2,635 Information Governance jobs in India

Manager - Information Security (Governance, Risk and Compliance)

Bengaluru, Karnataka Navi

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

About the Team

At Navi, the InfoSec team safeguards our digital ecosystem - ensuring the confidentiality, integrity, and availability of critical systems and data. We lead the charge on cyber risk management, regulatory compliance, and data protection, while championing a security-first culture across all teams.


Our mission: Protect what powers Navi - securely, compliantly, and confidently.


About the Role

Navi is looking for an Associate Manager II – Information Security to pilot key aspects of its group-wide information security and regulatory compliance program. This role involves interpreting and implementing information security and technology risks mandates from regulators such as RBI, IRDAI, SEBI, and NPCI, ensuring continuous tech compliance across all business units. You will collaborate closely with engineering, infrastructure, legal, and IT teams to establish and maintain robust security policies, frameworks, and controls. Additionally, the role includes conducting risk assessments, enabling audit readiness, managing third-party/vendor security audits, and driving awareness initiatives across the organization, while also representing Navi in internal and external forums when needed.


What We Expect From You

  • As Navi operates in the regulatory space, this role requires interpreting and helping implement regulations related to cyber security by Reserve Bank of India (RBI), IRDAI and SEBI, as well as any other applicable regulatory guidance related to the service offerings issued by relevant institutions.
  • Further to the point above, ensure on-going monitoring and tech-compliance with existing regulatory expectations across these dimensions
  • Lead the Information security - GRC practice for Navi group level.
  • Ensuring that information security principles, policies, frameworks, standards and controls are defined, implemented and managed effectively.
  • Partner and collaborate extensively with cross-functional teams, such as Engineering, Infrastructure, IT, Legal, and help minimize information security risks
  • Architect and deliberate on the solutions that are compliant with relevant regulatory cybersecurity requirements
  • Conduct and review results of Technology Risk Assessment, recommending mitigation strategies to bring the Risk to appropriate levels Nav is looking for a Senior Manager Information Security (GRC) to be part of the information security
  • Ensure readiness of the organization for internal and external audits by keeping all documents, evidences, ready
  • If required, represent Navi in Board and Board Committee meetings, as well as in discussions with regulators
  • Conduct Security awareness programs, train personnel on data security & privacy related processes and responsibilities
  • Review / conduct Third Party Risk Assessments & Vendor assessments before onboarding
  • Review security solutions / controls implemented by Tech / Engineering teams, controls at data center,
  • cyber / information security incidents, IT BCP and DR drills, cloud security controls
  • Identify and define Security KPIs including weekly, monthly reports and update Security Dashboards


Must Haves

  • Minimum 7+ years of experience working in information security GRC
  • Prior experience in the Fintech/Startup industry and knowledge of one of the regulatory compliances like PCI DSS, RBI Master Directives, IRDA, SEBI cyber security guideline is preferred.
  • Hands-on approach in solving complex security problems
  • Experience with Information Security & Risk Management frameworks like ISO27001, NIST SP 800-37, etc Cyber Kill Chain, MITRE ATT&CK, or other relevant frameworks
  • Working knowledge of Cloud environments like AWS, GCP, Oracle cloud is beneficial
  • Exposure to Agile methodologies, DevOps, Cloud technologies is beneficial

Soft Skills

  • Ability to multitask and meet deadlines, and to prioritize in a highly dynamic work environment
  • Ability to balance risk, potential impact, resourcing, business drivers, and timelines
  • Excellent verbal and written communication skills
  • Strong Product Thinking
  • Strong problem solving
  • Business acumen
  • Technology grounding
  • Strategic thinking
  • Strong written and verbal communication skills with a talent for articulating.


Inside Navi

We are shaping the future of financial services for a billion Indians through products that are simple, accessible, and affordable. From Personal & Home Loans to UPI, Insurance, Mutual Funds, and Gold - we’re building tech-first solutions that work at scale, with a strong customer-first approach.


