Manager Information Security & Compliance

Vernost Marketing

  • Posted: 2 months ago
  • Openings: 10
  • Applicants: 0

Job Description

JD

Position


Manager Information Security & Compliance

Reports To- Chief Information Security Officer (CISO)

Function -Information Security & Risk

Location- Mumbai (HQ) / Dubai

Experience -6-10 years

Employment Type- Full-time, Permanent

Role Summary

The Manager Information Security & Compliance owns the operational security posture of Vernost's products, projects, and corporate environment under the direction of the CISO. This is a hands-on role: regularising security practices across delivery teams, leading client and regulatory audits, managing VAPT cycles, and maintaining certifications including ISO 27001, PCI DSS, SOC 2 Type II DPDPA, PDPL, PDPA and GDPR.

Key Responsibilities

Security Governance & Project Assurance

  • Embed security controls into every active client project (loyalty, points exchange, travel, marketplace, payments) from kickoff to go-live.
  • Maintain and enforce the InfoSec policy framework secure SDLC, access control, change management, data classification, and incident response.
  • Conduct internal security reviews on architecture, code, and infrastructure changes before production release.
  • Drive consistency of security controls across teams in India, UAE, and KSA delivery centres.

Audit & Client Assurance

  • Act as the primary point of contact for client security audits bank and non-bank including questionnaires, evidence collection, walkthroughs, and remediation tracking.
  • Support regulatory and certification audits for banking clients, including SAMA, CBUAE, RBI, and MAS where applicable.
  • Own renewals and surveillance audits for ISO 27001, PCI DSS, and SOC 2 Type II in coordination with external auditors.

Vulnerability Management & VAPT

  • Plan, scope, and manage VAPT engagements (internal and third-party) across web, mobile, API, and cloud surfaces.
  • Triage findings, drive remediation with engineering teams, and report closure status to the CISO and clients.
  • Run continuous vulnerability scanning, patch management oversight, and secure configuration baselines.

Compliance & Risk

  • Maintain the enterprise risk register; conduct periodic risk assessments and present mitigation plans.
  • Ensure compliance with applicable data protection regimes, including DPDPA (India), GDPR, and PDPL (UAE, KSA).
  • Track and close non-conformities from internal audits and management reviews.

Security Operations & Incident Response

  • Coordinate security incident response detection, containment, root cause analysis, client and regulator communication, and post-incident hardening.
  • Manage SIEM and log review cadence with the SecOps team; tune alerts and reduce noise.
  • Run security awareness training for engineering, delivery, and corporate teams.

Required Qualifications

  • Experience: in information security, with at least 2 years in a managerial or team-lead capacity.
  • Domain: Hands-on experience in BFSI, fintech, or SaaS environments handling regulated data.
  • Technical Depth: Working knowledge of cloud security on AWS (IAM, KMS, VPC, GuardDuty, Security Hub); solid understanding of OWASP Top 10, mobile and API security, and secure SDLC; ability to read VAPT reports critically rather than forward them to engineering.
  • Compliance: Practical, in-the-trenches experience with ISO 27001 and PCI DSS; familiarity with SOC 2 Type II and at least one regional privacy regulation.
  • Audit: Demonstrated experience leading or substantively supporting client security audits for banking customers.
  • Years: 610 years total, with progression from individual contributor to lead/manager.

Preferred Certifications

One or more of the following, with at least one current and active:

  • CISM - Certified Information Security Manager
  • CISA - Certified Information Systems Auditor
  • ISO 27001 Lead Auditor or Lead Implementer
  • PCI ISA or PCIP
  • CEH - Certified Ethical Hacker
  • AWS Certified Security Specialty

Skills & Attributes

  • Direct communicator able to hold a hard conversation with a delivery head about a missed control without escalating to the CISO every time.
  • Comfortable producing audit-grade documentation and walking external auditors through it in person.
  • Strong prioritisation: knows what to fix this week, what to put on the roadmap, and what to accept as residual risk.
  • Calm under incident pressure; structured under audit pressure.
  • Commercially aware understands that security controls must scale with delivery velocity, not block it.

What This Role Is Not

  • An entry-level analyst role.
  • A CISO-track, policy-only mandate this role must dig into tickets, configurations, and reports.
  • A SOC shift role.

Reporting Structure

This role reports directly to the CISO and works in close coordination with the Delivery Heads, Engineering Leads, DevOps, and Legal/DPO functions. The Manager InfoSec & Compliance will, over time, lead a small team of security analysts and engineers.



More Info

Full Time
o
IT Computers / Hardware
Not Disclosed
English
Not Disclosed

Education

Any Graduate
Not Disclosed

Required Skills

Information Security Management Information security security compliance Security audit Management Auditing Security compliance

Contact Details

Vernost Marketing
+91 987654567
sales@vernost.com
  • Experience6+ years
  • Salary Above 10 LAKHS ANNUALLY
  • Location for Hiring Mumbai
  • Apply Now
Latest Job

Similar Jobs

HR Recruiter
Transient HR
  • 1 years
  • Mumbai
  • 18 Hours
Senior Human Resource Recruiter
Eclat Health Solutions
  • 2 years
  • Mumbai
  • 18 Hours
Recruitment Executive -HR
be3 Human Resource Management
  • Fresher
  • Mumbai
  • 18 Hours
Jr Recruiter -Ghansoli
PES Hr Services
  • Fresher
  • Mumbai
  • 18 Hours
HR Recruiter
Csml Group
  • 1 years
  • Mumbai
  • 18 Hours
Hr Recruiter Work From Home
Swati 7011890554
  • Fresher
  • Kolkata
  • 18 Hours