Sr Information Security Engineer - GRC

EDGE Executive Search
Posted on
EDGE Executive Search logo

Experience
5 - 8 yrs
Job Location
Gurugram, India
Vacancy
1
Designation
Senior Information Security Engineer
Job Type
Not specified

Job Description


The Company

The companys products and services simplify and connect the post-trade ecosystem across asset classes - from trade processing and portfolio optimization to collateral, risk, and regulatory solutions, the company brings together a deep heritage of market-trusted platforms and are now building the next generation of systems that combine modern architecture, data engineering, and advanced automation at global scale.


The Job

We are seeking a dedicated and collaborative Information Security Engineer to join our growing Governance, Risk, and Compliance (GRC) team. In this role, you will play a pivotal part in maintaining, maturing, and auditing our information security management framework.

The ideal candidate has 5 - 8 years of direct experience within an InfoSec GRC function and thrives in a team-oriented environment. You will be responsible for ensuring our policies remain up-to-date, driving our ISO 27001 certification lifecycle, and executing core compliance operations like user access reviews, exception management, and security awareness programs.


Key Responsibilities


Governance & ISO 27001 Management

  • ISMS Governance: Manage and maintain our ISO 27001 Information Security Management System (ISMS) to ensure continuous compliance.
  • Audit Facilitation: Lead internal security audits and act as a point of contact for external certification audits.
  • Policy Management: Regularly review, update, and draft information security policies, standards, and procedures to align with evolving regulatory landscapes and business needs.

GRC Operations & Risk Management

  • Access Governance: Coordinate and oversee periodic user access reviews across critical systems.
  • Exception Management: Evaluate, log, and monitor security policy exceptions, ensuring compensating controls are effectively implemented and tracked.
  • Risk Culture: Administer the company-wide security awareness training program and orchestrate routine phishing simulations to strengthen our human firewall.


Your Profile

Required Experience & Skills

  • Experience: 5 - 8 years of proven experience specifically within an Information Security GRC role.
  • ISO 27001 Expertise: Hands-on experience managing an ISO 27001 ISMS, including active participation in both internal and external certification audits.
  • Core GRC Competencies: Direct experience executing user access reviews, phishing simulations, security training, and policy exception workflows.

Preferred Qualifications (Good to Have)

  • Security Standards Knowledge: Familiarity with major security and compliance frameworks, including:
    • ISO 27001
    • SOC 2
    • NIST CSF
    • CIS v8
    • ISO 42001 (AI)
  • Program Experience: Experience in managing and implementing the following programs and processes:
    • Security Awareness programs and tools.
    • User Access Review processes and tools.
    • Data Loss Prevention (DLP).
  • Documentation: Experience in writing and maintaining policy documents and security standards.

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.