Founded by Sachin Bansal & Ankit Agarwal in 2018, we are one of India’s fastest-growing financial services organisations. But we’re just getting started!


Our Culture

The Navi DNA

Ambition. Perseverance. Self-awareness. Ownership. Integrity.

We’re looking for people who dream big when it comes to innovation. At Navi, you’ll be empowered with the right mechanisms to work in a dynamic team that builds and improves innovative solutions. If you’re driven to deliver real value to customers, no matter the challenge, this is the place for you.

We chase excellence by uplifting each other and that starts with every one of us.


Why You'll Thrive at Navi

At Navi, it’s about how you think, build, and grow. You’ll thrive here if:

  • You’re impact-driven : You take ownership, build boldly, and care about making a real difference.
  • You strive for excellence : Good isn’t good enough. You bring focus, precision, and a passion for quality.
  • You embrace change : You adapt quickly, move fast, and always put the customer first.
This advertiser has chosen not to accept applicants from your region.

Information Security Manager - Compliance & Governance

122001 Gurgaon, Haryana ₹1400000 Annually WhatJobs

Posted 22 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client is seeking an experienced Information Security Manager to oversee and enhance their security posture, focusing on compliance and governance. This role requires an individual to be based at our office in Gurugram, Haryana, IN . You will be responsible for developing, implementing, and managing security policies, procedures, and controls to protect sensitive information assets. Key duties include conducting risk assessments, managing security audits, ensuring adherence to relevant regulations (e.g., ISO 27001, GDPR, HIPAA), and developing incident response plans. You will also lead security awareness training programs for employees and collaborate with IT and legal teams to address security vulnerabilities and ensure data privacy. The ideal candidate will have a strong understanding of cybersecurity frameworks, threat landscapes, and risk management principles. Proven experience in developing and maintaining information security management systems is essential. Excellent leadership, communication, and project management skills are required to effectively manage security initiatives and advise senior management. A Bachelor's degree in Computer Science, Information Security, or a related field is preferred. Relevant certifications such as CISSP, CISM, or CISA are highly desirable. Minimum 7 years of experience in information security, with at least 3 years in a management or leadership role. You will be instrumental in safeguarding the company's data and reputation, ensuring a secure operating environment.
This advertiser has chosen not to accept applicants from your region.

Information Technology Governance Consultant

INSPYR Solutions

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

Job Opening: Governance, Risk & Compliance (GRC) Analyst – Level 2/3

Location : Offshore (India)

Contract : Long-term

Experience : 5–9 years (flexible beyond 10 years with adjusted pay rate)

Work Hours : India hours, up to 9:30 PM IST / 12 noon EST

About the Role

We are seeking a Governance, Risk, and Compliance (GRC) Analyst to strengthen our audit, compliance, and risk management functions. This role combines operational execution with strategic input , ensuring visibility and control over SaaS applications while helping define governance frameworks and risk processes.

Key Responsibilities

  • Governance & Compliance
  • Support governance processes for SaaS applications, ensuring visibility of use and purpose.
  • Participate in internal audits, documenting and reviewing existing controls.
  • Risk Management
  • Identify areas of risk in current processes and propose new controls or improvements.
  • Contribute to building stronger risk management practices beyond compliance.
  • Audit & Controls Support
  • Balance responsibilities across audit, governance, and risk.
  • Review policies, processes, and regulatory compliance related to applications and systems.
This advertiser has chosen not to accept applicants from your region.

