14 ISO/IEC 27001:2005 Jobs in Bangalore (Bengaluru) | ISO/IEC 27001:2005 Job openings in Bangalore (Bengaluru)
Apply to 14+ ISO/IEC 27001:2005 Jobs in Bangalore (Bengaluru) on CutShort.io. Explore the latest ISO/IEC 27001:2005 Job opportunities across top companies like Google, Amazon & Adobe.
Bengaluru (Bangalore) · 1 - 3 years · ₹7L - ₹9L / yr · Bootstrapped · Posted 25 Sep 2026
At Shipthis, we are building a better future for freight forwarders by evolving traditional operations into fully digital, efficient, and scalable systems. We’re a fast-growing product company where every individual has the opportunity to take ownership, move fast, and create real impact. If you enjoy solving complex problems, shaping products from the ground up, and influencing technical direction, Shipthis is the place for you.
Learn more at www.shipthis.co
Role Overview
We are looking for an associate-level SecOps Engineer to support security operations, compliance, endpoint management, cloud infrastructure, and DevOps engineering. The role will work closely with the CTO/CISO and engineering team. Security and compliance are core responsibilities; when those priorities are lighter, the engineer will focus on CI/CD, infrastructure automation, reliability, monitoring, performance, and cloud cost optimization.
What You’ll be Doing
Security Operations
- Monitor infrastructure, application, and security alerts and assist with incident investigation.
- Review access controls, privileged accounts, service accounts, permissions, and periodic access reviews.
- Support infrastructure hardening, logging, monitoring, backup, recovery, and other security controls.
- Track security issues and corrective actions through closure.
Vulnerability Management
- Run and review application and infrastructure vulnerability scans.
- Maintain a vulnerability register and coordinate remediation with engineering teams.
- Support VAPT and penetration-testing exercises and validate closure of findings.
- Monitor dependencies, containers, operating systems, and cloud infrastructure for known vulnerabilities and patching needs.
Compliance & Governance
- Support ongoing ISO/IEC 27001, SOC 2, GDPR, customer-security, and internal-policy requirements.
- Maintain audit evidence, control registers, security policies, procedures, risk items, and remediation records.
- Assist with internal/external audits, vendor assessments, customer security questionnaires, and asset inventories.
- Maintain evidence for access reviews, vulnerability management, incidents, onboarding/offboarding, backups, and infrastructure changes.
MDM & Endpoint Security
- Administer the company MDM platform and enroll/manage company laptops, desktops, and mobile devices.
- Maintain device inventory and monitor endpoint compliance.
- Enforce approved controls such as disk encryption, screen locks, password requirements, patching, and endpoint protection.
- Support employee device onboarding/offboarding, approved application deployment, lost/stolen-device procedures, and remote wipe where authorized.
- Maintain endpoint security and MDM evidence required for audits and troubleshoot enrollment or policy issues.
DevOps, CI/CD & Cloud
- Maintain and improve CI/CD pipelines, deployment workflows, build times, caching, and rollback processes.
- Support production and non-production cloud infrastructure, networking, DNS, TLS certificates, IAM, and secrets.
- Automate repetitive deployment, infrastructure, security, and compliance tasks.
- Improve monitoring, logging, alerting, reliability, resource utilization, and cloud costs.
- Troubleshoot pipeline, deployment, and infrastructure issues and participate in root-cause analysis.
Required Fundamentals
- Basic knowledge of Linux, networking, HTTP/HTTPS, DNS, TLS, Git, Docker, cloud computing, APIs, and web applications.
- Understanding of IAM, MFA, least privilege, vulnerabilities/CVEs, encryption, logging, patching, and secrets management.
- Strong troubleshooting, ownership, attention to detail, and willingness to learn.
Desired Qualifications
- 1–2 years of experience with strong fundamentals are welcome.
- Basic scripting knowledge in Python, Bash, or similar.
- Interest in cybersecurity, cloud infrastructure, automation, and troubleshooting.
- Exposure to AWS/GCP/Azure, Terraform, GitHub Actions, Cloudflare, OWASP, vulnerability scanners, MDM, ISO 27001, or SOC 2 is a plus, not mandatory.
We Welcome Candidates:
- Who can join immediately
- Female candidates returning to work after a career break are strongly encouraged.
We are an equal opportunity employer and are committed to fostering diversity and inclusivity. We do not discriminate based on race, religion, color, gender, sexual orientation, age, marital status, or disability status.
Job Synopsys
Location: Bangalore
Job Type: Full-time, Permanent
Experience: 1-2 years
Industry: Software Product
Bengaluru (Bangalore) · 5 - 10 years · ₹15L - ₹18L / yr · Raised funding · Posted 23 Sep 2026
IT Systems Engineer
Location: Bengaluru, India · On-site | Experience: 5+ years in IT systems / infrastructure
Department: IT & Information Security | Employment Type: Full-time | Reports To: Engineering Leadership
Focus: Own the identity, endpoints, network, and compliance backbone that powers immersive technology at
scale.
