TymblHub

© 2026 TymblHub

Information Security Manager

Shell Infotech
Posted on
Shell Infotech logo

Experience
8 - 13 yrs
Salary (CTC)
₹15L - ₹30L
Job Location
Hyderabad, India
Vacancy
1
Designation
Information Security Manager
Job Type
Not specified

Job Description

Hi Everyone,

Hope youre doing well!

We have an urgent opening for a Manager ISMS & Data Privacy with one of our esteemed clients.
Client Location: Hyderabad

Employment Type: Fulltime
Experience Required: 8 12Years
Education: BE, MSc, MCA, Computer Science.


Job Description:

Role Overview

We are looking for a detail-oriented and experienced Manager – ISMS & Data Privacy to support end-to-end information security and privacy engagements. The role requires strong expertise in ISO 27001 implementation, policy & procedures drafting, audit handling, and DPDPA compliance, with hands-on experience in delivering client engagements across the ISMS lifecycle.


Key Responsibilities

ISMS & ISO 27001

  • Lead and manage end-to-end ISMS implementations aligned with ISO 27001:2013 and ISO 27001:2022.
  • Drive transition and implementation projects from ISO 27001:2013 to ISO 27001:2022.
  • Develop, review, and update ISMS policies, procedures, and guidelines.
  • Ensure policy lifecycle management – drafting, review, approval, and periodic updates.
  • Conduct risk assessments (asset-based, process-based, and context-based approaches).
  • Support control implementation, testing, and effectiveness reviews.
  • Plan and execute internal audits and support external certification audits.
  • Drive closure of audit findings (NCs, observations, improvements).

Risk Management & Compliance

  • Perform information security risk assessments and maintain risk registers.
  • Define and monitor risk treatment plans.
  • Support regulatory and compliance requirements across clients.
  • Ensure alignment with industry best practices and frameworks.

Data Privacy & DPDPA

  • Work on DPDPA compliance programs (India-specific, beyond GDPR/HIPAA understanding).
  • Conduct data mapping and data flow analysis across business processes.
  • Create and maintain ROPA (Record of Processing Activities).
  • Perform privacy gap assessments and DPIAs.
  • Define and validate legal basis (consent, legitimate use, etc.).
  • Support implementation of privacy policies and controls (not just drafting).
  • Handle data principal rights management (requests, grievances, closures).
  • Review and assess vendor contracts, DPAs, and third-party data sharing.

Audit & Stakeholder Management

  • Manage client-facing engagements independently.
  • Coordinate with stakeholders for evidence collection and audit readiness.
  • Present findings, gaps, and recommendations to senior stakeholders.
  • Ensure timely delivery of high-quality audit and compliance reports.

Required Skills & Competencies

  • Strong knowledge of ISO 27001 (2013 & 2022) and control frameworks.
  • Expertise in ISMS policy drafting and governance.
  • Hands-on experience in risk assessment methodologies.
  • Practical exposure to DPDPA and data privacy lifecycle activities.
  • Strong documentation and report writing skills.
  • Ability to manage multiple engagements and timelines.
  • Good stakeholder communication and presentation skills.