evaluate security controls and identify gaps.
  • Contract review and negotiation skills specifically for security-related services.
  • Ability to effectively manage vendor relationships and performance.
  • Ability to develop and deliver engaging security training sessions and awareness campaigns.
  • Ability to stay updated with the latest security threats, vulnerabilities, technologies, and regulatory changes.
  • Capacity to quickly learn and adapt to new tools and methodologies.
  • Meticulous attention to detail in policy creation, audit documentation, and vulnerability analysis.
  • Ability to act calmly and effectively during security incidents and contribute to incident response efforts.

mail updated resume with salary details-

Key Skill:

information security manager, IT security, ISO 27001 LA, ISO 27001 LI, ISO 27001 LI/LA, ISO 27701, ISO 31000, internal auditor, DPDPA, CISM, compliance ISO 27001:2022

Read more
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos

About Marketwick

Founded :
2018
Type :
Products & Services
Size :
20-100
Stage :
Bootstrapped

About

N/A

Company social profiles

bloginstagramlinkedinfacebook

Similar jobs

OnActive
Mansi Gupta
Posted by Mansi Gupta
Delhi, Gurugram, Noida, Ghaziabad, Faridabad
6 - 10 yrs
₹2L - ₹4L / yr
Broking
Routing & Switching
Information security management system
Hardware troubleshooting
Firewall
+2 more

Responsibilities:

 • Managing all Network equipment and ensuring uptime

 • Attend the Incident Management calls.

 • Create diagrams as per the requirements with respect to process and locations.

 • Making configuration changes to devices, if any

 • To keep updating the documents.

 • Monitoring the network to determine capacity usage and escalate/ recommend necessary steps wit seniors.

 • Resolution of network faults within the time

 • Identifying LAN/WAN faults and resolving them through vendors providing maintenance services

 • Updating documentation of the LAN, like IP address register, PC IDs, Router configurations, hardware, network diagrams as and when changes happen.

 • Providing second level support for any network problems and troubleshooting the same in coordination with the vendor.

 • Creation of external and internal networks

 • Planning, implementation, and configuration of monitoring and maintenance network hardware and telecommunications links, including routers, switches, IDS, load-balancing, etc for expansions of network

 • Implementation and maintenance of network architecture components for managed services, including OS installation hardening management, implementation and maintenance of network monitoring tool sets

 • Establish and maintain a redundant network operations environment, including substantial software and hardware fail-over, monitoring and testing the configuration performance

 • Manage proper testing of the network environment, including simulations, stress testing, and benchmarks for both preventive maintenance and reporting purposes

 • Implementation and maintenance with consistent improvement of network security measures

 • Installation of router switches and LAN /WAN equipment

Read more
Why apply to jobs via Cutshort
people_solving_puzzle
Personalized job matches
Stop wasting time. Get matched with jobs that meet your skills, aspirations and preferences.
people_verifying_people
Verified hiring teams
See actual hiring teams, find common social connections or connect with them directly. No 3rd party agencies here.
ai_chip
Move faster with AI
We use AI to get you faster responses, recommendations and unmatched user experience.
21,01,133
Matches delivered
37,12,187
Network size
15,000
Companies hiring
Did not find a job you were looking for?
icon
Search for relevant jobs from 10000+ companies such as Google, Amazon & Uber actively hiring on Cutshort.
companies logo
companies logo
companies logo
companies logo
companies logo
Get to hear about interesting companies hiring right now
Company logo
Company logo
Company logo
Company logo
Company logo
Linkedin iconFollow Cutshort
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos