Enter a job title or keyword

ISMS Manager


Job Location:

Bengaluru - India

Monthly Salary: INR 7 - 10
Posted: 7 October 2026 (Yesterday)
Application Deadline: 4 January 2027
Vacancies: 1 Vacancy

Job Summary

Job Description

ISMS Manager Security Architecture & Compliance

Full-Time Mid-Level Manager Grade Role Title ISMS Manager Security Architecture & Compliance Grade Mid-Level Manager Department Cybersecurity Reporting To Director of Cybersecurity

Purpose of the Role

The ISMS Manager is a senior practitioner responsible for delivering end-to-end information security management across four core functions: security architecture reviews ISO 27001 and SOC 2 compliance presales security engagements and post-sales RFI/RFP support. The role requires an individual review cloud architecture managing audit cycles briefing enterprise CISOs and responding to client security questionnaires operating with a high degree of independence and accountability.

Key Responsibilities

1. Security Architecture Review

Conduct end-to-end security architecture reviews for product and platform offerings covering application API cloud infrastructure and data layers.

Engage directly with engineering and product teams to embed security controls at the design stage threat modelling data flow validation and trust boundary definition.

Assess third-party integrations vendor components and new feature deployments for security risk prior to go-live.

Maintain security architecture documentation including reference architecture component-level controls mapping and deviation/exception registers.

Define and enforce secure SDLC practices in alignment with industry standards (OWASP NIST CIS).

2. Compliance ISO 27001 & SOC 2 (BAU)

Own the information security management system (ISMS) and drive ongoing compliance for ISO 27001 and SOC 2 Type II from BAU control maintenance through audit readiness and recertification.

Manage the full evidence lifecycle: control testing artefact collection gap remediation and liaison with external auditors and certification bodies.

Drive remediation of audit findings in coordination with engineering infrastructure and operations teams.

Maintain the risk register asset inventory incident response plan business continuity provisions and vendor risk assessment programme in alignment with ISO 27001 Annex A.

Track changes in applicable regulations and standards updating the control framework accordingly.

3. Presales Security Architecture Briefings

Act as the security subject-matter expert during enterprise sales cycles briefing CISOs CIOs and technical evaluators at prospective accounts on architecture data residency access controls encryption and compliance certifications.

Develop and maintain standard presales security collateral: security overview decks trust and compliance one-pagers data processing summaries and product security FAQs.

Support sales and product teams in scoping security requirements during deal qualification solution design and contract negotiation stages.

Represent the security function at client meetings and procurement panels as required.

4. Post-Sales Support RFI / RFP Responses

Own end-to-end completion of security RFIs and RFPs from enterprise clients including those in regulated sectors (BFSI healthcare government).

Produce accurate technically detailed responses covering penetration testing cloud security VAPT findings and remediation status data privacy compliance and third-party risk management.

Build and maintain a structured RFI/RFP response library keeping answers current with the evolving controls landscape and certification status.

Manage client security questionnaires (SIG CSA CAIQ and bespoke sector questionnaires) within agreed SLA commitments.

Serve as the primary point of contact for post-sales security queries escalations and due diligence reviews from enterprise accounts.

Required Qualifications & Experience

Experience

812 years of progressive information security experience with at least 3 years in a senior security management or advisory capacity.

Demonstrated end-to-end ownership of ISO 27001 and SOC 2 compliance programmes from implementation through sustained BAU and certification cycles.

Hands-on background in security architecture review for SaaS or cloud-native platforms; familiarity with API security microservices and multi-tenant architectures.

Proven experience owning or significantly contributing to enterprise RFI/RFP security responses.

Prior exposure to regulated industry sectors (BFSI healthcare or equivalent) understanding of client security assessment dynamics and procurement-driven security requirements.

Technical Knowledge

Cloud security across AWS / Azure / GCP IAM network controls encryption logging and CSPM concepts.

Application and API security OWASP Top 10 authentication mechanisms (OAuth 2.0 SAML OpenID Connect) and secure SDLC practices.

Data protection and privacy DPDPA GDPR concepts data classification frameworks DLP controls.

Vulnerability management lifecycle VAPT coordination CVSS scoring remediation tracking and risk acceptance.

Governance frameworks ISO 27001 SOC 2 NIST CSF CIS Controls; ability to map controls across multiple frameworks.

Certifications

CISSP or CISM required.

ISO 27001 Lead Auditor or Lead Implementer strongly preferred.

CCSP AWS Security Specialty or equivalent cloud security certification preferred.

CEH or equivalent offensive security certification advantageous.

Key Competencies Competency What Were Looking For Executive Presence Comfortable briefing CISOs CIOs and procurement panels structured credible and calm under scrutiny. Client Communication Translates complex security concepts into clear commercially relevant language for both technical and non-technical audiences. Compliance Rigour Detail-oriented in executing audit evidence cycles control testing and documentation not just high-level oversight. Cross-Functional Collaboration Effective at working across engineering product legal and sales teams to drive security outcomes. Commercial Awareness Understands how security posture influences enterprise deal velocity and client retention in regulated sectors. Ownership Mindset Proactive in identifying and addressing risks takes accountability for outcomes without needing to be prompted. Adaptability Capable of shifting between architecture review compliance delivery and client-facing engagements within the same week.

Confidential For internal recruitment purposes only.


Required Skills:

Security Architecture ReviewCompliance ISO 27001 & SOC 2Presales Security Architecture Briefings