Website:
acuityanalytics.com
Job details:
Job description
Job description
Acuity Analytics (the trading name of Acuity Knowledge Partners) is a global, tech-first organisation helping financial institutions and corporates make better decisions through research, data, analytics and AI-enabled solutions. We combine deep financial services expertise with strong engineering, digital and AI capabilities to solve complex, real-world problems.
With a team of 7,200+ analysts, data specialists and technologists across 28 locations, we work with more than 800 organisations worldwide to drive efficiency, unlock insight and deliver measurable impact. Our success is built on the strength of our peopleby investing in talent, encouraging collaboration and creating room to grow, we enable our teams to do their best work for clients.
Acuity became an independent business in 2019 following its acquisition from Moodys Corporation by Equistone Partners Europe. In 2023, funds advised by global private equity firm Permira acquired a majority stake, with Equistone remaining a minority investor—supporting our continued growth and innovation.
For more information, visit www.acuityanalytics.com
Basic information
Position Title-Information Security Manager / Senior Manager
Experience Level-8-10 years
Department-Information Security
Location-Gurgaon
Job purpose
- Lead practical information security, cloud security and GRC activities across business units, client accounts and corporate functions, with a strong focus on AI governance, cloud security, third-party risk, audit readiness and automation of repetitive compliance controls.
- Translate ISO 27001, SOC 2, applicable regulatory requirements, client security expectations and internal policies into business processes that are effective, auditable and operationally sustainable.
- Act as a hands-on security professional who can assess technical risks, guide remediation, lead audits, manage risk exceptions and introduce AI-enabled workflow automation to improve compliance efficiency.
- Role Design: 60% Technical Security and 40% GRC / Process Compliance
Area
Technical Security Expectations - 60%
GRC / Process Compliance Expectations - 40%
Cloud & Infrastructure
Hands-on control assessment across Azure, AWS, Microsoft 365, IAM, endpoint, network, logging, monitoring, vulnerability management, conditional access, DLP, encryption and configuration governance.
Ensure cloud and infrastructure controls are mapped to ISO 27001, SOC 2, client contracts, internal policies and audit evidence expectations.
AI Governance & Automation
Assess AI-related security, data protection and operational risks; support governance of AI tools, AI agents and GenAI use cases; identify opportunities for control automation.
Embed AI governance, human oversight, policy adherence, evidence retention and exception workflows into practical SOPs and business processes.
Third-Party & Supply Chain Risk
Evaluate vendor security posture, cloud hosting, data handling, access management, resilience and subcontractor risk.
Run third-party risk assessments, track remediation, manage exceptions, maintain GRC records and align vendor risk decisions with policy and client requirements.
Audit & Risk Management
Test technical control effectiveness and validate remediation for security findings across on-premise, cloud and SaaS environments.
Lead internal audits, client audits, ISO 27001 audits, SOC 2 audits, risk registers, audit responses, corrective actions and management reporting.
Key responsibilities
A. Technical Security, Cloud and AI Governance Responsibilities
- Conduct hands-on security risk assessments for cloud platforms, Microsoft 365, SaaS applications, identity and access management, network security, endpoint security, vulnerability management, logging, monitoring and data protection controls.
- Provide SME guidance on Azure and AWS security controls including IAM, privileged access, conditional access, encryption, key management, security posture management, logging, SIEM integration, backup, resilience and secure configuration baselines.
- Assess AI / GenAI use cases from security, privacy, governance, data leakage, model output reliability, third-party dependency and human oversight perspectives.
- Help the AI Governance Function to design and operationalize AI governance controls, including approved use cases, secure AI usage guidance, prompt and output handling, evidence of human review, and AI risk acceptance workflows.
- Identify repetitive compliance activities that can be automated using workflow tools, scripts, dashboards or AI agents, while ensuring appropriate validation, access control, human oversight and audit evidence.
- Lead cybersecurity control testing across on-premise and cloud environments to determine effectiveness, identify gaps and recommend pragmatic remediation actions.
- Support RFPs, client security questionnaires and technical security discussions by providing clear, evidence-backed responses aligned with actual control implementation.
B. GRC, Risk, Audit and Process Responsibilities
- Maintain and improve the organization’s ISO 27001 ISMS, ISO 42001 AIMS, SOC 2 control framework, risk management practices and applicable security compliance programs.
- Automate SOC2, ISO 27001 compliance monitoring via GRC tool.
- Help maintain the Privacy Governance Management System and conduct privacy risk assessments.
- Support implementation and ongoing operation of privacy governance controls aligned with GDPR, India’s DPDPA, client contractual requirements and internal privacy policies.
- Maintain privacy governance artefacts and evidence, including records of processing activities, data inventories and data-flow inputs, privacy notices, consent or lawful-processing records, retention requirements and cross-border transfer documentation, in coordination with Legal, Privacy and business owners.
- Coordinate privacy impact assessments and data protection risk assessments for new or changed processes, applications, AI use cases, vendors and client engagements, and track identified actions to closure.
- Support data subject and data principal rights processes, including request intake, identity verification, internal coordination, response tracking, evidence retention and escalation within applicable timelines.
- Work with technology and business teams to implement privacy-by-design controls covering data minimisation, purpose limitation, access control, encryption, masking, retention and deletion, DLP, logging and secure handling of personal data.