Information Security Analyst

Chennai, Tamil Nadu Citigroup

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

Information Security Analyst - PAM specialist
As a bank with a brain and a soul, Citi creates economic value that is systemically responsible and in our clients' best interests. As a financial institution that touches every region of the world and every sector that shapes your daily life, our **Foundational Services** teams are charged with a mission that rivals any large tech company. Our technology solutions are the foundations of everything we do. We keep the bank safe and provide the technical tools our workers need to be successful. We design our digital architecture and ensure our platforms provide a first-class customer experience. Our operations teams manage risk, resources, and program management. We focus on enterprise resiliency and business continuity. We develop, coordinate, and execute strategic operational plans. Essentially, Foundational Services re-engineers client and partner processes to deliver excellence through secure, reliable, and controlled services.
Trust is part of our DNA at Citi. As such, we take safeguarding our customer data very seriously. The Cloud Technology Services (CTS) is made up of deeply dedicated and talented colleagues who work together to ensure the safety of Citi's and our clients' assets and information. We manage information security as an end-to-end program - one with a clear mandate and accountability. Our mission is to continually execute and enhance a global security program that is fully anchored to modern control and security frameworks, fully aligned with the technology of the firm, threat-focused and data-driven, and deeply integrated across all Citi businesses globally.
Being talent-driven, we are focused on attracting, developing, and retaining diverse and inclusive talent with a high technical skill level. As a member of our team we will provide you with career development opportunities at all stages of your career. Our employees model a passion for protecting Citi and our clients and believe in treating others with dignity and respect.
This is an opportunity to work with Global Secrets Management Platforms team which is part of Citi's Cloud Technology Services. We are responsible for secrets management on-prem and the cloud for several hundred applications across the firm.
Our commitment to diversity includes a workforce that represents the clients we serve globally from all walks of life, backgrounds, and origins. We foster an environment where the best people want to work. We value and demand respect for others, promote individuals based on merit, and ensure opportunities for personal development are widely available to all. Ideal candidates are innovators with well-rounded backgrounds who bring their authentic selves to work and complement our culture of delivering results with pride. If you are a problem solver who seeks passion in your work, come join us. We'll enable growth and progress together.
**Information Security Analyst - PAM specialist**
We are opening our doors for talented individuals who are passionate about Cyber Security, want to be part of innovation by implementing and driving cutting edge technologies within a world class organization.
If you have a background in technology and interested to learn and grow with a world class Cyber Security team, then Citi is a place for you to be.
**Responsibilities:**
+ Provide BAU support for secrets management applications like CyberArk, HashiCorp Vault.
+ Collaborate with various internal and external stakeholders/support teams as required to support the application and business needs.
+ Work with client applications to provide integration/onboarding guidance.
+ Identify security vulnerabilities in the system and implement necessary solutions to remediate the vulnerabilities.
+ Strong Automation experience - Identify manual processes that can be smartly automated.
+ Ensure security best practice is followed and provide solutions to improve existing infrastructure processes in the company.
+ Be involved in the design and subsequent implementation of software and service infrastructure.
+ Provide on-call support in rotation as required.
+ Gather requirements and provide walkthroughs to businesses on usage of various SDKs and API services available for integration with Secrets/Identity and Access Management applications.
**Qualifications:**
+ 5+ Years' experience
+ Bachelor's in Engineering Degree (Computer Science or Equivalent)
+ Any trainings/certifications in Cybersecurity will be considered a plus
**Critical Competencies:**
+ CyberArk, HashiCorp Vault experience will be a big plus.
+ Basic experience working with one or more of these scripting languages - Python, Unix Shell, Perl, Go & PowerShell scripting.
+ Experience with one or more server operating system like Linux, Windows.
+ Experience/basic understanding of CHEF, Ansible, Terraform, CI/CD.
+ Experience with one or more cloud providers such as AWS, GCP, AZURE.
+ Understanding of containers and associated technologies like Kubernetes/OpenShift.
+ Excellent written and verbal communication skills
+ Ability to work across all levels of the organization.
+ Must have good analytical skills.
+ Strong customer and quality-focus.
+ Sound problem resolution, judgment, and decision-making skills .
+ Ability to work well individually and as part of a team.
**About Citi**
Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. Citi provides consumers, corporations, governments, and institutions with a broad range of financial products and services, including consumer banking and credit, corporate and investment banking, securities brokerage, transaction services, and wealth management.
Additional information may be found at | Twitter: @Citi ( | YouTube: | Blog: | Facebook: | LinkedIn: .
---
**Job Family Group:**
Technology
---
**Job Family:**
Information Security
---
**Time Type:**
Full time
---
**Most Relevant Skills**
Please see the requirements listed above.
---
**Other Relevant Skills**
For complementary skills, please see above and/or contact the recruiter.
---
_Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law._
_If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review_ _Accessibility at Citi ( _._
_View Citi's_ _EEO Policy Statement ( _and the_ _Know Your Rights ( _poster._
Citi is an equal opportunity and affirmative action employer.
Minority/Female/Veteran/Individuals with Disabilities/Sexual Orientation/Gender Identity.
This advertiser has chosen not to accept applicants from your region.

