ISMS Compliance - Manager
Quest Global · Bengaluru, Karnataka, India
Quest Global · Bengaluru, Karnataka, India
**Job Requirements** **Job Description:** Incumbent serves as an information security executive and will be required to work with information security team members from respective work area **Job Designation:** ISMS Compliance - Manager / Deputy Manager **Key Responsibilities:** - Develops & revises information security policies & procedures - Initiates, facilitates and promotes activities to create information security awareness within the organization - Managing Information Security Exception Management by resolving service requests - Supports and Facilitates Customer and 3rd Party Information Security Audits - Plans and performs internal audit and technical compliance checks - Provide necessary support in filling out RFI/RFP/Customer Contracts/SOW requirements - Organizes & conducts ISMS core team meetings and security council - Facilitates the process owners in performing the risk assessment & mitigation actions - Facilitates the process owners in performing the root cause analysis for the critical incidents & other non-conformities identified during internal / external / customer audits - Monitors compliance with information security policies and procedures, referring problems to the appropriate Function / Operation Manager and report to CISO - Develops and supervises all information security measures in the organization - Advises the team with current details about information security technologies and related regulatory issues - Assists the BCP / DR team in establishing the robust framework on business continuity & disaster recovery - Managing customer specific compliance as per customer requirements **General Skills and Specifications:** - Ability to define problems, collect data, establish facts, and draw valid conclusions - Ability to work independently and to take emergent decisions on his/her own - Ability to effectively present information and respond to questions from top management, groups of managers and customers - Experience across developing policies, standards, and procedures as per ISO/IEC 27001, TiSAX and other information security related standards / frameworks - Strong Auditing skill, well differentiation between observation & Non-conformances. Analysis of Audit findings to indicate trend and identify the weak area - Good knowledge of GDPR and DPDPA regulations / requirements and implementation - Hands-on on conducting process trainings and facilitate eternal certification audits - Implementation knowledge on BCP and DR policies / procedures at Org level and customer account level - Excellent interpersonal communication and organizational skills with demonstrated abilities in team crisis management. Good team player, Strong team orientation & leadership qualities, hardworking, enthusiastic with good attitude **Education & Qualifications:** - Bachelors degree / Masters Degree or higher in Computer Science, Information Systems or a related field. - At least 10 - 20 years of experience in computing or related area with a focus on information security related activities. - Lead Auditor on ISO/IEC 27001 standard and other security related frameworks Professional IT security related certifications is an added advantage. **Work Experience** **Education & Qualifications:** - Bachelor’s degree / Master’s Degree or higher in Computer Science, Information Systems or a related field. - At least 10 - 20 years of experience in computing or related area with a focus on information security related activities. - Lead Auditor on ISO/IEC 27001 standard and other security related frameworks Professional IT security related certifications is an added advantage