- Support personal data breach governance by assessing privacy impact, coordinating evidence and stakeholder inputs, maintaining incident records and enabling timely escalation to Legal, Privacy and management for notification decisions.
- Assess privacy and data-protection controls of third parties and subprocessors, including data location, onward transfers, retention, deletion, incident notification and contractual control requirements.
- Plan, coordinate and lead internal audits, client audits, external certification audits, SOC 2 audits and ISO 27001 audits, including evidence readiness, stakeholder coordination and closure of observations.
- Operate risk exception management by assessing business justification, compensating controls, risk exposure, expiry dates, approvals, evidence and periodic review requirements.
- Perform third-party risk assessments for vendors, subcontractors and critical service providers, covering information security, privacy, cloud hosting, resilience, incident management and contractual control requirements.
- Conduct ISMS risk assessment and maintain risk registers, corrective action plans, control evidence, audit trackers, third-party risk records, exceptions and Statement of Applicability updates in the GRC tool or approved system of record.
- Work with HR, Compliance, IT, Facilities, Procurement, Delivery Business Units and Client Account teams to embed security requirements into business processes without creating unnecessary operational overhead.
- Develop, review and maintain security policies, standards, procedures, guidelines and security awareness content relevant to cloud, AI governance, data protection, third-party risk and audit compliance.
Key competencies
Required Qualifications and Certifications
- Bachelor’s degree in Engineering, Computer Science, Information Security, Information Technology or equivalent practical experience.
- 8-10 years of relevant experience in information security, cloud security, cybersecurity governance, technology risk management, third-party risk, audits or compliance assurance.
- Preferred certifications: CISSP, CISA, CISM, CCSP, ISO 27001 Lead Auditor / Lead Implementer, ISO 42001 awareness or implementation exposure, SOC 2 audit readiness experience, or equivalent credentials.
- Practical experience in a professional services, financial services, technology services, KPO/BPO, IT outsourcing or client delivery environment is preferred.
Functional Competencies
- Strong practical understanding of ISO 27001, SSAE 18 or ISAE 3000 SOC 2, ISO 31000 and 42001, NIST CSF / security best practices, CIS controls, cloud security benchmarks, data protection expectations and client security assurance requirements.
- Sound knowledge of GDPR, DPDPA and similar evolving global privacy laws, strong understanding of privacy technologist principles.
- Hands-on experience of operationalizing GRC platforms to monitor compliance for SOC2, ISO 27001. Sound knowledge of GRC and Privacy Management tools like Archer, TrustArc, OneTrust, ServiceNow
- Hands-on working knowledge of Azure, AWS and Microsoft 365 security controls, including IAM, MFA, SSO, conditional access, DLP, endpoint security, device compliance, vulnerability management, SIEM, encryption, firewall and monitoring controls.
- Ability to assess AI governance and GenAI risks covering data leakage, model output usage, human oversight, approved knowledge sources, third-party AI platforms, prompt hygiene and evidence of review.
- Strong third-party risk assessment skills, including review of vendor security questionnaires, certifications, SOC reports, penetration test summaries, incident management, subcontractor use and remediation commitments.
- Ability to design control automation and AI-agent-assisted workflows for evidence collection, control monitoring, audit follow-ups, risk exception tracking and compliance reporting.
- Strong audit management capability across internal audits, client audits, SOC 2 and ISO 27001, including evidence collection, walkthroughs, stakeholder management, responses and corrective action management.
- Excellent documentation ability for policies, procedures, risk assessments, audit responses, management reports, control narratives and client-facing security responses.
Behavioral and Leadership Competencies
- Demonstrates ownership, sound judgement and the ability to make risk-based decisions in fast-moving business environments.
- Strong interpersonal and stakeholder-management skills, with the ability to build trust, influence decisions and constructively convince technology, delivery, procurement, legal, compliance, HR, facilities and client-facing stakeholders to adopt required security, privacy, audit and compliance actions.
- Drive audit and compliance initiatives through active collaboration with control owners and stakeholders, including regular in-person meetings, working sessions and evidence walkthroughs where appropriate.
- Confidently facilitate discussions to resolve control gaps, clarify ownership, agree pragmatic remediation plans and secure timely commitment to closure dates.
- Adapt communication style to technical and non-technical audiences, presenting legal, policy, risk and control requirements clearly while maintaining constructive working relationships.
- Leadership ability to drive closure across cross-functional teams without relying only on escalation.
- Clear written and verbal communication skills, including the ability to explain technical risks and audit expectations to non-technical stakeholders.
- Comfortable working independently, managing multiple priorities and delivering under tight timelines.
- Curious about emerging technologies, AI governance, cloud security and automation, with a continuous improvement mindset.
Success Measures for the Role
- Cloud and technical security risks, ISMS Risk assessments, privacy risk assessments are assessed, documented and remediated with clear ownership and timelines.
- AI governance and emerging technology risks are translated into practical controls, review evidence and operational SOPs.
- Third-party risk assessments and exception reviews are completed with defensible risk rationale and compensating controls.
- Client audits, ISO 27001 audits, SOC 2 audits and internal audits are managed with timely evidence, clear responses and effective closure of findings.
- Repetitive compliance activities are progressively automated using workflow tools or AI agents, with appropriate governance and human review.
- Business teams experience security and compliance as practical, risk-based and enabling rather than as unnecessary process overhead.
- Sound personality to liaise with senior stakeholders in the business to drive security compliances
Click on Apply to know more.