Search by job, company or skills

Information Security Manager

Information Security Manager

Trilegal
15-17 Years
Not Disclosed
  • Posted 16 hours ago
  • Be among the first 10 applicants

Job Description

Information Security Manager

Experience: 15–16 Years

Location: Bengaluru, India

Function: Information Security

Industry Preference: Legal Services / Professional Services / Consulting

The Information Security Manager will operate within the Information Security function and will be responsible for driving the execution, governance, and reporting of key cybersecurity initiatives across the firm. The role will ensure that security programs aligned to Risk Management, Business Continuity, Disaster Recovery, GRC, and Cloud Security are executed effectively and tracked through a structured governance framework.

The individual will act as a central coordination point between Information Security, Technology, Risk, Compliance, and business stakeholders, ensuring that cybersecurity initiatives are delivered on time, within scope, and aligned with regulatory and client expectations.

Key Responsibilities

1. Security Program Governance

Establish and manage the Information Security governance framework.

Track and report progress of security initiatives, remediation programs, and regulatory projects.

Maintain program dashboards, risk registers, and executive reporting for the leadership team.

Conduct monthly governance reviews with security leadership and the DIG office.

2. Risk & Compliance Program Management

Coordinate enterprise risk assessments and security risk remediation programs.

Track closure of audit observations, risk findings, and compliance gaps.

Work closely with the GRC team on policy implementation and regulatory compliance initiatives.

3. Business Continuity & Disaster Recovery Programs

Manage the BCP/DR program lifecycle, including:

Business Impact Analysis (BIA)

Risk assessments

DR testing exercises

Tabletop simulations

Track action items arising from BCP/DR drills and resilience programs.

4. Cloud Security Initiatives

Coordinate security initiatives across cloud platforms, including AWS, Azure, and GCP.

Track implementation of cloud security controls, architecture reviews, and remediation programs.

Work with cloud engineering teams to ensure security alignment.

5. Stakeholder Management

Act as a bridge between the CISO office, IT teams, business functions, and external vendors.

Manage cross-functional dependencies for security initiatives.

Provide executive-level reporting and program updates to leadership committees.

6. Metrics & Reporting

Develop security KPIs and program maturity dashboards.

Maintain the security roadmap and transformation tracking.

Produce quarterly board-level reports on cybersecurity initiatives.

Required Skills & Experience

Experience

15–16 years of total experience, with at least 8–10 years in PMO, program management, or information security management roles.

Experience managing enterprise cybersecurity or technology transformation programs.

Domain Knowledge

Strong understanding of:

  • Information Security Governance
  • Enterprise Risk Assessment
  • Business Continuity & Disaster Recovery
  • GRC frameworks
  • Cloud security fundamentals

Familiarity with standards such as:

  • ISO 27001
  • NIST
  • SOC 2
  • Regulatory compliance frameworks

Preferred Certifications

One or more of the following preferred:

  • PMP / PRINCE2
  • CISA
  • CRISC
  • CISM
  • ISO 27001 Lead Implementer / Lead Auditor

Key Competencies

  • Strong information security program management and governance experience
  • Ability to manage multiple concurrent cybersecurity initiatives
  • Strong executive communication and reporting skills
  • Risk-oriented thinking
  • Strong stakeholder management, influence, and coordination skills

Success Metrics for the Role

  • Timely delivery of security roadmap initiatives
  • Closure rate of security risk remediation programs
  • Effective BCP/DR program execution
  • Quality and effectiveness of Information Security reporting and governance dashboards

We are an equal opportunity employer and value diversity. We do not discriminate based on gender, race, age, sexual orientation, and religious identities or any other applicable characteristics protected by law. We seek individuals who uphold the highest standards of integrity, demonstrate professionalism in every interaction, treat others with respect, and consistently align personal ambition with the collective goals of the firm.

The incumbent is required to comply with the Firm's Information Security policies and procedures, including safeguarding confidential information, adhering to secure data handling practices, and promptly reporting information security incidents.

More Info

Job Type:
Industry:
Employment Type:

Key Skills

GRC frameworks

Enterprise Risk Assessment

Cloud security fundamentals

Business Continuity Disaster Recovery

SOC 2

About Company