The Mission
About Metadome.ai
Metadome.ai is an immersive 3D & XR technology company that enables cloud-based, photorealistic, and captivating customer experiences for brands. Our technology offers a complete stack for creating immersive 3D & XR applications with omni-channe deployment across both in-store and digital touchpoints, and over a multitude of devices. These experiences span a spectrum of use cases across the automotive, home décor, fashion, and cosmetics & accessories sectors. Our flagship automotive platform — Autodome — enables unprecedented photorealistic, cloud-based immersive 3D & XR applications that cover the entire pre-retail funnel, empowering brands to launch products virtually and drive awareness, engagement, and bookings among modern automotive consumers. Today, we are trusted partners to leading brands across the globe — including Unilever, MG Motor, Lexus, Asian Paints, Tata Motors, and Royal Enfield, among others. We have also partnered with the likes of TCS, SAP , and PwC, and are an active voice in the XR community, including the
Metaverse Standards Forum and the VR/AR Association.
About the Role
We are looking for a hands-on IT Systems Engineer to own and run the technology backbone that keeps our teams productive and our data secure. You will be the single point of accountability for IT operations and information security across a multi-location business where 24x7 systems availability is core to how we operate — managing identity, endpoints, network, and our cloud workspace, while operating and continuously hardening our GDPR, SOC 2, and ISO 27001 compliance posture.
This is a builder-operator role, not a supervisory one. We run a tight ship on security and compliance, and we expect you to have personally implemented and operated the systems and controls described below — you should know them inside out, down to the configuration, the evidence, and the edge cases.
Core Responsibilities
● Identity & Access Management — JumpCloud:
○ Own the JumpCloud directory end-to-end: user lifecycle (joiner / mover / leaver), groups, and organizational structure.
○ Administer SSO, enforce MFA, and configure conditional and device-based access policies across all SaaS applications.
○ Manage cross-platform device policies (macOS, Windows, Linux) via JumpCloud device management, including disk encryption and compliance baselines.
○ Integrate RADIUS / LDAP for Wi-Fi and application authentication.
○ Automate onboarding and offboarding to guarantee least-privilege access and clean, auditable deprovisioning.
● Google Workspace Administration — GWS:
○ Administer the Google Workspace tenant: users, groups, organizational units, and email routing.
○ Configure and enforce security controls — 2-Step Verification, context-aware access, DLP rules,
and sharing / visibility policies.○
○ Manage retention, eDiscovery, and legal holds through Google Vault. Optimize licensing and SaaS spend across Workspace and other portals.
Endpoint & Threat Protection — Sophos:
○ Deploy, configure, and manage Sophos Central (Intercept X / XDR) across all endpoints and
servers.
○ Monitor alerts, triage threats, and lead incident detection, response, and remediation.
○ Maintain endpoint encryption, web / application control, and device-hardening standards.
○ Where Sophos Firewall is in use, manage firewall policies, IPS, and secure remote access.
Network, Firewall & Wi-Fi:
○ Design, configure, and maintain firewalls, VLAN segmentation, VPN, and secure remote access.
○ Administer enterprise Wi-Fi and wired networks (switches, access points), including
RADIUS-backed authentication.
○ Manage LAN / WAN connectivity, ISP relationships, and network performance and uptime.
○ Implement network monitoring, intrusion detection, and centralized logging.
Hardware, Software & Asset Management:
○ Own the full hardware lifecycle — procurement, provisioning / imaging, maintenance, repair, and
decommissioning.
○ Support a mixed fleet of macOS, Windows, and Android devices, including high-performance workstations and XR / VR hardware used by our creative and engineering teams.
○ Maintain an accurate hardware and software inventory and asset register.
○ Manage software deployment, patch management, and license compliance.
Security, Risk & Compliance — GDPR · SOC 2 · ISO 27001:
○ Operate and continuously improve the company's Information Security Management System
(ISMS).
○ Own day-to-day compliance for GDPR, SOC 2 (Type II), and ISO/IEC 27001 — including control
implementation, evidence collection, and continuous monitoring.
○ Conduct risk assessments, internal audits, periodic access reviews, and vendor security / DPA
assessments.
○ Serve as a primary point of contact during external audits and customer security reviews.
○ Maintain security policies, records of processing (RoPA), DPIAs, and incident / breach-response
runbooks.
○ Drive security-awareness and phishing-simulation programs across the organization.
IT Operations & Support:
○ Ensure 24x7 high availability of core systems and meet defined uptime and SLA metrics.
○ Provide escalation-level troubleshooting and support across macOS, Windows, and Android.
