Skip to content

Open nowPosted 19 days ago

Information Security Engineer (GRC)

osttrahcm19 open roles

Where
Gurugram, Haryana, India
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowInformation Security Engineer (GRC)osttrahcm · Gurugram, Haryana, India
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on osttrahcm's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 19 days ago

The posting

About the Role: The team: The Information Security team is responsible for security controls relating to protecting information in all formats. We maintain a number of policies and an Information Security Management System which dictates how infosec is integrated into processes as well as tools and technical controls to directly protect against cyber security threats.    Responsibilities and impact: We are seeking a dedicated and collaborative Information Security Engineer to join our growing Governance, Risk, and Compliance (GRC) team. In this role, you will play a pivotal part in maintaining, maturing, and auditing our information security management framework. The ideal candidate has 3–5 years of direct experience within an InfoSec GRC function and thrives in a team-oriented environment. You will be responsible for ensuring our policies remain up-to-date, driving our ISO 27001 certification lifecycle, and executing core compliance operations like user access reviews, exception management, and security awareness programs.   Key Responsibilities Governance & ISO 27001 Management

ISMS Governance: Manage and maintain our ISO 27001 Information Security Management System (ISMS) to ensure continuous compliance. Audit Facilitation: Lead internal security audits and act as a point of contact for external certification audits. Policy Management: Regularly review, update, and draft information security policies, standards, and procedures to align with evolving regulatory landscapes and business needs.

GRC Operations & Risk Management

Access Governance: Coordinate and oversee periodic user access reviews across critical systems. Exception Management: Evaluate, log, and monitor security policy exceptions, ensuring compensating controls are effectively implemented and tracked. Risk Culture: Administer the company-wide security awareness training program and orchestrate routine phishing simulations to strengthen our human firewall.

Collaboration & Communication

Partner closely with cross-functional teams (IT, Legal, HR, and Engineering) to embed security compliance into daily operations. Translate complex compliance requirements into actionable, easy-to-understand guidance for non-technical stakeholders. 

  What we’re looking for: Required Experience & Skills

Experience: 3–5 years of proven experience specifically within an Information Security GRC role.I ISO 27001 Expertise: Hands-on experience managing an ISO 27001 ISMS, including active participation in both internal and external certification audits. Core GRC Competencies: Direct experience executing user access reviews, phishing simulations, security training, and policy exception workflows. Communication: Exceptional verbal and written communication skills, with the ability to document clear policies and present findings to various business units. Soft Skills: A strong team player with a highly collaborative mindset, excellent problem-solving abilities, and a proactive approach to security culture.

Preferred Qualifications (Nice-to-Have)

Relevant industry certifications (e.g., ISO 27001 Internal/Lead Auditor, CISA, CRISC, Security+, or CISM). Experience with the ISO 42001 AIMS standard. Experience utilizing GRC automation platforms/tools.

The location: Gurgaon,India   Our Benefits: Global vision, local impact At OSTTRA, our benefits philosophy offers a market-competitive package that reflects our position as an industry leader. We want to ensure you feel valued, secure, and empowered wherever you are in the world. Our approach is built on three core pillars:

Global foundations: We provide a baseline of excellence across all our offices, focusing on comprehensive Health & Wellness, Financial Security, and Work-Life Balance. No matter your location, you are part of a culture that prioritizes your holistic well-being. Locally tailored: We benchmark in each market to ensure our packages are genuinely competitive where you live and work. Flexibility and growth: We empower you to work in a way that suits your life. This includes a hybrid working model, generous leave policies, and a commitment to your continuous professional development.

The Trust employee ownership plan Every employee at OSTTRA is an owner, and a member of The Trust, our employee ownership programme. Our distinct culture encourages colleagues to think and act like owners and raise the bar constantly. This plan reflects our belief that when we work together to build a stronger, more valuable organisation, then all colleagues should benefit from the value we create.   About OSTTRA We build and operate the infrastructure that the world’s post-trade financial system runs on. Launched in 2021, we have unified more than 20 years of heritage and expertise from four industry leaders into a single, integrated business. Today,we operate a trusted network that connects thousands of market participants to streamline end-to-end workflows, from trade capture through portfolio optimisation.We translate industry change into workable process, engineering an open, intelligent ecosystem that removes friction and reduces risk for the global markets. Our distinct ownership culture is underpinned by four behaviours: boldness, curiosity, accountability, and collaboration. In 2025 we were acquired by KKR, one of the world’s most successful private equity firms, and are on a journey of growth and impact.  Joining our team now is a unique opportunity - you will help to shape the next generation of post-trade, transform shared infrastructure into shared benefit, and accelerate your own career. Learn more at www.osttra.com. Equal opportunity employer statement at OSTTRA We are committed to fostering a connected and engaged workplace where all colleagues have access to opportunities based on their skills, experience, and contributions. Our hiring practices emphasise fairness, transparency, and merit, ensuring that we attract and retain the best talent. By valuing different perspectives and promoting a culture of respect and collaboration, we drive and operate the infrastructure that the world’s post-trade financial system runs on.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against osttrahcm's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on osttrahcm's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    osttrahcm's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.