TymblHub

© 2026 TymblHub

infosec Manager

Icra
Posted on
Icra logo

Experience
6 - 12 yrs
Salary (CTC)
₹20L - ₹25L
Job Location
Mumbai, India
Vacancy
1
Designation
Information Security Manager
Job Type
Not specified

Job Description

Roles and Responsibilities :

  • Define and own the enterprise group cybersecurity roadmap, aligning security initiatives with business priorities, digital transformation programs, and risk management objectives.
  • Lead technical risk assessments to identify, prioritize & mitigate Infosec risks by driving actionable technology-driven solutions. 
  • Should be a trusted technical advisor to senior leadership on cybersecurity posture, technology risks, and strategic trade-offs. 
  • Lead technical risk assessments to identify, prioritize, and mitigate cybersecurity risks in line with organizational risk tolerance. 
  • Architect and govern the implementation of enterprise-wide security architectures, covering applications security including security of software stack, SBOM monitoring, source code repository, network, endpoint, identity, and cloud, by defining governing principles for security architecture.
  • Ensure security-by-design principles into enterprise governance processes.
  • Enterprise Software Security: Lead the governance and enterprise-wide security architectures, ensuring security-by-design principles are embedded across applications, platforms, cloud services, and technology infrastructure. 
  • Own the application security program, including secure software development practices, source code repository security, software supply chain riskmanagement, and Software Bill of Materials (SBOM) monitoring to identify, assess, and remediate vulnerabilities and third-party component risks. 
  • Establish security standards, controls, and assurance processes to safeguard the software stack throughout its lifecycle while ensuring compliance with organizational policies, regulatory requirements, and industry best practices. 
  • Threat monitoring & analysis: Monitor SIEM detections, EDR/XDR alerts, and cloud security posture signals; triage, investigate, and document incidents using NIST incident response recommendations (SP 800-61 Rev. 3); map detections and playbooks to MITRE ATT&CK® tactics/techniques. 
  • Incident response (IR): Execute containment, eradication, and recovery actions with IT and application teams; maintain IR runbooks and after-action reviews; ensure timely external reporting (e.g., CERT-In within 6 hours when applicable). 
  • Vulnerability management: Run routine scans, validate findings, prioritise using risk/context, track remediation SLAs, and report closure metrics aligned to CIS Controls v8 and CSF 2.0 outcomes. 
  • Security hardening: Enforce secure configurations for endpoints, servers, databases, network devices, and M365/Azure /AWS / Cloud workloads; apply Zero Trust principles (verify explicitly, least privilege, assume breach) across identities, devices, apps, and data. 
  • Identity & access governance: Support IAM controls (RBAC, JML, privileged access, conditional access/MFA), periodic access reviews, and segregation of duties. 
  • Cloud security: Assist with cloud posture baselines and vendor assessments referencing CSA Cloud Controls Matrix (CCM v4); clarify shared responsibility with CSPs and partners. 
  • Data protection & privacy enablement: Partner with Data Owners and Legal/Privacy to classify data, apply protection (encryption, DLP), and support obligations under DPDP Act 2023. 
  • Security testing support: Coordinate periodic VAPT and source-code security checks; track fixes and re-tests; maintain evidence for audits. (For SEBI-regulated entities within the Group, align with applicable SEBI CSCRF guidance and timelines.)
  • Controls assurance & reporting: Contribute to ISMS artefacts, KPI/KRI dashboards, risk registers, exceptions, and ISO/IEC 27001:2022 control effectiveness reviews. 
  • Awareness & enablement: Deliver security awareness bytes, table-top exercises, and secure-by-design guidance to engineering and business teams mapped to CIS Controls v8. 
  • Third-party risk: Support due diligence and periodic reviews of vendors/service providers (incl. cloud, SOC/MDR) against CIS Controls/CSA CCM and contractual requirements.

Job Requirements :

Bachelor’s degree in computer science, Information Security, Electronics/IT, or related discipline; Master’s degree is preferred. 

One or more of: CISSP, CISM, CEH, CompTIA Security+ / CySA+, GIAC (GSEC/GCIH/GCIA/GCTI), AZ-500/SC-200/SC-300 (or equivalent).

6–12 years of hands-on experience in Security Operations, Incident Response, Vulnerability Management, or Security Engineering within enterprise or financial-services environments. 

Demonstrated experience operating to recognized frameworks (NIST CSF 2.0, ISO 27001:2022, CIS Controls v8).


Technical Competencies :

Threat detection & IR: SOC workflows, log analysis, alert tuning, threat hunting; IR aligned to NIST SP 800-61 Rev. 3; MITRE ATT&CK® mapping and use-case development. 

SIEM/XDR/EDR: Experience with one or more enterprise platforms (e.g., Microsoft Defender XDR stack/SIEM, or equivalent); rule/analytics creation, watchlists, and automation (SOAR). 

 Vulnerability management: Network/app/container scanning, risk-based prioritization, remediation tracking, and reporting per CIS Controls v8. Identity & access: RBAC, PAM, MFA/Conditional Access, SSO, service identities; designing policies consistent with Zero Trust. 

Endpoint, email & web security: Configuration baselines, EPP/EDR policies, anti-phish controls, sandboxing, and safe-links/file inspection. 

Network security: Firewalls/WAF, segmentation/micro-segmentation, secure remote access, TLS, DNS security. 

Cloud security (M365/Azure/AWS/Private Cloud): Posture management, key management, logging/monitoring, and CSA CCM-aligned control checks and supplier assessments. 

Data security & DLP: Data classification, encryption (KMS/PKI), DLP policies, secure key handling. 

Governance frameworks: Working knowledge of NIST CSF 2.0, ISO/IEC 27001:2022, and CIS Controls v8; ability to map controls and produce evidence for audits. 

Regulatory familiarity (India): DPDP Act 2023, CERT-In 6-hour reporting, and SEBI CSCRF expectations where applicable to Group entities.

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.