○ Manage backups, disaster recovery, and business-continuity testing.
○ Coordinate internal teams and third-party vendors to deliver IT projects on time and within
budget.
○ Maintain documentation, runbooks, and standard operating procedures.
○ Own and report on the IT budget and asset allocation.
Required Skills & Experience
● 5+ years in IT systems / infrastructure engineering — with direct, hands-on ownership of the systems
below rather than purely supervisory exposure.
● JumpCloud — demonstrated hands-on expertise across identity, SSO, MFA, and device management.
● Google Workspace (GWS) — deep admin-console experience including security, DLP , and Vault.
● Sophos — hands-on endpoint / XDR administration and threat response.
● Networking — firewall configuration, Wi-Fi, VLANs, VPN, LAN / WAN, and RADIUS / LDAP fundamentals.
● GDPR, SOC 2 & ISO 27001 — hands-on — you have personally taken an organization through at least one
full audit / certification cycle and know the controls, evidence, and auditor expectations inside out.
Cross-platform support — proven troubleshooting across macOS, Windows, and Android in a 24x7, multi-location environment.
System security — solid grasp of IDS / IPS, endpoint hardening, encryption, and backup / recovery.
Education — B.Sc. / B.Tech in Information Technology, Computer Science, or a related discipline.
Mindset — strong documentation discipline, ownership, resourcefulness, and a structured, problem-solving approach.
Preferred Qualifications
●Relevant certifications — e.g., ISO 27001 Lead Implementer / Auditor, CompTIA Security+ / Network+, or vendor certifications from JumpCloud and Sophos.
●Experience with compliance-automation platforms such as Sprinto, Vanta, or Drata.
●Scripting and automation for IT operations (Bash, PowerShell, or Python).
●Experience in a fast-paced SaaS or technology company serving enterprise and global clients.
●Familiarity with supporting creative, 3D, or XR workflows and high-performance computing environments.
Why Join Us
You will own the systems and security posture of a company building category-defining immersive technology for some of the world's most recognizable brands. It is a high-trust, high-ownership role with the autonomy to design things properly — and the visibility that comes with keeping a security- and compliance-first business running
flawlessly.
Bengaluru (Bangalore), Chennai · 4 - 15 years · Profitable · Posted 10 Mar 2026
Job Description:
We are looking for a skilled Ethical Hacker (Penetration Tester) who will be responsible for identifying vulnerabilities in systems, networks, and applications before malicious hackers can exploit them. The role involves conducting security assessments, penetration testing, and recommending security improvements to strengthen the organization’s cybersecurity posture.
Key Responsibilities
· Conduct penetration testing on web applications, mobile applications, APIs, and networks.
· Identify security vulnerabilities and weaknesses in systems and infrastructure.
· Perform vulnerability assessments using automated tools and manual techniques.
· Simulate cyberattacks to evaluate the effectiveness of existing security measures.
· Prepare detailed security reports highlighting risks, vulnerabilities, and remediation strategies.
· Collaborate with development, DevOps, and IT teams to fix security gaps.
· Ensure compliance with security standards and frameworks such as OWASP, ISO 27001, and NIST.
· Conduct security audits and risk assessments across digital platforms.
· Stay updated on the latest hacking techniques, security vulnerabilities, and cyber threats.
Required Skills & Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or related field.
- 4+ years of experience in ethical hacking, penetration testing, or cybersecurity.
- Strong knowledge of network security, system security, and application security.
- Experience with security tools such as:
- Burp Suite
- Metasploit
- Nmap
- Wireshark
- Kali Linux
- Knowledge of OWASP Top 10 vulnerabilities.
- Understanding of Linux, Windows, and cloud security environments.
- Strong analytical and problem-solving skills.
Preferred Certifications
- CEH (Certified Ethical Hacker)
- OSCP (Offensive Security Certified Professional)
- CompTIA Security+
- CISSP (optional but valuable)
Key Competencies
- Cybersecurity risk assessment
- Vulnerability management
- Penetration testing methodologies
- Incident response awareness
- Strong documentation and reporting skills
Nice to Have
- Experience in cloud security (AWS, Azure, GCP)
Bengaluru (Bangalore) · 6 - 10 years · ₹30L - ₹50L / yr · Posted 30 Dec 2025
SENIOR INFORMATION SECURITY ENGINEER (DEVSECOPS)
Key Skills: Software Development Life Cycle (SDLC), CI/CD
About Company: Consumer Internet / E-Commerce
Company Size: Mid-Sized
Experience Required: 6 - 10 years
Working Days: 5 days/week
Office Location: Bengaluru [Karnataka]
Review Criteria:
Mandatory:
- Strong DevSecOps profile
- Must have 5+ years of hands-on experience in Information Security, with a primary focus on cloud security across AWS, Azure, and GCP environments.
