Experience
5 - 8 yrs
Job Location
Vadodara, India
Vacancy
1
Designation
Information Security Officer
Job Type
ONSITE
Job Description
Role & responsibilities
- Coordinate the implementation, maintenance and continual improvement of the organization's ISMS in accordance with ISO/IEC 27001:2022.
- Maintain information security policies, procedures, standards and supporting ISMS documentation.
- Coordinate information security risk assessments, risk treatment activities, risk register maintenance and Statement of Applicability (SoA).
- Coordinate identification, classification and periodic review of information assets and their ownership.
- Monitor implementation and effectiveness of applicable information security controls and coordinate remediation of identified gaps.
- Coordinate Vulnerability Assessment and Penetration Testing (VAPT), including scope definition, review of findings, remediation tracking and re-testing.
- Coordinate the information security incident management process, including incident reporting, investigation, corrective actions and maintaining the incident register.
- Support periodic user access reviews, privileged access reviews and appropriate joiner/mover/leaver controls.
- Coordinate information security assessments of critical suppliers and third parties and monitor remediation of identified risks.
- Develop and coordinate information security awareness and training programmes for employees.
- Maintain applicable information security legal, regulatory and contractual requirements and coordinate compliance activities.
- Support integration of information security requirements into Business Continuity and Disaster Recovery processes.
- Establish and monitor appropriate Information Security KPIs/KRIs and prepare periodic security reports for management.
- Coordinate internal ISMS audits and support external certification/surveillance audits.
- Coordinate closure of audit findings, corrective actions and improvement initiatives.
- Prepare inputs and support the periodic ISMS Management Review.
- Act as the central coordination point between management, IT, business functions and external security/service providers for information security matters.
Preferred candidate profile
- Practical understanding of ISO/IEC 27001:2022 and ISMS implementation.
- Experience in information security risk assessment, GRC and compliance activities.
- Working knowledge of vulnerability management, VAPT, incident management, access management, security awareness and third-party risk management.
- Experience in supporting internal and external information security audits.
- Good documentation, analytical and report-writing skills.
- Ability to coordinate with both technical and non-technical stakeholders.
- Strong communication and stakeholder management skills.
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