Engineer, Information Security

Maharashtra, Maharashtra Danaher Corporation

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

Bring more to life.
Are you ready to accelerate your potential and make a real difference within life sciences, diagnostics and biotechnology?
At Pall Corporation, one of Danaher's ( 15+ operating companies, our work saves lives-and we're all united by a shared commitment to innovate for tangible impact.
You'll thrive in a culture of belonging where you and your unique viewpoint matter. And by harnessing Danaher's system of continuous improvement, you help turn ideas into impact - innovating at the speed of life.
As a global leader in high-tech filtration, separation, and purification, Pall Corporation thrives on helping our customers solve their toughest challenges. Our products serve diverse, global customer needs across a wide range of applications to advance health, safety and environmentally responsible technologies. From airplane engines to hydraulic systems, scotch to smartphones, OLED screens to paper-everyday Pall is there, helping protect critical operating assets, improve product quality, minimize emissions and waste, and safeguard health. For the exponentially curious, Pall is a place where you can thrive and amplify your impact on the world. Find what drives you on a team with a more than 75-year history of discovery, determination, and innovation.
Learn about the Danaher Business System ( which makes everything possible.
The Engineer, Information Security is responsible for designing, implementing an organisation's security systems and protocols to protect against security breaches, cyber-attacks, and other malicious activities.
They must develop and implement security tools, providing guidance and training to analysts on security best practices. They must collaborate with external security vendors and partners on the deployment of such tools and the best practices involved in keeping them operating optimally.
This position reports to the Director, Information Security and is part of the Information Technology Department located in Pune, India and will be an on-site role.
In this role, you will have the opportunity to:
+ Design and implement security controls, including access control, network segmentation, intrusion prevention and other tools, to mitigate risks and protect against security threats.
+ Evaluate emerging security technologies and make recommendations for their integration into the security architecture framework.
+ Conduct security reviews and risk assessments of new and existing IT systems, applications, and networks.
+ Create and maintain comprehensive documentation for security systems, procedures, and security incidents.
+ Participate in incident response planning and execute incident response procedures with security analysts in the event of a security breach.
The essential requirements of the job include:
+ Proven experience as a security engineer in a mid-sized organization, with 2+ years of experience in an engineering role.
+ Experience in building and maintaining security systems.
+ Hands-on experience in security systems, including firewalls, intrusion detection systems, anti-virus software, authentication systems, log management, content filtering, etc.
+ Knowledge of security standards, frameworks and regulations such as ISO 27001, NIST, PCI DSS, and GDPR.
+ Exhibit good analytical skills, as well as the ability to work well in a demanding, dynamic environment.
Travel, Motor Vehicle Record & Physical/Environment Requirements:
+ Ability to travel - international travel up to 10% per year.
It would be a plus if you also possess the following:
+ Bachelor's degree in computer science, Information Technology, or related field.
+ Professional certifications such as CISSP, Security+, CASP+, GIAC.
Pall Corporation, a Danaher operating company, offers a broad array of comprehensive, competitive benefit programs that add value to our lives. Whether it's a health care program or paid time off, our programs contribute to life beyond the job. Check out our benefits at Danaher Benefits Info ( .
At Pall we believe in designing a better, more sustainable workforce. We recognize the benefits of flexible, remote working arrangements for eligible roles and are committed to providing enriching careers, no matter the work arrangement. This position is eligible for a remote work arrangement in which you can work remotely from your home. Additional information about this remote work arrangement will be provided by your interview team. Explore the flexibility and challenge that working for Pall can provide.
Join our winning team today. Together, we'll accelerate the real-life impact of tomorrow's science and technology. We partner with customers across the globe to help them solve their most complex challenges, architecting solutions that bring the power of science to life.
For more information, visit .
This advertiser has chosen not to accept applicants from your region.