- Must have strong practical experience working with Cloud Security Posture Management (CSPM) tools such as Prisma Cloud, Wiz, or Orca along with SIEM / IDS / IPS platforms
- Must have proven experience in securing Kubernetes and containerized environments including image security,runtime protection, RBAC, and network policies.
- Must have hands-on experience integrating security within CI/CD pipelines using tools such as Snyk, GitHub Advanced Security,or equivalent security scanning solutions.
- Must have solid understanding of core security domains including network security, encryption, identity and access management key management, and security governance including cloud-native security services like GuardDuty, Azure Security Center etc
- Must have practical experience with Application Security Testing tools including SAST, DAST, and SCA in real production environments
- Must have hands-on experience with security monitoring, incident response, alert investigation, root-cause analysis (RCA), and managing VAPT / penetration testing activities
- Must have experience securing infrastructure-as-code and cloud deployments using Terraform, CloudFormation, ARM, Docker, and Kubernetes
- B2B SaaS Product companies
- Must have working knowledge of globally recognized security frameworks and standards such as ISO 27001, NIST, and CIS with exposure to SOC2, GDPR, or HIPAA compliance environments
Preferred:
- Experience with DevSecOps automation, security-as-code, and policy-as-code implementations
- Exposure to threat intelligence platforms, cloud security monitoring, and proactive threat detection methodologies, including EDR / DLP or vulnerability management tools
- Must demonstrate strong ownership mindset, proactive security-first thinking, and ability to communicate risks in clear business language
Roles & Responsibilities:
We are looking for a Senior Information Security Engineer who can help protect our cloud infrastructure, applications, and data while enabling teams to move fast and build securely.
This role sits deep within our engineering ecosystem. You’ll embed security into how we design, build, deploy, and operate systems—working closely with Cloud, Platform, and Application Engineering teams. You’ll balance proactive security design with hands-on incident response, and help shape a strong, security-first culture across the organization.
If you enjoy solving real-world security problems, working close to systems and code, and influencing how teams build securely at scale, this role is for you.
What You’ll Do-
Cloud & Infrastructure Security:
- Design, implement, and operate cloud-native security controls across AWS, Azure, GCP, and Oracle.
- Strengthen IAM, network security, and cloud posture using services like GuardDuty, Azure Security Center and others.
- Partner with platform teams to secure VPCs, security groups, and cloud access patterns.
Application & DevSecOps Security:
- Embed security into the SDLC through threat modeling, secure code reviews, and security-by-design practices.
- Integrate SAST, DAST, and SCA tools into CI/CD pipelines.
- Secure infrastructure-as-code and containerized workloads using Terraform, CloudFormation, ARM, Docker, and Kubernetes.
Security Monitoring & Incident Response:
- Monitor security alerts and investigate potential threats across cloud and application layers.
- Lead or support incident response efforts, root-cause analysis, and corrective actions.
- Plan and execute VAPT and penetration testing engagements (internal and external), track remediation, and validate fixes.
- Conduct red teaming activities and tabletop exercises to test detection, response readiness, and cross-team coordination.
- Continuously improve detection, response, and testing maturity.
Security Tools & Platforms:
- Manage and optimize security tooling including firewalls, SIEM, EDR, DLP, IDS/IPS, CSPM, and vulnerability management platforms.
- Ensure tools are well-integrated, actionable, and aligned with operational needs.
Compliance, Governance & Awareness:
- Support compliance with industry standards and frameworks such as SOC2, HIPAA, ISO 27001, NIST, CIS, and GDPR.
- Promote secure engineering practices through training, documentation, and ongoing awareness programs.
- Act as a trusted security advisor to engineering and product teams.
Continuous Improvement:
- Stay ahead of emerging threats, cloud vulnerabilities, and evolving security best practices.
- Continuously raise the bar on a company's security posture through automation and process improvement.
Endpoint Security (Secondary Scope):
- Provide guidance on endpoint security tooling such as SentinelOne and Microsoft Defender when required.
Ideal Candidate:
- Strong hands-on experience in cloud security across AWS and Azure.
- Practical exposure to CSPM tools (e.g., Prisma Cloud, Wiz, Orca) and SIEM / IDS / IPS platforms.
- Experience securing containerized and Kubernetes-based environments.
- Familiarity with CI/CD security integrations (e.g., Snyk, GitHub Advanced Security, or similar).
- Solid understanding of network security, encryption, identity, and access management.
- Experience with application security testing tools (SAST, DAST, SCA).
- Working knowledge of security frameworks and standards such as ISO 27001, NIST, and CIS.
- Strong analytical, troubleshooting, and problem-solving skills.
Nice to Have:
- Experience with DevSecOps automation and security-as-code practices.
- Exposure to threat intelligence and cloud security monitoring solutions.
- Familiarity with incident response frameworks and forensic analysis.
