Admaren Tech Private Limited
Website:
admaren.com
Job details:
Job Title: Information Security Manager
Seniority Level: Senior Level
Years of Relevant Experience: 5+ Years
Department: Information Technology
Reporting Organization: Admaren Tech
Employment Type: Full-time
Location: Kochi
Job Summary
We are seeking an experienced Information Security Manager to lead the design, implementation, and continuous improvement of our Information Security Management System (ISMS) in accordance with the ISO/IEC 27001 standard. You will act as the subject matter expert for all things related to information security governance, risk management, and compliance. The ideal candidate has hands-on experience driving an organization from gap analysis through to successful ISO 27001 certification and managing the system post-certification.
Key Responsibilities
1. ISMS Implementation & Management
- Lead the end-to-end implementation and continuous improvement of the ISMS based on ISO/IEC 27001:2022 standards.
- Develop, publish, and maintain comprehensive information security policies, procedures, standards, and guidelines.
- Define and maintain the Statement of Applicability (SoA) and ensure all selected controls are effectively implemented.
2. Risk Assessment & Management
- Conduct regular information security risk assessments and business impact analyses (BIA).
- Develop and track Risk Treatment Plans (RTP) and maintain the corporate risk register.
- Collaborate with department heads to ensure security risks are identified, understood, and mitigated to acceptable levels.
3. Audit & Compliance
- Plan, manage, and conduct internal ISMS audits to measure compliance and operational effectiveness.
- Act as the primary liaison for external certification bodies and third-party auditors during surveillance and certification audits.
- Track non-conformities and ensure corrective and preventative actions (CAPA) are completed on time.
- Assist with vendor security risk assessments and client security questionnaires.
4. Incident Management & Operations
- Oversee the information security incident management process, ensuring timely identification, containment, eradication, and recovery.
- Lead post-incident reviews and integrate lessons learned into the ISMS.
- Monitor compliance with data protection laws (e.g., GDPR, CCPA, DPDP Act) in collaboration with the legal/privacy team.
5. Training & Awareness
- Design and deliver ongoing information security awareness training for all employees and contractors.
- Promote a culture of security by launching phishing simulations and regular communications.
Required Skills & Qualifications
- Education: Bachelor’s degree in computer science, Information Security, Cybersecurity, or a related field (or equivalent practical experience).
- Experience: Minimum of 5+ years of dedicated experience in Information Security or GRC, with at least 2+ years taking a primary role in managing or implementing an ISO 27001 ISMS.
- Certifications:
- Mandatory: ISO/IEC 27001 Lead Implementer and/or Lead Auditor.
- Highly Preferred: CISM (Certified Information Security Manager), CISSP, CISA, or CRISC.
- Technical Knowledge: Strong understanding of network security, cloud security (AWS/Azure/GCP), identity and access management (IAM), and endpoint protection.
- Soft Skills: Excellent written and verbal communication skills, with the ability to translate complex security requirements into business-friendly language for executive stakeholders.
Key Competencies
- Strong expertise in ISO/IEC 27001:2022 implementation and ISMS management.
- Experience in risk assessment, compliance, and internal/external audits.
- Knowledge of cloud security, IAM, network security, and security governance.
- Excellent stakeholder management, communication, and problem-solving skills.
- Ability to drive a security-first culture through awareness and continuous improvement.
Why Join Us?
- Lead the organization's ISO/IEC 27001 certification and information security initiatives.
- Work with global teams on innovative technology solutions in the maritime industry.
- Enjoy opportunities for professional growth, continuous learning, and certifications.
- Be part of a collaborative, innovation-driven organization where security is a strategic priority.
Click on Apply to know more.