Analyst, Information Security

Maharashtra, Maharashtra Danaher Corporation

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

Bring more to life.
Are you ready to accelerate your potential and make a real difference within life sciences, diagnostics and biotechnology?
At Pall Corporation, one of Danaher's ( 15+ operating companies, our work saves lives-and we're all united by a shared commitment to innovate for tangible impact.
You'll thrive in a culture of belonging where you and your unique viewpoint matter. And by harnessing Danaher's system of continuous improvement, you help turn ideas into impact - innovating at the speed of life.
As a global leader in high-tech filtration, separation, and purification, Pall Corporation thrives on helping our customers solve their toughest challenges. Our products serve diverse, global customer needs across a wide range of applications to advance health, safety and environmentally responsible technologies. From airplane engines to hydraulic systems, scotch to smartphones, OLED screens to paper-everyday Pall is there, helping protect critical operating assets, improve product quality, minimize emissions and waste, and safeguard health. For the exponentially curious, Pall is a place where you can thrive and amplify your impact on the world. Find what drives you on a team with a more than 75-year history of discovery, determination, and innovation.
Learn about the Danaher Business System ( which makes everything possible.
The role of Analyst, Information Security is a critical function within our organisation, which primarily involves the protection of digital assets and data from cyber threats, by analysing and improving the security measures in place.
The analyst will be responsible for managing the day-to-day operations of our security infrastructure, including monitoring, responding to security incidents, risk management and policy enforcement. They will need to have a strong understanding of security principles, experience with security tools, and the ability to work in a fast-paced, agile environment.
This position reports to the Director, Information Security and is part of the Information Technology Department located in Pune, India and will be an on-site role.
In this role, you will have the opportunity to:
+ Monitor for security events and alerts to detect and respond to incidents in a timely manner, meeting required metrics.
+ Investigate security incidents to determine root cause and impact.
+ Respond to security incidents by implementing appropriate remediation actions.
+ Support and maintain incident response plans.
+ Investigate and resolve security incidents and breaches highlighted by the Security Operations Centre, providing recommendations to prevent future incidents.
+ Manage security tools and technologies, intrusion detection and prevention systems, antivirus software, content filters IDS/IPS & NGFW.
.
The essential requirements of the job include:
+ 2+ years of experience in a security operations role.
+ Hands-on experience with security tools, such as SIEM, IDS/IPS, and vulnerability scanners.
+ Strong knowledge of security principles and best practices.
+ Good analytical and problem-solving skills.
+ Knowledge of security standards and regulations such as ISO 27001, NIST, PCI DSS, and GDPR.
Travel, Motor Vehicle Record & Physical/Environment Requirements:
+ Ability to travel - international travel up to 10% per year.
It would be a plus if you also possess the following:
+ Bachelor's degree in computer science, Information Technology, or related field.
+ Relevant certifications such as Security+, CASP+, GIAC.
Pall Corporation, a Danaher operating company, offers a broad array of comprehensive, competitive benefit programs that add value to our lives. Whether it's a health care program or paid time off, our programs contribute to life beyond the job. Check out our benefits at Danaher Benefits Info ( .
At Pall we believe in designing a better, more sustainable workforce. We recognize the benefits of flexible, remote working arrangements for eligible roles and are committed to providing enriching careers, no matter the work arrangement. This position is eligible for a remote work arrangement in which you can work remotely from your home. Additional information about this remote work arrangement will be provided by your interview team. Explore the flexibility and challenge that working for Pall can provide.
Join our winning team today. Together, we'll accelerate the real-life impact of tomorrow's science and technology. We partner with customers across the globe to help them solve their most complex challenges, architecting solutions that bring the power of science to life.
For more information, visit .
This advertiser has chosen not to accept applicants from your region.

