Manager Information Security & Compliance
Vernost Marketing
- Posted: 2 months ago
- Openings: 10
- Applicants: 0
Job Description
JD
Position
Manager Information Security & Compliance
Reports To- Chief Information Security Officer (CISO)
Function -Information Security & Risk
Location- Mumbai (HQ) / Dubai
Experience -6-10 years
Employment Type- Full-time, Permanent
Role Summary
The Manager Information Security & Compliance owns the operational security posture of Vernost's products, projects, and corporate environment under the direction of the CISO. This is a hands-on role: regularising security practices across delivery teams, leading client and regulatory audits, managing VAPT cycles, and maintaining certifications including ISO 27001, PCI DSS, SOC 2 Type II DPDPA, PDPL, PDPA and GDPR.
Key Responsibilities
Security Governance & Project Assurance
- Embed security controls into every active client project (loyalty, points exchange, travel, marketplace, payments) from kickoff to go-live.
- Maintain and enforce the InfoSec policy framework secure SDLC, access control, change management, data classification, and incident response.
- Conduct internal security reviews on architecture, code, and infrastructure changes before production release.
- Drive consistency of security controls across teams in India, UAE, and KSA delivery centres.
Audit & Client Assurance
- Act as the primary point of contact for client security audits bank and non-bank including questionnaires, evidence collection, walkthroughs, and remediation tracking.
- Support regulatory and certification audits for banking clients, including SAMA, CBUAE, RBI, and MAS where applicable.
- Own renewals and surveillance audits for ISO 27001, PCI DSS, and SOC 2 Type II in coordination with external auditors.
Vulnerability Management & VAPT
- Plan, scope, and manage VAPT engagements (internal and third-party) across web, mobile, API, and cloud surfaces.
- Triage findings, drive remediation with engineering teams, and report closure status to the CISO and clients.
- Run continuous vulnerability scanning, patch management oversight, and secure configuration baselines.
Compliance & Risk
- Maintain the enterprise risk register; conduct periodic risk assessments and present mitigation plans.
- Ensure compliance with applicable data protection regimes, including DPDPA (India), GDPR, and PDPL (UAE, KSA).
- Track and close non-conformities from internal audits and management reviews.
Security Operations & Incident Response
- Coordinate security incident response detection, containment, root cause analysis, client and regulator communication, and post-incident hardening.
- Manage SIEM and log review cadence with the SecOps team; tune alerts and reduce noise.
- Run security awareness training for engineering, delivery, and corporate teams.
Required Qualifications
- Experience: in information security, with at least 2 years in a managerial or team-lead capacity.
- Domain: Hands-on experience in BFSI, fintech, or SaaS environments handling regulated data.
- Technical Depth: Working knowledge of cloud security on AWS (IAM, KMS, VPC, GuardDuty, Security Hub); solid understanding of OWASP Top 10, mobile and API security, and secure SDLC; ability to read VAPT reports critically rather than forward them to engineering.
- Compliance: Practical, in-the-trenches experience with ISO 27001 and PCI DSS; familiarity with SOC 2 Type II and at least one regional privacy regulation.
- Audit: Demonstrated experience leading or substantively supporting client security audits for banking customers.
- Years: 610 years total, with progression from individual contributor to lead/manager.
Preferred Certifications
One or more of the following, with at least one current and active:
- CISM - Certified Information Security Manager
- CISA - Certified Information Systems Auditor
- ISO 27001 Lead Auditor or Lead Implementer
- PCI ISA or PCIP
- CEH - Certified Ethical Hacker
- AWS Certified Security Specialty
Skills & Attributes
- Direct communicator able to hold a hard conversation with a delivery head about a missed control without escalating to the CISO every time.
- Comfortable producing audit-grade documentation and walking external auditors through it in person.
- Strong prioritisation: knows what to fix this week, what to put on the roadmap, and what to accept as residual risk.
- Calm under incident pressure; structured under audit pressure.
- Commercially aware understands that security controls must scale with delivery velocity, not block it.
What This Role Is Not
- An entry-level analyst role.
- A CISO-track, policy-only mandate this role must dig into tickets, configurations, and reports.
- A SOC shift role.
Reporting Structure
This role reports directly to the CISO and works in close coordination with the Delivery Heads, Engineering Leads, DevOps, and Legal/DPO functions. The Manager InfoSec & Compliance will, over time, lead a small team of security analysts and engineers.
More Info
Education
Required Skills
Contact Details
Latest Job
Similar Jobs
- 1 years
- Mumbai
- 18 Hours
- 2 years
- Mumbai
- 18 Hours
- Fresher
- Mumbai
- 18 Hours
- Fresher
- Mumbai
- 18 Hours
- 1 years
- Mumbai
- 18 Hours
- Fresher
- Kolkata
- 18 Hours
