Open role

Information Security Manager

End-to-end ownership of our ISO/IEC 27001:2022 ISMS, plus the technical security work behind it — VAPT, cloud and identity controls, customer assurance, Secure SDLC and AI security.

The role

Position Overview

We are looking for a hands-on and execution-oriented Information Security Manager to take end-to-end ownership of the organization's ISO/IEC 27001:2022 Information Security Management System (ISMS) while strengthening the organization's technical security, customer security assurance, Secure SDLC, and AI security practices.

This is not a purely compliance or documentation-focused role. The successful candidate will be responsible for ensuring that information security controls are continuously implemented, monitored, measured, evidenced, and improved throughout the year.

The ideal candidate should be comfortable operating across GRC and technical security, independently driving security initiatives, managing audits and remediation, responding to customer security requirements, and translating security requirements into practical controls.

Key Responsibilities

  • ISMS & ISO 27001 operations (40%) — own and continuously operate the ISO/IEC 27001:2022 ISMS.
  • Manage policies, procedures, registers, risk assessments, SoA, and compliance obligations.
  • Drive risk identification, treatment, monitoring, escalation, and closure.
  • Define and track ISMS objectives, KPIs, corrective actions, and continuous improvement.
  • Coordinate Management Reviews, internal audits, surveillance/recertification audits, and audit readiness.
  • Drive security awareness, training, onboarding awareness, and phishing simulations.
  • Hands-on technical security (25%) — manage VAPT, vulnerability scanning, remediation, and retesting.
  • Review security configurations across Microsoft 365, Entra ID, AWS/Azure, and access controls.
  • Drive least privilege, patch compliance, and periodic access reviews.
  • Coordinate security incident triage, containment, RCA, corrective actions, and escalation.
  • Support CERT-In reporting, security monitoring, threat intelligence, and control improvements.
  • Customer security assurance & third-party risk (20%) — own customer security questionnaires, assessments, due diligence, and audits.
  • Conduct vendor and third-party security risk assessments.
  • Review security requirements in NDAs, contracts, DPAs, and outsourcing arrangements.
  • Support Sales/AM teams in customer security discussions and pre-sales engagements.
  • Maintain security evidence, certification information, and a reusable security questionnaire/evidence library.
  • Secure SDLC & AI security (15%) — drive Secure SDLC, secure coding, and application security practices.
  • Support SAST, SCA, secret scanning, vulnerability management, and CI/CD security controls.
  • Partner with engineering teams on security findings, project risks, architecture, and access reviews.
  • Assess AI/LLM security risks, including prompt injection, data disclosure, excessive privileges, insecure outputs, and unauthorized access.
  • Promote recognized AI and application security best practices.

Required Skills

  • 5–8+ years of relevant experience in Information Security, Cybersecurity, GRC, ISMS, or a closely related domain.
  • Strong hands-on experience in ISO/IEC 27001:2022 implementation and ISMS operations.
  • Practical experience managing information security risk registers, risk assessments and treatment plans, Statement of Applicability (SoA), internal audits, management reviews, corrective actions, and audit readiness.
  • Strong practical understanding of information security controls and their implementation within an organization.
  • Experience in VAPT, vulnerability management, remediation tracking, and security findings management.
  • Working knowledge of Microsoft 365 and Microsoft Entra ID security.
  • Good understanding of cloud security across AWS and/or Azure.
  • Experience coordinating information security incidents and response activities.
  • Experience responding to customer security questionnaires, assessments, and security due diligence requests.
  • Good understanding of vendor and third-party security risk assessments.
  • Understanding of Secure SDLC and application security practices.
  • Exposure to SAST, SCA, secret scanning, CI/CD security controls, or similar application security practices.
  • Awareness of emerging AI/LLM security risks.
  • Strong documentation, analytical, communication, stakeholder-management, and problem-solving skills.

Good to Have

  • CISSP / CISM / ISO 27001 Lead Implementer / ISO 27001 Lead Auditor or equivalent certification.
  • Experience working in an IT services, software development, product engineering, or technology consulting organization.
  • Experience supporting enterprise customers during security audits and due-diligence exercises.
  • Knowledge of CERT-In and Indian information security compliance requirements.
  • Knowledge of security frameworks such as CIS Controls, NIST CSF, OWASP, and OWASP ASVS / Top 10.
  • Exposure to cloud security posture management and identity/security tools.
  • Experience with AI Security, GenAI Security, or LLM application security assessments.
  • Experience with enterprise security platforms, vulnerability management tools, SIEM, or security monitoring solutions.

Education

Ideal Candidate

The ideal candidate is hands-on and execution-oriented rather than purely documentation-focused, comfortable working across both GRC and technical security, and capable of independently driving security actions with IT, Engineering, Cloud, and Business teams. They are confident interacting directly with enterprise customers and external auditors, comfortable managing audits, evidence, remediation, risks, and deadlines throughout the year, and able to translate security and compliance requirements into practical, measurable controls.

They are strong in stakeholder management and cross-functional collaboration; analytical, structured, and detail-oriented, identifying security gaps proactively; curious about emerging security risks across cloud, applications, and AI; and comfortable taking ownership rather than waiting for instructions.

What we offer

  • End-to-end ownership of an established ISO/IEC 27001:2022 ISMS, and a key role in strengthening the organization's overall information security maturity.
  • Exposure across ISMS, GRC, technical security, cloud security, application security, customer assurance, third-party risk, Secure SDLC, and emerging AI security — a broad and impactful information security profile.
  • Significant ownership and visibility if you enjoy turning security requirements into real-world controls, driving continuous improvement, and working closely with both technology and business teams.
Apply Now

Share your details and upload your CV.

Fill in a few basic details and attach your CV. Our team will get in touch when there’s a role that matches your background.

  • Takes about two minutes to complete.
  • Every submission is reviewed by our team.
  • Kept on file for current and future openings.
A note on recruitment fraud. Focaloid never asks for payments, deposits, training fees or banking details at any stage. Anyone claiming otherwise is not us. Write to careers@focaloid.com.

Application

Max file size 10MB.
Uploading...
fileuploaded.jpg
Upload failed. Max size for files is 10 MB.
Reviewed by a person · reply within a week
Application received. Our talent team will review your details and get back to you.
Oops! Something went wrong while submitting the form.