Search icon
Current Openings Current Openings

Current Openings

Manager - Information Security

Designation: MANAGER
Location: India UTTAR PRADESH Noida - A
Group: DS Group
Entity: Dharampal Satyapal Limited
SBU: CORPORATE
Department: INFORMATION TECHNOLOGY
Function: INFORMATION SECURITY

Job Description:

1. Information Security Governance & GRC

  • Manage and continuously improve the organization's Information Security Governance, Risk and Compliance (GRC) framework.
  • Develop, review and maintain information security policies, standards, procedures, guidelines and control frameworks.
  • Conduct periodic Information Security Risk Assessments and maintain risk registers.
  • Track remediation of identified security risks and ensure timely closure of risk treatment plans.
  • Coordinate internal, external, customer and regulatory security audits.
  • Prepare management reports, dashboards and security KPIs/KRIs for senior management.
  • Drive compliance with applicable regulatory and contractual information security requirements.
  • Support third-party/vendor security risk assessments and security due diligence.

2. ISO 27001:2022 / ISMS

  • Own and manage day-to-day activities related to the ISO 27001:2022 ISMS.
  • Ensure implementation and effectiveness of applicable ISO 27001:2022 controls.
  • Maintain ISMS documentation, Statement of Applicability (SoA), risk treatment plans and supporting evidence.
  • Coordinate internal audits, surveillance audits and certification audits.
  • Manage audit observations, non-conformities, corrective actions and preventive actions.
  • Conduct periodic ISMS reviews and support Management Review Meetings (MRM).
  • Drive continual improvement of the organization's information security management system.

3. Data Loss Prevention (DLP)

  • Manage and monitor the organization's DLP solution and data protection controls.
  • Develop and fine-tune DLP policies based on business requirements and data classification.
  • Monitor DLP incidents involving email, endpoints, web, cloud applications and removable media.
  • Investigate potential data leakage incidents and coordinate remediation with relevant stakeholders.
  • Reduce false positives while ensuring effective protection of sensitive and confidential information.
  • Prepare DLP dashboards, incident reports and management metrics.

4. Endpoint Detection & Response (EDR)

  • Manage and oversee EDR operations across endpoints and servers.
  • Monitor endpoint security alerts and coordinate investigation and response.
  • Ensure appropriate endpoint security policies, configurations and exclusions are implemented.
  • Track malware, ransomware, suspicious activity and other endpoint security incidents.
  • Coordinate with SOC/IT teams for containment, remediation and recovery.
  • Monitor endpoint security posture and coverage across the organization.

5. Vulnerability Assessment & Penetration Testing (VAPT)

  • Manage the organization's periodic Vulnerability Assessment and Penetration Testing (VAPT) program.
  • Define VAPT scope covering applications, infrastructure, networks, APIs, cloud and external-facing assets.
  • Review VAPT reports and validate the risk rating of identified vulnerabilities.
  • Coordinate with application, infrastructure and business teams for remediation.
  • Track vulnerability remediation against defined SLA timelines.
  • Conduct periodic vulnerability closure validation and exception management.
  • Maintain vulnerability dashboards and report security posture to management.

6. Security Operations & Incident Management

  • Coordinate with the SOC for monitoring, detection, investigation and response to security incidents.
  • Review security alerts and incident trends and ensure appropriate escalation.
  • Participate in investigation and response to cybersecurity incidents.
  • Support development and testing of Incident Response and Business Continuity processes.
  • Conduct root-cause analysis and track corrective actions following significant incidents.
  • Participate in security incident drills and tabletop exercises.

7. Security Awareness & Stakeholder Management

  • Drive organization-wide information security awareness initiatives.
  • Conduct security awareness sessions covering phishing, social engineering, password security, data protection and cyber hygiene.
  • Work closely with IT, Infrastructure, Network, Application, HR, Legal, Privacy, Procurement and Business teams.
  • Provide security requirements and guidance for new projects, applications, technologies and vendors.
  • Promote a strong security-by-design and risk-based approach across the organization.


Key Deliverables / KPIs

  • ISO 27001:2022 certification and continual compliance.
  • Timely closure of internal/external audit observations.
  • Reduction in critical and high-risk vulnerabilities.
  • VAPT remediation within defined SLAs.
  • DLP incident reduction and effective protection of sensitive data.
  • EDR coverage and endpoint security posture.
  • Timely closure of information security risks.
  • Security incident response and resolution within defined SLAs.
  • Vendor/third-party security assessment coverage.
  • Information security awareness and training completion.
  • Periodic cybersecurity dashboards and management reporting.


Education & Certifications

· Bachelor's degree in Computer Science, Information Technology, Cybersecurity or related discipline.

· 7–10 years of relevant Information Security / Cybersecurity experience.

 Preferred Certifications:

· CISM / CISSP

· ISO 27001 Lead Implementer / Lead Auditor

· CEH / OSCP

· CRISC

· CompTIA Security+

· Other relevant cybersecurity certifications

Skills:
Information Security
ISO 27001
IT Audit
Vulnerability Assessment
Security
Risk Management
SOC