Website:
openhire.cc
Job details:
Information Security Officer
- Location: Chennai / Hybrid
- Experience: 2–4 years
- Employment Type: Full-time
- Salary: 5 LPA
About the Role
We are looking for an Information Security Officer / Analyst to support the Information Security function by implementing security controls, coordinating compliance activities, monitoring risks, supporting audits and assessments, and ensuring timely closure of security actions.
The role will work closely with Information Security, IT, Engineering, HR, Legal, Privacy and business teams to ensure that security policies and controls are consistently implemented across the organisation.
Key Responsibilities
- Support implementation of Information Security policies, standards and procedures.
- Maintain security control documentation, evidence, trackers and dashboards.
- Support periodic review and update of security policies.
- Track security risks, action items and remediation status.
- Support ISO 27001, SOC 2, HIPAA and other security/privacy assessments.
- Coordinate collection and organisation of audit evidence.
- Track audit findings and remediation actions.
- Support internal and external audit activities and maintain compliance records.
- Support user access provisioning, modification and removal processes.
- Conduct periodic access reviews and track privileged and sensitive access.
- Coordinate with IT and business owners to address access exceptions.
- Ensure joiner/mover/leaver security controls are completed.
- Track vulnerability assessments and remediation activities.
- Coordinate with IT and Engineering teams on vulnerability closure.
- Support security monitoring and investigation of alerts.
- Escalate suspicious activities or incidents to the senior security team.
- Maintain incident records and documentation.
- Support employee Information Security awareness programmes and phishing-awareness campaigns.
- Coordinate security training, track completion and assist with security drills.
- Support vendor security assessments and security questionnaires.
- Maintain third-party security assessment records and track outstanding actions.
- Work with IT, Engineering, HR, Legal, Privacy and business teams on security requirements.
- Follow up with stakeholders to ensure timely completion of security activities.
- Escalate delays, risks and exceptions to senior Information Security leadership.
- Support global security teams when India-specific information or documentation is required.
Experience & Qualifications
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, IT or a related field.
- 2–4 years of relevant experience in Information Security, Cybersecurity, IT Risk or Compliance.
- Working knowledge of ISO 27001, SOC 2, HIPAA, risk assessment, IAM, vulnerability management, incident management and security awareness.
- Exposure to cloud security environments such as AWS, Azure or GCP preferred.
- Experience supporting audits and security assessments.
- Strong documentation and coordination skills.
- Ability to work with multiple stakeholders and follow issues through to closure.
- Healthcare or health-tech experience is an advantage.
Click on Apply to know more.