RedDoorz
Website:
reddoorz.com
Job details:
Job Title: Security, Risk & Compliance Lead
Experience: 6+ Years
Job Summary
We are seeking an experienced Security, Risk & Compliance Lead to drive the organisation's security and compliance initiatives. The ideal candidate will be responsible for developing and executing the overall information security strategy, ensuring compliance with industry standards, managing security assessments, leading incident investigations, and strengthening the organisation's security posture through proactive governance and risk management.
What We're Looking For
A proactive security leader who can balance business objectives with security requirements, lead cross-functional initiatives, and build a strong security-first culture across the organisation.
Key Responsibilities
- Lead and execute the organisation's overall information security and compliance strategy.
- Drive compliance initiatives for standards such as ISO 27001, SOC 2, PCI DSS, or other relevant
frameworks.
- Plan, coordinate, and manage internal and external compliance audits.
- Lead Vulnerability Assessment and Penetration Testing (VAPT) programs, ensuring timely
remediation of identified vulnerabilities.
- Conduct security risk assessments and establish risk mitigation plans.
- Perform vendor security assessments and third-party risk evaluations.
- Lead digital forensic investigations and support incident response activities.
- Define and implement security policies, standards, procedures, and governance frameworks.
- Monitor emerging security threats and recommend appropriate security controls.
- Collaborate with Engineering, Infrastructure, Product, and Business teams to embed security
into business processes.
- Drive security awareness and training programs across the organization.
- Manage security metrics, compliance dashboards, and executive reporting.
- Ensure continuous improvement of the organization's security posture.
Required Skills & Expertise
- 6+ years of experience in Information Security and Compliance.
- Strong expertise in ISO 27001, SOC 2, PCI DSS, or equivalent compliance frameworks.
- Hands-on experience in Vulnerability Assessment and Penetration Testing (VAPT)
management.
- Experience conducting vendor security assessments and third-party risk management.
- Strong understanding of digital forensics and incident response.
- Knowledge of security governance, risk management, and compliance (GRC).
- Experience developing and implementing enterprise-wide security policies and controls.
- Good understanding of cloud security (AWS/Azure/GCP) and application security principles.
- Excellent stakeholder management, communication, and leadership skills.
Preferred Qualifications
- Certifications such as CISSP, CISM, ISO 27001 Lead Implementer/Lead Auditor, CEH, CHFI, or
equivalent.
- Experience working with cloud-native environments and DevSecOps practices.
- Prior experience leading security and compliance initiatives across multiple business functions.
Click on Apply to know more.