- Security certifications such as CISSP, CISM, CCSP, or CompTIA Security+.
Perks, Benefits and Work Culture:
A wholesome opportunity in a fast-paced environment that will enable you to juggle between concepts, yet maintain the quality of content, interact and share your ideas and have loads of learning while at work. Work with a team of highly talented young professionals and enjoy the comprehensive benefits that company offers.
Bengaluru (Bangalore) · 4 - 8 years · ₹9L - ₹15L / yr · Profitable · Posted 22 Sep 2023
Information Security Manager shall be primarily responsible to :
- Run and manage the BAU security infosec operations
- Create and maintain ISMS Policy and Process documents
- Ensure Infosec compliance with RBI and other regulatory agencies
- Participate in IT / Infosec Audits and ensure closure of observations within given timeliness
- Conduct regular VAPT (Vulnerability Assessments) and track closure of open observations
- Identifying and evaluating new IT security technologies and services and implementing it
- Ensure cyber security related polices and technologies are in place
- Conducting regular Inforsec Awareness within users in the organization
- The person needs to work closely with the CISO and other stakeholders – Risk, IT and Audit teams.
Key Accountability:
- Ensuring adequate security controls are in place & working effectively within the organization for information & cyber security
- Ensuring effectiveness of all IT controls to prevent any unauthorized access or activities at a system administration level
- Identify potential security weaknesses through vulnerability assessments and track them to closure within the timeliness
- Tracking and reporting key risk indicators defined for IT processes
- Create and maintain the documentation for information system audits in accordance with regulatory and compliance requirements
- Create / Review ISMS policy and process
- Implement Strategic IT Infosec projects to strengthen the overall IT Security posture
Bengaluru (Bangalore) · 7 - 14 years · Profitable · Posted 5 Jun 2023
Experience:- Overall 10 to 12 years of experience of which atleast 5 to 7 years’ experience should be in Information Security. Mandatory is 5 to 7 years’ experience in Information security and with one full end to end implementation experience.
Base location: - Bengaluru - Must
Requirements: -
- Mandatory - ISO 27001:2013 lead implementor certified
- Mandatory - ISO 27001:2013 lead auditor certified (but if it is a good candidate, we can still consider)
- Good to have – CISA, CISM, Risk management certification, Privacy certifications.
- Mandatory - Atleast one end to end implementation experience of ISO 27001 standard. The candidate should have a good implementation knowledge of ISO 27001, ISO 27002 standards and is required to implement the ISO requirements and run the ISMS program for multiple countries.
- This immediate requirement is for implementing the ISMS program for our Canadian office location. The candidate should be willing to work from Bengaluru in EST time zone during this implementation phase whenever required.
- Good documentation skills.
- Develop, implement, maintain, review and continually improve Information Security policies.
- Good understanding and knowledge of applicable legal and regulatory requirements as relevant to information security.
- Manage and maintain a risk register / risk database along with risk treatment plans.
- Good understanding of physical and environmental security.
- Conduct Internal Audits based ISO 27001 standards and Personal Data Protection policies. A good experience in independently conducting Internal and supplier audit with respect to information security.
- Provide training to the employees on Privacy & Information Security Management System on regular intervals.
- The greater part of the job involves interacting with people, interviewing them / auditing, Preparing audit reports, discussing / persuading / influencing.
- Mandatory: Good verbal and written communication skills. Eye for details.
- Good presentation skills.
- Since this is a trusted role, candidates must be willing to undergo extensive background checks to verify their identity, character, qualifications, skills and experience.
Bengaluru (Bangalore) · 7 - 10 years · ₹5L - ₹10L / yr · Profitable · Posted 25 May 2023
Experience:- Overall 10 to 12 years of experience of which atleast 5 to 7 years’ experience should be in Information Security. Mandatory is 5 to 7 years’ experience in Information security and with one full end to end implementation experience.
Base location: - Bengaluru - Must
Joining requirement: - Not later than second week of June 2023.
Requirements: -
1. Mandatory - ISO 27001:2013 lead implementor certified
2. Mandatory - ISO 27001:2013 lead auditor certified (but if it is a good candidate, we can still consider)
3. Good to have – CISA, CISM, Risk management certification, Privacy certifications.
4. Mandatory - Atleast one end to end implementation experience of ISO 27001 standard. The candidate should have a good implementation knowledge of ISO 27001, ISO 27002 standards and is required to implement the ISO requirements and run the ISMS program for multiple countries.
5. This immediate requirement is for implementing the ISMS program for our Canadian office location. The candidate should be willing to work from Bengaluru in EST time zone during this implementation phase whenever required.
