About the Role
We are looking for a Junior ISMS Engineer to support the implementation, maintenance, monitoring, and continuous improvement of the organization's Information Security Management System (ISMS).
The ideal candidate should have practical experience in ISO 27001, information security risk assessment, security controls, compliance, audit support, and ISMS documentation.
Key ResponsibilitiesISMS & Documentation
- Maintain and update ISMS policies, procedures, standards, guidelines, and control documentation.
- Maintain ISMS records, registers, and evidence repositories.
- Support Statement of Applicability (SoA) maintenance and periodic reviews.
- Ensure proper version control, review, approval, and audit readiness of ISMS documentation.
Information Security Risk Management
- Conduct information security risk assessments for applications, systems, vendors, processes, and business activities.
- Identify and document information security risks, threats, vulnerabilities, and business impact.
- Maintain the Information Security Risk Register.
- Support risk scoring, risk treatment planning, and remediation tracking.
- Track risk mitigation activities through to closure.
- Support periodic risk reviews and risk reassessments.
Security Controls & Compliance
- Support assessment and testing of information security controls.
- Collect and validate security evidence from IT, Engineering, HR, Finance, Legal, and other teams.
- Identify control gaps and coordinate remediation activities.
- Support compliance mapping against ISO 27001, SOC 2, NIST CSF, CIS Controls, or similar frameworks.
- Support security questionnaires and third-party/vendor security assessments.
Audit Support
- Prepare and organize evidence for internal and external security audits.
- Coordinate with stakeholders and auditors during audit activities.
- Track audit observations, non-conformities, corrective actions, and remediation.
- Maintain audit trackers and evidence repositories.
- Support management reviews, security metrics, and compliance reporting.
Security Awareness & Improvement
- Support information security awareness and training programs.
- Communicate security policies and requirements to employees.
- Identify opportunities to improve ISMS processes, controls, and documentation.
- Prepare periodic security/compliance reports and dashboards.
Required Skills
- 2–4 years of experience in ISMS, GRC, Information Security, IT Risk, IT Audit, or Security Compliance.
- Practical understanding of ISO/IEC 27001 and ISMS.
- Experience with Information Security Risk Assessment and Risk Treatment.
- Experience maintaining or working with Risk Registers.
- Understanding of security controls and compliance requirements.
- Experience supporting security/internal/external audits and evidence collection.
- Strong documentation and stakeholder coordination skills.
- Good analytical and problem-solving ability.
- Good communication skills.
- Working knowledge of MS Excel/Google Sheets and MS Word/Google Docs.
Good to Have
- ISO 27001 Foundation / Internal Auditor / Lead Auditor / Lead Implementer certification.
- Experience with SOC 2, NIST CSF, CIS Controls, GDPR/DPDPA, or PCI DSS.
- Exposure to GRC/ISMS platforms such as Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC, or Archer.
- Knowledge of vulnerability management, access control, incident management, BCP/DR, and third-party risk management.
- Basic understanding of AWS, Azure, or GCP security.
Pay: ₹300,000.00 - ₹500,000.00 per year
Benefits:
Education:
Experience:
Location:
- Mumbai, Maharashtra (Required)
Work Location: In person