Skip to content

Open nowPosted 46 days ago

InfoSec Manager

Workable (global search)108,016 open roles

Where
Delhi, DL, India
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowInfoSec ManagerWorkable (global search) · Delhi, DL, India
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 46 days ago

Workable (global search) median: 7 days open

The posting

We are looking for an InfoSec Manager who will run the company’s day-to-day Governance, Risk, and Compliance (GRC) activities under GDS, including security documentation, client security reviews, enterprise InfoSec processes, certifications, privacy requirements, and security readiness. Strategic security direction and oversight will sit with the Fractional CISO, while the InfoSec Manager will be responsible for ensuring that agreed security and compliance processes are executed effectively across the business.

This person will become the primary operational owner for InfoSec and GRC when enterprise clients request security reviews, questionnaires, vendor assessments, certifications, contractual security information, or compliance evidence.

This role is important because the company needs a strong but practical InfoSec foundation to build client trust, demonstrate reliability, and ensure security, compliance, documentation, certifications, and data protection requirements are professionally managed. The focus is on applying security and compliance intelligently and proportionately, avoiding unnecessary process overhead or procurement blockers while maintaining appropriate risk controls.

Key Responsibilities

  • Own the full client-facing InfoSec process from initial security request through completion and approval.
  • Manage enterprise security questionnaires, vendor assessments, compliance forms, procurement security documents, evidence collection, and follow-up actions.
  • Drive new ISO readiness, including coordinating evidence, controls, audit preparation, remediation activities, and maintaining the ISMS on a day-to-day basis.
  • Own operational GDPR and data protection activities, including DPAs, DPIAs, privacy/security assessments, and reviewing security and privacy clauses within client and vendor contracts.
  • Maintain all company security materials, including trust page content, data-room documents, policies, procedures, certifications, architecture diagrams, compliance evidence, and supporting security documentation.
  • Build and maintain a central InfoSec knowledge base containing approved standard responses, reusable evidence, and guidance for common enterprise security and privacy questions.
  • Join client security calls when required and work with technical/data infrastructure owners to accurately explain architecture, hosting, data flows, access control, encryption, backup, logging, monitoring, incident response, and secure development practices.
  • Work with leadership, engineering, infrastructure, QA, legal/privacy stakeholders, and client-facing teams to ensure security and compliance responses are accurate, consistent, proportionate, and professionally managed.
  • Support new certifications, renewals, audits, assessments, recurring compliance reviews, and ongoing security evidence requests.
  • Propose practical and proportionate security and compliance improvements across software development, deployment, cloud infrastructure, access management, incident response, vendor management, and client onboarding.
  • Apply security and compliance controls pragmatically so that risk is appropriately managed without creating unnecessary process, slowing procurement, or introducing avoidable blockers for clients, vendors, or internal teams.
  • Coordinate with team to ensure deployment environments follow approved security and compliance standards.
  • Coordinate with QA and engineering for security testing, access testing, permission validation, secure SDLC evidence, and other required assurance activities.
  • Maintain an InfoSec action tracker covering client requests, risks, missing evidence, audit findings, certification tasks, remediation items, owners, and completion status.
  • Escalate material or high-risk security and compliance findings to the Head of GDS, or senior leadership, providing clear context, risk assessment, and recommended actions.
  • Work within the strategic security direction established by the Fractional CISO while owning the day-to-day execution and continuous improvement of GRC activities under GDS.

Requirements

  • Strong hands-on experience with ISO 27001 and SOC 2, including implementation, control operation, audit preparation, evidence collection, remediation, or certification readiness.
  • Practical experience with GDPR, DPAs, DPIAs, data protection requirements, privacy/security contractual clauses, and associated compliance evidence.
  • Strong experience completing enterprise security questionnaires, client security assessments, vendor-risk reviews, procurement security requirements, and related evidence requests.
  • Strong understanding of GRC, application security, cloud security, data protection, enterprise security reviews, and risk management.
  • Working knowledge of cloud platforms such as GCP, sufficient to confidently support enterprise security assessments and client security discussions.
  • Knowledge of access control, SSO, encryption, key management, logging, monitoring, backup and recovery, incident response, vulnerability management, and secure SDLC practices.
  • Ability to read and understand architecture diagrams, API flows, data-flow diagrams, infrastructure documentation, and technical security evidence.
  • Experience preparing, organizing, and presenting security and compliance evidence for enterprise clients, auditors, and assessors.
  • Strong documentation, stakeholder management, and communication skills, with the ability to translate technical and compliance topics into clear business responses.
  • Ability to apply security and compliance requirements pragmatically, balancing risk reduction with commercial and operational needs.
  • Relevant professional certifications such as ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, CISM, or equivalent security/GRC certifications are highly valued.

Benefits

  • Private Health Insurance
  • Paid Time Off
  • Work From Home
  • Training & Development
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.