6. Good documentation skills.
7. Develop, implement, maintain, review and continually improve Information Security policies.
8. Good understanding and knowledge of applicable legal and regulatory requirements as relevant to information security.
9. Manage and maintain a risk register / risk database along with risk treatment plans.
10. Good understanding of physical and environmental security.
11. Conduct Internal Audits based ISO 27001 standards and Personal Data Protection policies. A good experience in independently conducting Internal and supplier audit with respect to information security.
12. Provide training to the employees on Privacy & Information Security Management System on regular intervals.
13. The greater part of the job involves interacting with people, interviewing them / auditing, Preparing audit reports, discussing / persuading / influencing.
14. Mandatory: Good verbal and written communication skills. Eye for details.
15. Good presentation skills.
16. Since this is a trusted role, candidates must be willing to undergo extensive background checks to verify their identity, character, qualifications, skills and experience.
Bengaluru (Bangalore) · 4 - 10 years · ₹11L - ₹20L / yr · Bootstrapped · Posted 10 Feb 2023
1) Determine client needs and expectations and participate in the development of the overall client service plan. Analyse, develop, and implement information security programs, including organizational design and key processes for our clients as per plans
2)Design and develop cyber security strategies and programs for large and complex organizations
3)Define and implement cyber risk management structures, governance models, organizational transformations in the areas of cyber security
4)Develop security policies, processes, procedures. Map controls and compliance requirements. Responsible for risk assessments, gap analysis (against standards and benchmarks), risk mitigation strategy development.
4)Roll out the GRC Cybersecurity controls framework while balancing the approach with end user experience and compliance
5)Develop and tailor approaches, methods and tools to support clients cyber risk programs and initiatives
6)Provide strategic and operational advice in the areas of safeguarding critical information. Identify areas requiring improvement in the client's business processes to enable preparation of recommendations. 7)Evaluate, implement and operationalize security controls, define metrics for measure performance and establish a framework for continuous monitoring and improvement and Play substantive role in internal and external client relationship and communication
8)Interact with CxOs to define the roadmap for GRC strategy.
9Help build Cyber Transformation practice by getting involved in areas beyond engagement delivery such as pre-sales, RFP response, solution designing, competency development and Go to market strategies
10)Create or help create though leadership content in the emerging areas of Cyber Strategy and Risk Transformation .
Immediate Joiners
Bangalore · 5 - 10 years · ₹15L - ₹30L / yr · Posted 26 Aug 2022
What are we looking for?
An enthusiastic individual with the following skills. Please do not hesitate to apply if you do not match all of it. We are open to promising candidates who are passionate about their work and are team players.
Key Responsibilities & expectations from the candidate
- Must have strong experience in Information Security Management system(ISMS), creation of policy, procedures and implementation.
- Operates as a key contributor to the RFP, Third-Party Risk assessment, cloud security assessment etc.
- Lead the strategic and tactical development of information security framework, risk management and new compliance initiatives
- Subject matter expertise in ISO 27001, SOC2, CCPA, CPRA, GDPR, PCI DSS and HIPAA.
- Must have a strong experience in the documentation process and reviewing MSA, SCC, SLA & DPA.
- Good knowledge of BCP/DR, Incident response, VA/PT and Audit methodologies of various compliance frameworks.
- Good knowledge of Access management, Network, Application Security, Encryption, Backup, Physical Security, ISMS Training & Awareness etc..
- Ability to deal with the customers and vendors on Security and privacy matters.
- Knowledge of Core IT processes, SDLC, network infrastructure will be useful.
Personal Attributes
- Good written, oral, and interpersonal communication skills.
- Ability to conduct research into IT security issues
- Ability to present ideas in business-friendly and user-friendly language.
- Ability to effectively prioritize and execute tasks in a high-pressure environment.
- Highly self-motivated and hardworking.
Qualification and certification
- Bachelor’s/master's degree in Security, Computer Science, Management Information Systems, Engineering or related field.
- Should be at least ISO 27001 lead auditor or lead implementer.
- 3+ years of related work experience in information security governance, risk and compliance (GRC) or relevant compliance roles in the SaaS industry.
What can you look for?
A wholesome opportunity in a fast-paced environment that will enable you to juggle between concepts, yet maintain the quality of content, interact, and share your ideas and have loads of learning while at work. Work with a team of highly talented young professionals and enjoy the benefits of being here.
We are
It is a rapidly growing fintech SaaS firm that propels business growth while focusing on human motivation. Backed by Giift and Apis Partners Growth Fund II, Company offers a suite of three products - Plum, Empuls, and Compass. Company works with more than 2000 clients across 10+ countries and over 2.5 million users. Headquartered in Bengaluru, Company is a 300+ strong team with four global offices in San Francisco, Dublin, Singapore, New Delhi.
Way forward
We look forward to connecting with you. As you may take time to review this opportunity, we will wait for a reasonable time of around 3-5 days before we screen the collected applications and start lining up job discussions with the hiring manager. We however assure you that we will attempt to maintain a reasonable time window for successfully closing this requirement. The candidates will be kept informed and updated on the feedback and application status.
