Promaynov Advisory Services Pvt. Ltd
Website:
promaynov.com
Job details:
Manager - Information Security
Department: Technology
Reporting To: SVP - Technology
Location: New Delhi
Role Overview
The Manager - Information Security will be responsible for establishing and managing the
organization's information security framework. The role will lead ISO 27001 certification,
drive information security operations, and manage internal and external audits while ensuring
compliance with applicable regulatory requirements.
The ideal candidate will have strong experience in information security operations,
compliance, ISO 27001 implementation, and audit management.
Key Responsibilities
ISO Certification & Compliance
Own the end-to-end ISO 27001 ISMS implementation and certification lifecycle,
from gap assessment through certification and surveillance audits.
Coordinate with certification bodies and internal stakeholders to ensure audit
readiness.
Track and close non-conformities and maintain audit documentation and corrective
action plans.
Ensure compliance with applicable regulations, including the IT Act, DPDP Act, and
CERT-In advisories.
Security Operations
Manage day-to-day information security operations, including threat monitoring,
incident response, and vulnerability management.
Administer security tools such as SIEM, Endpoint Protection, WAF, IAM, and DLP
solutions.
Define and enforce security baselines across cloud infrastructure and API
environments.
Collaborate with engineering teams to integrate security practices into the software
development lifecycle (DevSecOps).
Risk Management & Governance
Conduct periodic risk assessments and maintain a risk register with mitigation plans.
Develop, review, and maintain information security policies, standards, and
procedures.
Perform security assessments for third-party vendors and partners.
Report security metrics and risk posture to senior leadership.
Audit Management
Plan and execute internal information security audits across systems, processes, and
integrations.
Coordinate with external auditors and regulatory bodies during audit engagements.
Maintain audit trails and compliance evidence repositories.
Prepare management review reports and security posture updates for leadership.
Candidate Profile
Experience
8-10 years of experience in Information Security, including hands-on ownership of
ISO 27001 implementation and audit cycles.
Strong experience in security operations, including SOC management, incident
response, and vulnerability management.
Good understanding of cloud security (AWS, Azure, or GCP) and API security
principles.
Certifications
ISO 27001 Lead Implementer or Lead Auditor.
CISSP and/or CISM certification preferred.
Skills
Strong communication and stakeholder management skills.
Ability to work effectively with both technical teams and senior leadership.
Strong analytical, governance, and risk management capabilities.
Click on Apply to know more.