We are seeking a self-motivated, proactive Information Security Manager to own and run the company’s information security programme end-to-end with minimal intervention. This is a hands-on leadership role for a security professional who can design, implement, operate and continuously improve security controls across cloud, applications, networks, endpoints and third-party vendors while confidently representing the organisation to clients, auditors and regulators.
1.Leadership & Program Management:
Own and improve a comprehensive, business-aligned information security programme.
Define and manage the security roadmap, policies, standards, and architecture principles.
Oversee budget and resourcing as the organisation grows.
2.Risk Management & Compliance:
Maintain the risk register and conduct third-party/vendor security assessments.
Manage contractual SLAs and implement IAM controls (RBAC, least privilege, MFA, PAM, SSO).
Ensure compliance with applicable industry standards and data privacy laws (ISO, NIST, PCI, SOC2, RBI, GDPR, CCPA).
Lead external audits, manage client due diligence, and oversee remediation of findings.
3.Security Operations & Incident Response:
Integrate security within the SDLC.
Implement and monitor cloud security controls and tools.
Operate and maintain the Incident Response Plan (IRP) and lead incident management and post-mortems.
Oversee vulnerability management, penetration testing, and patching cycles.
Manage security tools (SIEM, EDR, DLP, WAF) and track key metrics for ongoing improvement.
4.Data Security & Privacy:
Maintain and test business continuity and disaster recovery plans.
Enforce data classification, protection, and retention policies.
Ensure confidentiality, integrity, and availability of sensitive financial data.
Drive compliance with data privacy regulations.
5.Security Awareness & Training:
6.Stakeholder Engagement & Communication:
Communicate complex security topics clearly to both technical and non-technical audiences, including leadership, clients, auditors, and regulators.
Collaborate with engineering, product, operations, and legal teams to embed security by design throughout the business.
Requirements:
Experience:
Experience managing InfoSec for multiple companies, showcasing adaptability.
Proven record of managing and scaling end-to-end security programs independently.
Technical Expertise:
Deep knowledge of InfoSec principles, frameworks, and best practices (e.g., ISO 27001, NIST CSF).
Familiarity with DevSecOps and CI/CD pipeline security integration.
Strong experience with finance regulatory standards (PCI DSS, SOC 2, GDPR, etc.).
Skilled in cloud security (AWS, Azure, GCP).
Hands-on with security tools (SIEM, EDR, DLP, IAM, WAF) and network/app/database security.
Experienced in incident response, forensics, and recovery.