Bengaluru (Bangalore) · 3 - 6 years · ₹20L - ₹30L / yr · Posted 9 Aug 2022
What are we looking for?
An enthusiastic individual with the following skills. Please do not hesitate to apply if you do not match all of it. We are open to promising candidates who are passionate about their work and are team players.
Key Responsibilities & expectations from the candidate
- Must have strong experience in Information Security Management system(ISMS), creation of policy, procedures and implementation.
- Operates as a key contributor to the RFP, Third-Party Risk assessment, cloud security assessment etc.
- Lead the strategic and tactical development of information security framework, risk management and new compliance initiatives
- Subject matter expertise in ISO 27001, SOC2, CCPA, CPRA, GDPR, PCI DSS and HIPAA.
- Must have a strong experience in the documentation process and reviewing MSA, SCC, SLA & DPA.
- Good knowledge of BCP/DR, Incident response, VA/PT and Audit methodologies of various compliance frameworks.
- Good knowledge of Access management, Network, Application Security, Encryption, Backup, Physical Security, ISMS Training & Awareness etc..
- Ability to deal with the customers and vendors on Security and privacy matters.
- Knowledge of Core IT processes, SDLC, network infrastructure will be useful.
Personal Attributes
- Good written, oral, and interpersonal communication skills.
- Ability to conduct research into IT security issues
- Ability to present ideas in business-friendly and user-friendly language.
- Ability to effectively prioritize and execute tasks in a high-pressure environment.
- Highly self-motivated and hardworking.
Qualification and certification
- Bachelor’s/master's degree in Security, Computer Science, Management Information Systems, Engineering or related field.
- Should be at least ISO 27001 lead auditor or lead implementer.
- 3+ years of related work experience in information security governance, risk and compliance (GRC) or relevant compliance roles in the SaaS industry.
What can you look for?
A wholesome opportunity in a fast-paced environment that will enable you to juggle between concepts, yet maintain the quality of content, interact, and share your ideas and have loads of learning while at work. Work with a team of highly talented young professionals and enjoy the benefits of being at Xoxoday.
We are
Xoxoday is a rapidly growing fintech SaaS firm that propels business growth while focusing on human motivation. Backed by Giift and Apis Partners Growth Fund II, Xoxoday offers a suite of three products - Plum, Empuls, and Compass. Xoxoday works with more than 2000 clients across 10+ countries and over 2.5 million users. Headquartered in Bengaluru, Xoxoday is a 300+ strong team with four global offices in San Francisco, Dublin, Singapore, New Delhi.
Way forward
We look forward to connecting with you. As you may take time to review this opportunity, we will wait for a reasonable time of around 3-5 days before we screen the collected applications and start lining up job discussions with the hiring manager. We however assure you that we will attempt to maintain a reasonable time window for successfully closing this requirement. The candidates will be kept informed and updated on the feedback and application status.
Bengaluru (Bangalore), Pune, Mumbai, Delhi · 3 - 8 years · ₹5L - ₹15L / yr · Profitable · Posted 14 Feb 2022
Qualifications & Responsibilities
Year of Experience : 3- 8 yrs
Location : Bangalore, Delhi, Mumbai, Pune
Work on ISO 27001 & NIST based Information Security Management System implementation and sustenance.
- Responsible for SOX (IT Security Controls) and track the monthly/quarterly/annual control reports and drive effectiveness of SOX controls.
- Work on Business Continuity Planning, IT Disaster Recovery as per ISO27001 & NIST requirements
- Assess information security posture, identify the gaps/risks in the existing environment and develop solutions to mitigate the identified gaps/risk
- Conduct Information Systems audits covering IT infrastructure assets
- Working knowledge in security domains such as: security governance policies and procedures, risk management, compliance, access control, network security, security architecture, security incident response, disaster recovery, business continuity management, privacy and data protection
- Experience in leveraging industry standards and frameworks such as ISO/IEC 27001, NIST CSF/800-171, etc.
- Possesses certifications such as ISO27001 LA. CISSP, CISA certification- preferred
Why NCG?
WHO WE ARE DRIVES WHAT WE DO!
We Don't build the organization; we create an everlasting family. Our people express a sense of winning together when times are good and sticking together when times are tough.
Are you a Doer or Achiever?
Well, at NCG, our doors are Open for Doers and Achievers alike. We are a Cult where we create, innovate, learn and Contribute in a comfortable, transparent, and fair environment.
Joining NCG means contributing to a shared ambition for reliable work culture, tackling extraordinary technological challenges in multicultural teams, preserving your work/life balance, and more!
