
Job Description:
Key Responsibilities:
Policy & Procedure Management:
- Create, review, and periodically update IT and Information Security policies, procedures, and standards.
- Coordinate with stakeholders to ensure timely approval and alignment of policies with regulatory and industry best practices.
- Maintain a centralized repository of all policies, procedures, and governance documents.
Audits, Assessments and Compliances:
- Facilitate internal, external, and regulatory audits/assessments, including audit kick-off, data collection, evidence validation, and closure discussions.
- Respond to auditor/assessor queries, ensuring timely and accurate evidence submission.
- Maintain a secure repository of all documents and related artifact.
- Drive closure of open observations/issues within defined timelines.
Risk Management:
- Assist in conducting Information Security Risk Assessments in line with organizational, regulatory, and industry requirements.
- Maintain and update the risk register, ensuring timely closure of action items arising from identified risks.
- Conduct third-party/vendor risk assessments, prepare assessment reports, and drive remediation plans with vendors.
Training & Awareness:
- Conduct induction sessions on Information Security for new joiners.
- Organize periodic awareness training including targeted training as and when required.
- Develop and deliver ongoing security awareness initiatives across the organization.
Governance & Monitoring:
- Prepare and present monthly Information Security review decks and tracking status of action items.
- Track closure of identified gaps from periodic access reviews.
- Review and assess Master Service Agreements (MSAs) and vendor contracts for compliance with Information Security requirements.
- Conduct periodic meetings to monitor end-user security posture and follow-ups on remediation plans.
Eligibility Criteria for the Job:
Education:
- Bachelors degree in information technology, Computer Science, or related field.
- Relevant certifications preferred (e.g. CISA, CISM, ISO 27001 LA/LI, CRISC).
Experience:
- 5 years of relevant experience in Information Security Governance, Risk, and Compliance (GRC).
- Strong knowledge of regulatory frameworks (e.g. ISO 27001, GDPR, RBI, etc).
- Hands-on experience in facilitating audits/assessments and managing security documentation.
- Experience in risk management and vendor security assessments.
- Strong presentation, communication and stakeholder management skills.
Skills & Competencies:
- Detail-oriented with strong analytical skills.
- Ability to work independently and collaboratively in a cross-functional environment.
- Proactive in driving closure of issues and ensuring compliance readiness.
- Strong commitment to fostering a culture of security awareness within the organization.
Didn’t find the job appropriate? Report this Job