Information Security Manager

Mumbai, Maharashtra Burns & McDonnell

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

**Description**
This position is responsible for the leadership of the India Information Security (IS) department as part of the Global Information Security Directorate. Areas of responsibility will include coordination with the other IS Departments to ensure standard enforcement of security polices and controls, interfacing with local India IT teams and business leaders, and mitigating risks to the organization's information assets.
**Responsibilities :**
+ Manage India Information Security team's day to day operations.
+ Support the global Security Operations (SecOps) department to safeguard digital assets by assisting with detecting, investigating, and resolving cybersecurity threats
+ Assist the global Governance, Risk & Compliance (GRC) department with enforcing cybersecurity policies, overseeing cybersecurity risk, facilitating cybersecurity compliance audits, and conducting cybersecurity awareness training.
+ Assist the global Cybersecurity Infrastructure and Design (CID) department with management and maintenance of the cybersecurity systems, platforms, and controls.
+ Implement Secure Software Development Lifecycle (SSDLC) in India office by enforcing the compliance of global policies, processes, procedures and principles.
**Qualifications**
+ Bachelor's degree in Cyber/Information Security or Information Technology, Computer Science, Computer Engineering
+ Professional certifications such as CISSP, CISM, or equivalent multi-domain cybersecurity focused certification.
+ At least 10 years of experience in IT security management, with a proven track record of managing teams in global matrix environment
+ Experience with security technologies: EDR, SIEM, SOAR, CASM, CASB, CSPM, IAM, PAM
+ Excellent communication and interpersonal skills to effectively engage internal stakeholders.
+ Demonstrated ability to analyze complex security issues, devise solutions, and enforce established security controls.
+ Strong leadership skills to drive standardization of processes, procedures, and principles.
This job posting will remain open a minimum of 72 hours and on an ongoing basis until filled.
**Job** Engineering
**Primary Location** India-Maharashtra-Mumbai
**Schedule:** Full-time
**Travel:** No
**Req ID:**
**Job Hire Type** Experienced Not Applicable #BMI N/A
This advertiser has chosen not to accept applicants from your region.
Be The First To Know

About the latest Information governance Jobs in India !

Information Security Officer

Pune, Maharashtra Undisclosed

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

Location

The successful candidate shall be placed at Pune Location. It is a Full-time Job, “No” remote work. Information Security Officer/Associate willing to work on a 12-month contract/full-time may apply.


Experience

Candidates should have experience between 4-6 years


Role Description

We’re Hiring: Information Security Officer/Associate

We are looking for people who are passionate about making data safer, secure, and accessible through appropriate systems, processes, and rules. Information Protection is the key function and additional data security sub-functions (like data discovery, classification, and protection), we would require a specialist like you to support with the below high-level responsibilities, amongst others.


Responsibilities

  • Data Discovery and Classification(DDC): Design Data Discovery Processes, Develop comprehensive Data Lifecycle Management processes to identify, classify, and protect sensitive data across the organization.
  • Create Standard Operating Procedures (SOPs): Draft and implement templatized SOPs for data analysis, ensuring consistency and focus on risk reduction.
  • Automate Processes: Identify and coordinate automation opportunities within Data Discovery to improve efficiency and accuracy.
  • Data Protection (DP) – DLP + CASB + Insider Threat Management: Perform detailed analysis of DLP incidents to identify policy violations, insider threats, or data exfiltration attempts. Investigate CASB alerts, Triage and categorize incidents by severity, business impact, and risk
  • Reporting: Provide detailed reports to management stakeholders, highlighting the addressed risks, process improvements, and actionable insights
  • Work closely with teams like IT Security Team, Cloud Centre of Excellence (CCoE), IT Help Desk, IP Management and IT GRC etc to develop systems & SOPs


