Skip to content

Open nowPosted 4 days ago

Program Manager-Security Operations & Compliance

anovia16 open roles

Where
India, Remote
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowProgram Manager-Security Operations & Complianceanovia · India, Remote
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on anovia's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.2%30 days
This job: posted 4 days ago

The posting

Anovia (formerly Innovatia Technical Services) is an industry-leading technology outsourcing support provider with expertise in the telecommunications industry. Operating for over 20 years, we specialize in workflow and knowledge processes, as well as technical support, helpdesk and multilingual support services. With over 200 professional experts across the globe, we service some of the worlds’ most successful Fortune 500 and Fortune 1000 companies.

About the Role

Anovia is looking for a hands-on information security and compliance professional with practical experience working with ISO/IEC 27001, SOC 2, HIPAA, or similar security and compliance programs.

The successful candidate will have experience helping an organization prepare for and work through an audit or certification process, including developing and maintaining policies and controls, supporting evidence collection, coordinating activities and meetings, tracking actions, and working with internal and external auditors.

This is also a build and delivery role. Anovia has a number of technical and operational initiatives that require more structure, planning, coordination, and follow-through. The successful candidate will be comfortable taking an initiative that is not yet well defined, establishing a practical plan, coordinating the people involved, and driving the work through to completion. Examples could include implementing a new security tool, improving security monitoring or vulnerability management, or helping establish a NOC/SOC capability.

Responsibilities

  • Maintain and continue to develop Anovia's ISO/IEC 27001 Information Security Management System (ISMS), including policies, procedures, controls, risks, objectives, evidence, and ongoing improvement activities.
  • Support ISO 27001, SOC 2, HIPAA, and other security and compliance initiatives as they are introduced and developed.
  • Coordinate internal and external audit activities, including preparing evidence, scheduling and facilitating meetings, maintaining action items, and ensuring audit findings and resulting actions are addressed.
  • Maintain the information asset inventory and data classification program, including assigning and tracking ownership.
  • Support identity and access management activities, including provisioning and de-provisioning, access reviews, least-privilege requirements, and privileged access controls.
  • Monitor and improve security tooling and processes, including Microsoft 365 security capabilities, Microsoft Defender, Intune, Entra ID, security monitoring, endpoint protection, and vulnerability management.
  • Coordinate vulnerability identification, remediation tracking, and escalation of significant findings.
  • Coordinate third-party and vendor security assessments, including security questionnaires and contract review support.
  • Develop, maintain, and support adoption of information security policies, standards, and operating procedures.
  • Coordinate security awareness training and phishing simulation programs.
  • Support security incident response activities, including detection, containment, investigation, root-cause analysis, and post-incident reporting.
  • Support business continuity and disaster recovery activities, including maintenance of recovery requirements, testing, and related evidence.
  • Lead or coordinate technical and operational initiatives from initial scope through implementation, establishing plans, identifying dependencies and owners, coordinating stakeholders, tracking risks and issues, and driving work to completion.
  • Serve as a primary point of contact for internal and external auditors and coordinate responses with relevant business and technical stakeholders.

Required Qualifications

  • 4+ years of progressively responsible experience in information security, IT compliance, GRC, security operations, or a related field.
  • Practical experience working with ISO/IEC 27001, SOC 2, or a comparable security and compliance framework. Experience should include meaningful participation in an audit or certification process and familiarity with activities such as policy development, control implementation, evidence collection, audit preparation, management meetings, action tracking, and remediation.
  • Experience with GRC processes and tools, including risk and control management, evidence collection, compliance tracking, audit preparation, and remediation or corrective-action management.
  • Working experience with the Microsoft 365 security environment, including familiarity with Microsoft Defender, Intune, Entra ID, and related security and compliance capabilities.
  • Demonstrated ability to take an ambiguous technical or operational initiative and bring structure to it, including defining scope, developing a practical plan, coordinating stakeholders, managing dependencies and issues, and driving the work through to completion.
  • Working knowledge of information security principles, risk management, access control, vulnerability management, incident response, and security awareness.
  • Comfortable working directly with auditors, technical teams, business stakeholders, vendors, and leadership.
  • Strong organizational and communication skills, with the ability to manage multiple ongoing activities and follow through on commitments.
  • Bachelor's degree in Information Security, Computer Science, IT, or a related field, or equivalent practical experience.

Nice to Have

  • Experience with HIPAA Security and Privacy Rule requirements or other healthcare security and privacy requirements.
  • Experience with GRC platforms such as Secureframe, Vanta, Drata, or OneTrust.
  • Experience with SIEM, EDR/endpoint protection, vulnerability scanners, or related security tooling beyond the Microsoft 365 environment.
  • Experience with NIST CSF or other complementary security frameworks.
  • Experience managing contractors or vendors during technical or security initiatives.
  • Experience helping establish or improve security monitoring, NOC, SOC, or similar operational capabilities.
  • Experience with business continuity and disaster recovery planning.

Certifications

Certifications are useful supporting evidence of knowledge, but are not a substitute for practical experience. Relevant certifications include:

  • ISO/IEC 27001 Lead Implementer or Lead Auditor
  • CISA (Certified Information Systems Auditor)
  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)

Relevant certifications are preferred but not require

Benefits at Anovia

  • Comprehensive Health Insurance policy
  • Employee Wellness Program with focus on mental health
  • Robust reward and recognition programs
  • Company incentive programs offered
  • Attractive leave policy: Holiday Leave, Maternity Leave, Paternity Leave, Birthday leave, Bereavement Leave and Paid Leave for personal time off
  • Ample growth and learning opportunities
  • Remote work opportunities
  • Focus on work/life balance
  • Immigration Program supporting immigration to Canada for eligible employees

We thank all candidates for their interest, however, only those selected for an interview will be contacted.

Anovia is an equal opportunity employer.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against anovia's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on anovia's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    anovia's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.