Job Description
We have an urgent opportunity for Infosec Manager role .
Experience : 7-12 yrs
Location: Navi Mumbai (Mahape)
Work Mode: All 5 days office.
Key Responsibilities:
1) ISO/IEC 27001 Information Security Management System (ISMS)
- Develop, implement, maintain, and continuously improve the ISO/IEC 27001 ISMS.
- Conduct periodic risk assessments, risk treatment planning, and control effectiveness reviews.
- Lead preparation, coordination, and closure of certification, surveillance, and recertification audits.
- Ensure alignment with ISO 27001:2022 control requirements and organizational risk posture.
2) Privacy Information Management System (PIMS / ISO 27701)
- Implement and manage PIMS in line with applicable privacy regulations (DPDP Act, GDPR, etc.).
- Ensure protection of personal data through privacybydesign and privacybydefault practices.
- Coordinate with Legal, HR, and IT teams for privacy impact assessments (PIAs/DPIAs).
- Support privacyrelated customer queries, audits, and compliance attestations.
3) SOC 2 Compliance
- Own and manage SOC 2 Type I and Type II compliance programs.
- Define, implement, and validate security, availability, confidentiality, and privacy controls.
- Coordinate with external auditors and internal control owners to ensure timely audit closure.
- Monitor control deficiencies and drive corrective and preventive actions.
4) Customer Audits, RFPs & Contractual Security Reviews
- Lead and support customer information security audits, assessments, and duediligence activities.
- Act as the primary Infosec SPOC for customer audits, security questionnaires, and onsite/remote assessments.
- Review and validate RFPs, RFIs, and customer security requirements, ensuring accurate and riskaligned responses.
- Perform information security review of MSAs, SOWs, NDAs, and customer contracts, covering:
- Data protection and confidentiality clauses
- Security control obligations
- Incident notification and breach management terms
- Righttoaudit and compliance requirements
- Provide riskbased recommendations to management before contract signoff.
5) Employee Security Awareness & Training
- Design and deliver information security and privacy awareness programs for employees.
- Conduct periodic phishing simulations and awareness campaigns.
- Promote a strong security culture across all business functions.
6) Internal Audits & Governance
- Plan, conduct, and report internal audits for ISMS, PIMS, and SOC controls.
- Identify nonconformities, risks, and improvement opportunities.
- Track corrective and preventive actions (CAPA) to closure.
- Maintain auditready documentation, policies, procedures, and records.
7) Incident Response & Security Operations
- Lead and coordinate information security incident response activities.
- Conduct rootcause analysis, impact assessment, and postincident reviews.
- Ensure incident communication aligns with contractual and regulatory requirements.
- Maintain and test incident response and business continuity procedures.
8) Technical Security Oversight
- Oversee deployment, tuning, and operational effectiveness of SIEM / SOC tools.
- Plan and manage VAPT, red teaming, and security testing across networks, applications, and infrastructure.
- Work closely with IT, Cloud, and DevOps teams to remediate vulnerabilities.
- Monitor emerging threats, vulnerabilities, and regulatory changes.
- Prepare periodic management and customerready security reports.
Experience Requirements
- 7+ years of experience in information security, governance, risk, and compliance.
- At least 5 years in a leadership or managerial role.
- Handson experience managing ISO 27001, PIMS / ISO 27701, and SOC 2 programs.
- Proven experience in customer audits, RFP responses, and contractual security reviews.
Skills & Competencies
- Strong understanding of information security frameworks, risk management, and compliance standards.
- Excellent stakeholder communication, audit handling, and negotiation skills.
- Ability to work crossfunctionally with HR, Legal, IT, DevOps, Sales, and Customers.
- Strong documentation, reporting, and presentation skills.
Certifications (Atleast 1 of these)
- ISO/IEC 27001:2022 Lead Auditor (LA) or Lead Implementer (LI)
- CISM / CISA
- ISO 27701 LA/LI
- CISSP
Job Classification
Industry: IT Services & Consulting
Functional Area / Department: IT & Information Security
Role Category: IT & Information Security - Other
Role: IT & Information Security - Other
Employement Type: Full time
Contact Details:
Company: Qualitykiosk
Location(s): Mumbai
Keyskills:
ISMS
ISO Implementation
Information Security
Risk Assessment
ISO Audit
Risk Management