Requirements

  • Hands-on experience with Sentinel
  • Proven experience in Data Security domain
  • Training in any of SC 200 / SC 400/ CompTia Security+ / CEH
  • Zscaler EDU 220/ Zscaler EDU -22/ Microsoft Ninja for Cloud Apps
  • BigID Fundamentals / BigID Security Professional
  • Proficiency in general system troubleshooting for Windows and MAC
  • Configure advanced auditing and reporting capabilities to monitor compliance adherence.
  • Ensure secure data governance across on-premises, cloud, and hybrid environments


About Us

Terra TCC is a Technology & Sustainability company offering services in Software, Environmental consulting, and Staff Augmentation to top-notch clients. We continuously strive to help companies find the right technology, the right services and the right talent for their needs. Learn more at

Any information that is shared with us, shall be retained as per company's data privacy policy. In case you wish to revise, modify or delete any of the submitted information, please write back to us. See contact details on

This advertiser has chosen not to accept applicants from your region.

Information Security Analyst

Pune, Maharashtra Verdantas

Posted 4 days ago

Job Viewed

Tap Again To Close

Job Description

Join Verdantas – A Top #ENR 81 Firm,


We at Verdantas are seeking a highly motivated and detail-oriented Information Security Analyst, to protect our company’s critical systems and sensitive data. You will be an integral part of our security team, responsible for implementing, maintaining, and monitoring our security posture. The ideal candidate will have a strong technical background, a proactive mindset, and a passion for staying ahead of the latest security trends and threats.


Key Responsibilities

Security Operations & Monitoring:

  • Monitor security alerts from SIEM, IDS/IPS, firewalls, and other security tools to identify and investigate potential security incidents.
  • Perform vulnerability scans and assessments, prioritizing and tracking remediation efforts.
  • Manage and configure security tools, including EDR/XDR, antivirus, and email security gateways.
  • Conduct log analysis and forensic investigations to determine the root cause of security events.

Incident Response:

  • Serve as a key member of the incident response team.
  • Respond to and mitigate security incidents in a timely and effective manner.
  • Document incidents and develop runbooks for future reference.

Security Architecture & Engineering:

  • Design, implement, and maintain security controls and technologies to protect cloud (e.g., AWS, Azure, GCP) and on-premises infrastructure.
  • Implement and manage identity and access management (IAM) policies and practices.
  • Harden systems, networks, and applications based on industry best practices (e.g., CIS Benchmarks).
  • Assist in the development and enforcement of security policies, standards, and procedures.

Governance, Risk, and Compliance (GRC):

  • Participate in risk assessments and audits (e.g., SOC 2, ISO 27001, PCI-DSS, HIPAA).
  • Assist in third-party security risk assessments.
  • Promote security awareness across the organization through training and communication.


Required Qualifications & Skills

  • Bachelor’s degree in computer science, Information Security, or a related field, or equivalent experience.
  • (8+) years of experience in an information security role.
  • Hands-on experience with core security technologies (SIEM, EDR, Firewalls, IDS/IPS, DLP).
  • Strong understanding of networking protocols (TCP/IP, DNS, HTTP/S) and network security.
  • Knowledge of operating systems (Windows, Linux, macOS) and their security aspects.
  • Familiarity with cloud security principles (AWS, Azure, or GCP).
  • Understanding of common attack vectors, malware, and threat actor tactics (e.g., MITRE ATT&CK framework).
  • Excellent problem-solving and analytical skills.
  • Strong written and verbal communication skills.


