Job Description
Job Overview
The Information Security Process Manager is responsible for ensuring strong implementation and continuous improvement of security controls across VFS Global platforms, applications, and business processes. The role supports compliance with ISO 27001, data protection regulations, client requirements, and enterprise cybersecurity frameworks by evaluating controls, identifying gaps, and driving remediation. It also promotes security awareness, governance alignment, and operational discipline across business and technology teams to strengthen the organizations overall security posture.
Duties & Responsibilities
Job Description
Security Controls & Compliance
- Conduct RCA for security incidents; recommend corrective & preventive actions to avoid recurrence.
- Design, implement, and monitor security controls to minimize risks and prevent data breaches.
- Assess effectiveness of deployed controls and document periodic performance reports.
- Participate in security reviews, gap assessments, and risk evaluations for assigned scope.
- Ensure adherence to Information Security Policies, Standards, SOPs, and regulatory frameworks.
- Ensure compliance with ISO 27001, data protection laws, and client/government security requirements.
- Drive organization-wide awareness initiatives to strengthen security culture.
- Advise business units on risks, mitigation strategies, and security best practices.
- Support IT & business teams in maintaining secure configurations and reducing vulnerabilities.
- Maintain accurate worklogs, time-tracking, and documentation as per ISMS guidelines
Compliance, Brand Management, and Market Intelligence
- Ensure compliance with the companys information security policies and procedures.
- Enhance the company profile and brand image through strategic initiatives and sustained business development efforts.
- Conduct market intelligence activities to stay informed on industry trends, competition, and emerging opportunities.
Sustainability
- Promote judicious use of natural resources.
- Adhere to the organizations environment, health, and safety policies, objectives, and guidelines.
Anti Bribery Management Systems (ABMS)
- Follow the ABMS roles and responsibilities details as prescribed on the ABMS manual.
a. Understanding of ethical standards and the importance of integrity in business practices.
b. Ability to identify and evaluate risks related to bribery in various business contexts. For more detailed explanation, follow the ABMS manual.
Education
- Graduate degree required; professional certifications such as CISSP, CISM, ISO 27001 LA/LI, PMP, or ITIL are preferred.
Experience
- 3 to 5 years of experience in Information Security, IT risk, or compliance functions.
- Strong understanding of ISMS, data protection, risk assessment, IT controls, and incident management
Job Classification
Industry: IT Services & Consulting
Functional Area / Department: IT & Information Security
Role Category: IT & Information Security - Other
Role: IT & Information Security - Other
Employement Type: Full time
Contact Details:
Company: VFS Global
Location(s): Mumbai
Keyskills:
Information Security
IT risk
Application & Cloud Security
Application Security
CISSP
Security Operations
CISM
IT Security