QualityKiosk Technologies Pvt. Ltd.
Website:
qualitykiosk.com
Job details:
HIRING ALERT | InfoSec Executive | QualtiyKiosk Technologies | Mahape, Navi Mumbai
Looking for InfoSec professionals with 3-6 years experience
Preferred immediate joiner
Applicants please share your updated resume on tanvi.palwankar@qualitykiosk.com
Job Summary:
We are seeking an Information Security Executive to oversee and manage our organization's information security programs, including ISO 27001, PIMS, and SOC 2 compliance. The ideal candidate will be responsible for conducting internal audits, enhancing employee awareness, and ensuring the security of our information systems. The candidate must be certified as an ISO 27001 Lead Auditor (LA) or Lead Implementer (LI).
Key Responsibilities:
1) ISO 27001 Management:
- Develop, implement, and maintain the ISO 27001 Information Security Management System (ISMS).
- Conduct regular risk assessments and ensure compliance with ISO 27001 standards.
- Lead the preparation and execution of ISO 27001 certification and surveillance audits.
2) PIMS (Privacy Information Management System):
- Oversee the implementation and management of PIMS in accordance with relevant privacy regulations.
- Ensure the protection of personal data and compliance with data privacy laws.
3) SOC 2 Compliance:
- Manage the SOC 2 compliance program, including the development and maintenance of controls.
- Coordinate with external auditors for SOC 2 Type I and Type II audits.
4) Employee Awareness:
- Develop and deliver information security awareness training programs for employees.
- Promote a culture of security awareness and best practices across the organization.
5) Internal Audits:
- Plan and conduct internal audits to assess the effectiveness of the ISMS and other security controls.
- Identify and report on areas of non-compliance and recommend corrective actions.
6) Incident Response:
- Lead the incident response team in identifying, managing, and mitigating security incidents.
- Conduct post-incident reviews and implement lessons learned.
7) Third-Party Risk Management (TPRM):
- Develop and maintain a TPRM framework to assess and monitor vendor security posture.
- Conduct due diligence and risk assessments for new and existing third-party vendors.
8) Application Security Review:
- Ensure compliance with OWASP standards and secure SDLC practices.
- Conduct due diligence and risk assessments for new and existing third-party vendors.
Experience:
- Minimum of 3 years of experience in information security role
- Experience in managing ISO 27001, PIMS, and SOC 2 compliance programs.
Skills & Certifications:
- Strong knowledge of information security principles, practices, and technologies.
- Excellent communication and leadership skills.
- Ability to work collaboratively with cross-functional teams.
- ISO 27001:2022 Lead Auditor (LA) or Lead Implementer (LI) certification is required.
- Additional certifications such as CISSP, CISM, or CISA are preferred.
Click on Apply to know more.