Information Security Officer - CISSP/CISA
Employee Forums
Officer - Information SecurityLocation : MumbaiExperience : 5-10 YearsAbout the Opportunity :Our client is a leading technology-driven organization operating in a highly regulated environment, serving enterprise customers across India. The organization is looking to strengthen its Information Security Governance, Risk & Compliance function and is seeking an experienced information security professional to support security governance, compliance management, risk assessments, third-party security reviews, and audit programs.Key Responsibilities :- Support and enhance the organization's Information Security Management System (ISMS).- Develop, review, and maintain Information Security Policies, Standards, Procedures, and Guidelines.- Conduct Information Security Risk Assessments across applications, infrastructure, cloud environments, and third-party ecosystems.- Perform security control and infrastructure gap assessments against industry standards and regulatory requirements.- Maintain risk registers and track remediation activities through closure.- Review vulnerability assessment and penetration testing reports and coordinate remediation tracking.- Monitor security remediation timelines and support governance reporting.- Conduct third-party and vendor security assessments.- Review security certifications, audit reports, and compliance documentation provided by external partners.- Coordinate internal, external, customer, and regulatory audits.- Track audit observations and ensure timely closure of findings.- Prepare governance dashboards, risk reports, compliance metrics, and management updates.- Present security posture and compliance updates to key stakeholders.Desired Candidate Profile :- 5-10 years of experience in Information Security Governance, Cyber Risk, Compliance, Security Assurance, IT Audit, or related domains.- Strong understanding of Information Security Management Systems (ISMS).- Experience with security frameworks and standards such as ISO 27001, SOC 2, PCI DSS, NIST CSF, or equivalent.- Exposure to regulatory compliance requirements and audit management.- Experience conducting risk assessments, control reviews, and remediation tracking.- Understanding of vulnerability management and security control validation.- Experience in vendor risk management and third-party security assessments.- Strong stakeholder management, documentation, and communication skills.Preferred Certifications :- ISO 27001 Lead Auditor / Lead Implementer- CISA- CISSP- CRISC- PCI-related certificationsWhy Consider This Opportunity ?- Opportunity to work in a mature cybersecurity and governance environment.- Exposure to enterprise-scale security, compliance, and risk programs.- High visibility with senior stakeholders and business leadership.- Opportunity to contribute to critical security and compliance initiatives in a regulated industry. (ref:hirist.tech)
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Officer - CISSP/CISA. Be the first to apply!
