Information Security Manager

Shell Infotech
Posted on
Shell Infotech logo

Experience
8 - 13 yrs
Salary (CTC)
₹15L - ₹30L
Job Location
Hyderabad, India
Vacancy
1
Designation
Information Security Manager
Job Type
Not specified

Job Description

Hi Everyone,

Hope youre doing well!

We have an urgent opening for a Manager ISMS & Data Privacy with one of our esteemed clients.
Client Location: Hyderabad

Employment Type: Fulltime
Experience Required: 8 12Years
Education: BE, MSc, MCA, Computer Science.


Job Description:

Role Overview

We are looking for a detail-oriented and experienced Manager – ISMS & Data Privacy to support end-to-end information security and privacy engagements. The role requires strong expertise in ISO 27001 implementation, policy & procedures drafting, audit handling, and DPDPA compliance, with hands-on experience in delivering client engagements across the ISMS lifecycle.


Key Responsibilities

ISMS & ISO 27001

  • Lead and manage end-to-end ISMS implementations aligned with ISO 27001:2013 and ISO 27001:2022.
  • Drive transition and implementation projects from ISO 27001:2013 to ISO 27001:2022.
  • Develop, review, and update ISMS policies, procedures, and guidelines.
  • Ensure policy lifecycle management – drafting, review, approval, and periodic updates.
  • Conduct risk assessments (asset-based, process-based, and context-based approaches).
  • Support control implementation, testing, and effectiveness reviews.
  • Plan and execute internal audits and support external certification audits.
  • Drive closure of audit findings (NCs, observations, improvements).

Risk Management & Compliance

  • Perform information security risk assessments and maintain risk registers.
  • Define and monitor risk treatment plans.
  • Support regulatory and compliance requirements across clients.
  • Ensure alignment with industry best practices and frameworks.

Data Privacy & DPDPA

  • Work on DPDPA compliance programs (India-specific, beyond GDPR/HIPAA understanding).
  • Conduct data mapping and data flow analysis across business processes.
  • Create and maintain ROPA (Record of Processing Activities).
  • Perform privacy gap assessments and DPIAs.
  • Define and validate legal basis (consent, legitimate use, etc.).
  • Support implementation of privacy policies and controls (not just drafting).
  • Handle data principal rights management (requests, grievances, closures).
  • Review and assess vendor contracts, DPAs, and third-party data sharing.

Audit & Stakeholder Management

  • Manage client-facing engagements independently.
  • Coordinate with stakeholders for evidence collection and audit readiness.
  • Present findings, gaps, and recommendations to senior stakeholders.
  • Ensure timely delivery of high-quality audit and compliance reports.

Required Skills & Competencies

  • Strong knowledge of ISO 27001 (2013 & 2022) and control frameworks.
  • Expertise in ISMS policy drafting and governance.
  • Hands-on experience in risk assessment methodologies.
  • Practical exposure to DPDPA and data privacy lifecycle activities.
  • Strong documentation and report writing skills.
  • Ability to manage multiple engagements and timelines.
  • Good stakeholder communication and presentation skills.


No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.