Bengaluru (Bangalore) · 2 - 5 years · ₹6L - ₹12L / yr · Posted 12 Oct 2021
The Role
We are looking foran Information Security Analyst – Compliance to primarily strengthen our practice towards compliances such as HIPAA, HITRUST,etc. and ensure highest levels of security around sensitive data.
- Identifying new risks and performing risk assessments.
- Performing continuous gap analysis.
- Auditing the applications, configurations, and internal practices against standards such as HIPAA, HITRUST etc.
- Providing advice and implementing forward-thinking information security policies, procedures, and standards.
- Assisting several teams (internal and external) with best practicesand security consultations.
- Supporting with other information security activities as assigned.
- Ensuring the organizational compliance during audits and certification efforts.
Requirements:
- Demonstrated experience in implementing and maintaining security standards such as HIPAA, HITRUST, SOC2, ISO 27001 etc.
- Ability to understand and interpret legal, regulatory, and contractual compliance requirements.
- Experience in InfoSec policy creation and documentation.
- Ability to understand technology and pertaining risks.
- Knowledge on IT, Servers, SDLC, Database, etc.
- Experience working with / securing cloud-based applications is an add-on.
- 2+ years of experience.
- Excellent written and verbal communication skills.
- Relevant Security Certifications will be a good add-on.
Bengaluru (Bangalore) · 3 - 5 years · ₹4L - ₹12L / yr · Raised funding · Posted 6 Aug 2021
Job Title: QA Associate
Job Description:
- Responsible for Implementing, controlling and monitoring quality management system documentation (ISO 27001) and data privacy (SOC2).
- Coordinate improvement in the system through output from audit, management review, and responsible to close NC’s during audits.
- Knowledge of SAMD (Software as Medical Device) SaaS product, processes and procedures.
3-5 years of relevant experience in Medical Devices Industry.
Area of Expertise:
- To generate, implement and maintain internal quality procedures and systems to comply with ISO 27001, SOC2 standards
- Maintaining and updating various documents like internal docs log, external log, , Obsolete docs log, DCN, ECN, CAPA, SQA/IQA log, product complaint, equipment log
- Maintaining Engineering documents like part specs, Bill of materials, Drawings, Design review documents etc
- Co-ordinate and conduct periodic internal audits of various functional groups of an organization and drive compliance to QMS.
- Manage all documentation related to internal and external audit.
- Manage all the documents related to supplier qualification and coordinate Supplier’s audit and maintain the supplier file.
- Experience in Handling of CAPA (Corrective & Preventive Actions) & Product Complaints
- Co-ordination of Management Review Meetings & its action items implementation
Experience Required:
- 3-5 years of relevant experience in Medical Devices Industry.
- Educational Qualification – Diploma/Engineering graduate, preferably Computer Science or related.
- Ability to read and understand standard requirements independently.
- Good teamwork, communication and interpersonal skills. A demonstrated commitment to company values
- Good understanding of design control, and post marketing processes
- Knowledge of FDA / EU / Indian & other national regulations is an added advantage.
- Working knowledge of an e-QMS is an added advantage.
Bengaluru (Bangalore) · 4 - 8 years · ₹12L - ₹18L / yr · Raised funding · Posted 22 Jan 2021
What you’ll be doing:
- Establish, implement and monitor a strategic, comprehensive enterprise information security and IT risk management program
- Work directly with the business units to facilitate risk assessment and risk management processes
- Develop and enhance an information security management framework
- Understand and interact with related disciplines through committees to ensure the consistent application of policies and standards across all technology projects, systems and services
- Provide leadership to the enterprise's information security organization
- Partner with business stakeholders across the company to raise awareness of risk management concerns
- Assist with the overall business technology planning, providing a current knowledge and future vision of technology and systems
- Conduct regular internal audits in compliance with applicable legal and contractual requirements, ISO 27001 and PCI DSS requirements and companies internal requirements
- Conduct regular Management reviews and update the management on information security aspects. The MRMs shall also focus on drawing Management attentions to the key areas for required management actions.
- CISO is also responsible to ensure customer audits as well as re-certification and surveillance audits and successful.
- Coordinate with relevant stakeholders to address the NC closures.
- CISO shall ensure the information incidents are responded and resolved on time to ensure compliance with legal and contractual requirements.
What you’ll bring along:
- Degree in business administration or a technology-related field required.
- Professional security management certification
- Minimum of 5 years of experience in a combination of risk management, information security and IT jobs
- Knowledge of common information security management frameworks, such as ISO/IEC 27001, and PCI DSS.
- Excellent written and verbal communication skills and high level of personal integrity
- Innovative thinking and leadership with an ability to lead and motivate cross-functional, interdisciplinary teams
- Experience with contract and vendor negotiations and management including managed services.
- Specific experience in Agile (scaled) software development or other best in class development practices.
- Experience with Cloud computing/Elastic computing across virtualized environments.