Preferred Qualifications & Skills

  • Relevant industry certifications such as:
  • Entry-Level: Security+, GIAC GSEC
  • Mid-Level: CISSP, CISM, CEH, CompTIA CySA+
  • Cloud-Specific: CCSP, AWS Certified Security - Specialty, Azure Security Engineer Associate
  • Experience with scripting languages (e.g., Python, PowerShell, Bash) for automation.
  • Knowledge of application security (SAST, DAST) and secure SDLC practices.
  • Experience with penetration testing or red teaming tools and methodologies.
  • Prior experience in a regulated industry (finance, healthcare, etc.)
This advertiser has chosen not to accept applicants from your region.

Information Security Consultant

Kochi, Kerala Soffit Infrastructure Services (P) Ltd

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

The Information Security Consultant will be responsible for the implementation, assessment, and management of ISO 27001:2022, ISO 27002, and SOC 2 standards for clients. This role involves working independently or alongside senior consultants to help clients achieve and maintain information security compliance and other best practices. The consultant will focus on assessing and ensuring compliance with key security frameworks and will provide vCISO support to various clients.


Key Responsibilities:

ISO 27001/27002 Compliance:

  • Assist clients in achieving ISO 27001 certification by identifying and implementing the appropriate controls within the audit scope.
  • Verify compliance with ISO 27001/27002 controls and provide recommendations for improvement.

SOC 2 Compliance:

  • Assist clients in achieving SOC 2 compliance by identifying and implementing the appropriate Trust Service Criteria (TSCs).
  • Conduct SOC 2 compliance assessments and ensure the proper implementation of required controls.

Risk Assessment and Mitigation:

  • Conduct risk assessments of business activities, collaborating with stakeholders to manage risks until closure or acceptance.
  • Provide actionable recommendations to mitigate identified risks.

Policy and Procedure Development:

  • Define, develop, and review information security policies, procedures, guidelines, forms, and templates in line with best practices.
  • Ensure documentation is up-to-date and aligned with industry standards.

Baseline Standards Review:

  • Create and review baseline standards for operating systems, databases, web servers, and applications.
  • Recommend improvements based on security assessments.

Post-Implementation Audits:

  • Support post-implementation audits for ISO 27001:2022 to ensure ongoing compliance.
  • Monitor and assess adherence to established information security standards.

Information Security Awareness:

  • Create and execute organizational information security awareness programs.
  • Conduct training sessions to ensure employees are knowledgeable about security best practices.

Security Standards Compliance:

  • Assist clients in ensuring compliance with various security standards (ISO 27001, SOC 2, HIPAA, NIST, CIS, PCI DSS, etc.).
  • Recommend strategies to ensure long-term adherence to security best practices.

Incident Response:

  • Develop and implement incident response plans to handle security breaches and cyberattacks.
  • Ensure that clients have clear, actionable plans to address potential security incidents.

Gap Assessment:

  • Conduct gap assessments to identify areas of non-compliance and provide remediation strategies.

vCISO Support:

  • Provide virtual Chief Information Security Officer (vCISO) support to clients, advising on information security strategy and governance.


Skills and Qualifications:


Technical Skills:

  • Strong background in Information Technology and/or Cybersecurity .
  • Proficiency in auditing, policy development, database security, firewall design, risk analysis, identity management, access control, and web security.
  • Knowledge of security frameworks including ISO 27001, SOC 2, HIPAA, NIST, CIS, PCI DSS, and other industry best practices.
  • Hands-on experience with ISO 27001:2022 and SOC 2 implementations and assessments.
  • Strong understanding of risk management and the ability to assess and mitigate security risks.


Presales and Communication Skills:

  • Excellent client-facing communication skills.
  • Strong problem-solving abilities and the capacity to work effectively in a team environment.
  • Ability to communicate complex technical concepts to both technical and non-technical audiences.
  • Demonstrated ability to deliver presentations and conduct training sessions.
This advertiser has chosen not to accept applicants from your region.
 

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Information Governance Jobs