Search Jobs

Search by job, company or skills

Information Security Program Manager (ISO/IEC 27001)

Information Security Program Manager (ISO/IEC 27001)

Netsach
8-12 Years
Quick Apply
  • Posted 3 hours ago
  • Be among the first 10 applicants

Job Description

  1. Job Purpose

Looking for an experienced Information Security Program Manager to lead its ISO/IEC 27001:2022 program. The role holder will establish, maintain and continually improve their Information Security Management System (ISMS), manage information security and technical risk, and guide c through successful re-certification and surveillance audits, protecting the confidentiality, integrity and availability of information and systems that support their healthcare services.

As a secondary responsibility, the role supports their IT Service Management System (ISO/IEC 20000-1) and Business Continuity Management System (ISO 22301), working towards an integrated management system approach.

Job Title: Information Security Program Manager (ISO/IEC 27001)

Exp: 8 - 12yrs

Job Type: Fulltime

Work Location: Bangalore/Dubai

Please click the link to apply for this job - https://www.netsachglobal.com/job/information-security-program-manager-iso-iec-27001-netsach-8effcb.

Kindly register and upload your resume at www.netsachglobal.com.

  1. Key Responsibilities

  • Plan, lead and manage the end-to-end ISO/IEC 27001 program, including ISMS scope definition, timelines, budget, resources and stakeholder reporting.
  • Review existing information security policies, standards, procedures and records to assess completeness and alignment with ISO/IEC 27001:2022 and ISO/IEC 27002.
  • Examine current security practices and controls across people, processes and technology to evaluate how effectively they operate in practice.
  • Conduct a detailed gap analysis against ISO/IEC 27001 requirements (Clauses 4–10 and Annex A controls) and produce a prioritized remediation roadmap.
  • Develop and maintain the information security risk management methodology, and conduct periodic technical risk assessments of applications, infrastructure, networks, cloud services and medical and clinical systems.
  • Maintain the information security risk register and risk treatment plans, and track the implementation of treatments with risk and control owners.
  • Coordinate periodic vulnerability assessments, penetration tests and configuration reviews, and ensure findings are risk-rated, remediated and verified.
  • Establish and manage a CIS-based compliance program, adopting the CIS Critical Security Controls (v8) and CIS Benchmarks as secure configuration baselines for operating systems, databases, network devices, cloud platforms and applications.
  • Conduct periodic CIS compliance assessments using automated scanning tools (e.g., CIS-CAT Pro, Tenable, Qualys), track compliance scores against agreed targets, and coordinate remediation or documented exceptions with system owners.
  • Prepare and maintain the Statement of Applicability (SoA) and the documentation required for the ISMS, including the ISMS scope, policy, objectives and supporting procedures.
  • Assess information security risks of third parties and suppliers, and ensure appropriate security requirements are included in contracts.
  • Establish and run the ISMS internal audit program and management reviews, and track nonconformities and corrective actions through to closure.
  • Preparefor Stage 1 and Stage 2 re-certification audits and ongoing surveillance audits, coordinate with the certification body, and lead the response to any findings.
  • Define information security KPIs and metrics, and generate and present periodic (monthly and quarterly) reports covering risk posture, control effectiveness, vulnerability and remediation status, CIS compliance scores, security incidents, audit findings and awareness completion, to support management reviews and decision-making.
  • Drive information security awareness and training so that staff understand their responsibilities within the ISMS.
  • Ensure the ISMS aligns with Company's policies and applicable UAE and Dubai Government information security and data protection requirements, including the UAE Information Assurance Standards, Dubai Electronic Security Center (DESC) requirements and healthcare data regulations.

  1. Secondary Responsibilities

  • Support the implementation, maintenance and certification of the IT Service Management System (ISO/IEC 20000-1) and the Business Continuity Management System (ISO 22301), working closely with the IT Service Management and Business Continuity teams.
  • Align ISMS controls with ITSM processes, including incident, problem, change, configuration, capacity, availability and supplier management.
  • Contribute to business impact analysis (BIA), the definition of recovery objectives (RTO/RPO) and continuity risk assessments for critical IT services and information assets.
  • Support the development, review and testing of IT service continuity, disaster recovery and business continuity plans, and ensure lessons learned are captured and acted upon.
  • Identify opportunities for an integrated management system across ISO/IEC 27001, ISO/IEC 20000-1 and ISO 22301, including shared policies, documentation, internal audits and management reviews.
  • Support internal and external audits for ISO/IEC 20000-1 and ISO 22301, including evidence preparation and follow-up of corrective actions.

  1. Qualifications and Experience

  • Bachelor's degree in Information Security, Information Technology, Computer Science or a related field.
  • [7–10]+ years of experience in information security, including at least [3] years leading ISMS, security risk or compliance programs.
  • Proven track record of leading at least one ISO/IEC 27001 implementation or certification.
  • In-depth knowledge of ISO/IEC 27001:2022, ISO/IEC 27002 and ISO/IEC 27005, and of risk assessment methodologies.
  • Hands-on experience implementing and assessing the CIS Critical Security Controls and CIS Benchmarks, including the use of configuration compliance scanning tools.
  • Solid technical understanding of networks, operating systems, cloud platforms, identity and access management, and security technologies (e.g., firewalls, SIEM, EDR, vulnerability scanners).
  • Working knowledge of ISO/IEC 20000-1 and ISO 22301; hands-on implementation or audit experience with these standards is a strong advantage.
  • Familiarity with UAE and Dubai information security regulations and healthcare data protection requirements.
  • Experience in healthcare or government environments is preferred.

  1. Preferred Certifications

  • ISO/IEC 27001 Lead Implementer and/or Lead Auditor
  • CISSP, CISM or CISA
  • ISO/IEC 20000-1 and/or ISO 22301 Lead Implementer or Lead Auditor (advantageous)
  • CRISC or an equivalent risk management certification (advantageous)
  • PMP, PRINCE2 or equivalent project management certification

  1. Key Competencies

  • Program and change management
  • Risk-based thinking and sound technical judgement
  • Stakeholder management and ability to influence without direct authority
  • Analytical thinking and attention to detail
  • Excellent written and verbal communication in English (Arabic is an advantage)
  • Facilitation, coaching and training delivery

More Info

Job Type:
Function:
Employment Type:

Key Skills

Information Security Program Manager (ISO/IEC 27001)

IT Service Management System (ISO/IEC 20000-1)

Business Continuity Management System (ISO 22301)

ISO/IEC 27001

CIS Critical Security Controls (v8)

CIS Benchmarks

CIS compliance assessments

ISMS internal audit program

healthcare data

ISO/IEC 20000-1

ISO/IEC 27001 implementation

ISO/IEC 27005

ISO/IEC 27001:2022

cloud platforms

ISO/IEC 27001 Lead Implementer / Lead Auditor

About Company

Netsach is a Bangalore based company with professionals of great expertise & talent working within itself. We at Netsach endeavor to be the leading global provider of HR/Recruitment, IT Infrastructure, Media & Production, and Marketing Solution & Consulting of this time and in the future to come.