Information Security Executive
InFynd · Coimbatore South, India ·
- Category
- Security
- Experience
- 2+ years
Runs and continuously improves InFynd's ISO/IEC 27001 ISMS: coordinating internal and external audits, performing risk assessments, maintaining security policies and control evidence, tracking incidents and corrective actions, and delivering employee security-awareness training. It's a GRC/compliance role centered on ISO 27001 rather than hands-on security engineering.
- Maintain
and continuously improve the organization's ISMS in alignment with
ISO/IEC 27001.
- Coordinate internal and external ISO audits, including audit preparation,
evidence collection, and closure of observations.
- Conduct information security risk assessments and maintain the risk
register and risk treatment plans.
- Develop,
review, and maintain information security policies, procedures,
standards, and guidelines.
- Coordinate
the implementation and monitoring of ISO 27001 Annex A controls.
- Maintain
ISMS documentation, control evidence, compliance records, and audit
trackers.
- Conduct
periodic user access reviews, asset reviews, and security compliance
checks.
- Support vendor/third-party security assessments and compliance reviews.
- Coordinate
information security incident reporting, investigation, corrective
actions, and documentation.
- Support Business Continuity and Disaster Recovery activities.
- Conduct
and coordinate employee information security awareness and training
programs, including phishing awareness, password security, social
engineering, data protection, and acceptable-use practices.
- Monitor
compliance with organizational security policies and report deviations.
- Coordinate
with IT, HR, Operations, and other internal teams for
implementation of security controls.
- Track
corrective and preventive actions and ensure timely closure.
- Prepare ISMS reports, dashboards, compliance reports, and management review
inputs.
- Keep
updated with applicable information security standards, regulations, and
industry best practices.
Requirements
- 2–5
years of experience in ISMS / Information Security / IT GRC / IT
Compliance / Cybersecurity Governance.
- Strong
understanding of ISO 27001 and ISMS implementation.
- Knowledge
of ISO 27001 Annex A controls.
- Hands-on
experience in risk assessment and risk treatment.
- Experience
supporting ISO/internal/external audits.
- Good
understanding of:
- Information
Security Governance
- Access
Control
- Asset
Management
- Incident
Management
- Vendor
Risk Management
- Business
Continuity
- Data
Protection & Privacy
- Security
Awareness
- Strong
documentation and report-writing skills.
- Good
communication and stakeholder-management skills.
- Strong
attention to detail and ability to manage compliance activities
independently.
Benefits
- ISO
27001 Lead Implementer
- ISO
27001 Lead Auditor
- ISO
27001 Internal Auditor
- CISA
- CISM
- CRISC