Information Security Manager - IT - India
Job no: IND2025-CTOB20
Work type: Permanent - Full Time
Location: India
Categories: Mid-Senior Level
Information Security Manager(GRC)
Role Profile: |
Alshaya employed a dedicated security team to implement and maintain the organization's information security program. Typically, this group is led by a chief information officer. The security group is generally responsible for conducting risk management, a process through which vulnerabilities and threats to information assets are continuously assessed, and the appropriate protective controls are decided on and applied. The value of an organization lies within its information and its security is critical for business operations, as well as retaining credibility and earning the trust of clients. Information security programs are built around the core objectives of the CIA triad: maintaining the confidentiality, integrity and availability of IT systems and business data. Role and
|
The below Key Performance Areas include but are not limited to: |
• Work closely with the leadership for the Security requirements and implementation of security initiatives based on ISMS (ISO 27001:2013), Business Continuity Management Systems (BCMS ISO22301:2012) and IDR, PCI-DSS, SSAE SOC etc. • • Direct, develop, implement and manage Information Security practices with hands-on experience managing GRC for the complete Organization • • Responsible for consulting, design and implementation of security controls and solutions to reduce the risk to Organization. • • Directly responsible for procedures and controls to assure compliance with applicable regulatory and legal requirements as well as good business practices • • Design information security management systems that impact multiple domains and operations • • Experience consulting, designing and implementing security technologies, such as IDS/IPS, SIEM, access controls, encryption and forensic tools. • • Experience working with VA/PT technologies, Infrastructure & Endpoint Security solutions • • Broad understanding of various Risk models (e.g. OSSTMM, CVSS, OCTAVE) • • Experience in Security evaluation, threat assessments, threat modelling, risk assessment methodologies and frameworks. • • Work on RFP related to security services and end-to-end supplier security management Page 2 of 2
• • Experience in design, plan, architecture and management principles for Application Security, Infrastructure Security, Encryption, Data masking , Database security, Cloud Security, PKI , Certificate life cycle management , Enterprise key management, Data Governance etc • • Develop, implement and enforce suitable and relevant information security policies, ensuring that these are compliant with Alshaya IT Policies and standards and other legislation and regulations related to information security; reviewing policies on a regular basis. • • Inform, consult and advise the company on matters related to compliance and data protection laws including privacy compliance for GDPR and relevant standards • • Manage Internal and External audit related to information security compliance and best IT practices • • Advise business and project teams on Security requirements • • Responsible for training and awareness
|
Knowledge (Desired):
|
Experience 10 15 years minimum experience in Information Security Domain Post Graduate/graduate in Information Security or IT related field. • Preferred certifications: Preferred certifications: CISM, ISMS LA/ LI, BCMS LA/LI, CISSP, ITIL • • Optional PMP certification
|
Skills:
|
Additional role requirements: |
|
All employees are required to adhere to company policies and procedures, and work in line with Alshaya’s Vision and Values - ‘Think Big’, ‘Act Small’, ‘Be You’. |
Advertised: India Standard Time
Application close:
Apply now