Manager - Information Security
Mohali
|
1. Job Title |
|
|
2.Department |
|
|
3.Location |
|
|
4.Work Model |
|
|
5.Reports to |
|
|
6.Direct reports |
|
|
7. Level |
|
8. Role Summary / Job Purpose
The InfoSec Lead is the security conscience of the Enterprise Technology & Enablement function. This is a player-coach role: the lead owns the security strategy and executes it. AVASO is building its security posture and this person sets the tone. The lead establishes the foundation, including compliance programmes, access controls, incident response, and security awareness across the organisation.
The InfoSec Lead owns AVASO's security posture end to end. This means being hands-on across vulnerability management, access controls, compliance programmes, and incident response while simultaneously building the policies, standards, and frameworks that govern the function. The lead works closely with the Head of ET&E and across all technology towers to embed security into how the organisation operates, not as a gatekeeper, but as a partner. Technical depth matters, and so does the ability to communicate risk clearly to leadership and to grow into a strategic security leader as the organisation matures.
9. Key Responsibilities
Security Strategy & Posture
- Own and communicate AVASO's security posture, identifying gaps and building a prioritised roadmap to close them.
- Define and maintain security policies, standards, and controls across the enterprise.
- Drive security architecture decisions in alignment with infrastructure and application delivery.
Compliance Programmes
- Lead ISO 27001 and SOC2 compliance programmes, from gap assessment through evidence collection and audit coordination.
- Maintain the risk register and track control gap remediation.
- Ensure AVASO is ready to respond to client security questionnaires in RFPs without delay.
Hands-On Security Operations
- Manage or oversee SIEM monitoring, vulnerability scanning, and remediation tracking.
- Own identity and access management: policies, access reviews, and joiner/mover/leaver processes.
- Lead incident response when security events occur, including escalation and post-incident review.
Security Awareness
- Design and deliver a security awareness programme across the organisation.
- Build a security-conscious culture without creating friction for day-to-day operations.
Additional Areas of Focus
- Contribute to vendor security assessments for key technology suppliers.
- Support client-facing security audits and due diligence processes.
- Provide security input into AI and data initiatives as they develop.
10. Required Skills
Technical Skills
- Security architecture and the design of policies, standards, and controls across an enterprise.
- ISO 27001 and SOC2 compliance programme delivery, including gap assessment, evidence collection, and audit coordination.
- SIEM monitoring, vulnerability management, and remediation tracking.
- Identity and access management, including access reviews and joiner/mover/leaver processes.
- Incident response leadership: containment, escalation, and post-incident review.
- Risk management, including risk register maintenance and control gap remediation.
- Familiarity with GDPR and NIS2 requirements.
Functional Knowledge
- Breadth across multiple security domains, comfortable operating end to end without a large team behind the role.
- Clear communicator who can translate technical risk into business language for leadership and non-technical stakeholders.
- Self-directed and structured, able to build programmes with limited support.
- Collaborative by nature: security that works with the business, not against it.
- Growth mindset: motivated to develop strategic security leadership skills as the organisation scales.
- Comfortable in a player-coach posture, balancing hands-on execution with programme ownership.
11. Tools / Systems / Technical Knowledge
- SIEM platforms (e.g. Microsoft Sentinel, Splunk, or equivalent).
- Vulnerability management tooling (e.g. Tenable, Qualys, Rapid7, or equivalent).
- Identity and access management (IAM) platforms, including Microsoft Entra ID and equivalents.
- Endpoint detection and response (EDR) and email security tooling.
- GRC tooling for ISO 27001 and SOC2 evidence and risk register management.
- Microsoft 365 security stack (Defender, Purview) and cloud security tooling for Azure and equivalents.
- Frameworks: ISO 27001, SOC2, NIST CSF, GDPR, NIS2.
12. Decision-Making Authority
- Final authority on AVASO's security policies, standards, and controls across the enterprise.
- Owns the security roadmap, including prioritisation of gap remediation and investment recommendations.
- Authority over incident response decisions during active security events, including escalation paths and containment actions.
- Owns ISO 27001 and SOC2 compliance posture, including audit readiness and evidence quality.
- Decision rights on access management policies, access reviews, and exception handling.
- Provides binding security input on vendor selection, integrations, and AI/data initiatives where security risk is material.
- Escalates to the Head of ET&E only where decisions exceed risk appetite or require executive arbitration.
13. Problem-Solving Complexity
- Complex and high-ambiguity. The security function is at an early stage and the role builds it from the foundation up.
- Player-coach problem-solving: balancing hands-on operational issues (alerts, vulnerabilities, incidents) with programme-level work (policy, compliance, roadmap).
- Cross-tower complexity: resolving security issues that span Infrastructure, App Delivery & AI, and data platforms.
- Continuous trade-offs between security rigour and business agility, embedding controls without creating friction.
- Real-time decision-making under pressure during incident response, with limited prior playbooks in place.
14. Stakeholder Management / Influence
- Reports to and advises the Head of ET&E on security posture, risk, and compliance status.
- Peers: tower leads across Infrastructure, App Delivery & AI, and Data & Information Governance, plus business platform owners.
- Cross-functional influence: HR for joiner/mover/leaver processes; Legal and Compliance for GDPR, NIS2, and contractual security obligations; Procurement for vendor security assessments.
- External stakeholders: auditors for ISO 27001 and SOC2, clients for security questionnaires and due diligence, and key technology vendors.
- Client-facing where required, supporting client security audits, due diligence, and RFP security questionnaires.
- Influence at peer and leadership level, translating technical risk into business language for the executive audience.
15. Education & Certification Requirements
Minimum Mandatory Qualifications
- Bachelor's degree in Information Security, Computer Science, or a related field; or equivalent practical experience.
Preferred Qualifications / Certifications
- CISSP, CISM, or equivalent, or demonstrable progress toward certification.
- ISO 27001 Lead Implementer or Lead Auditor.
- Familiarity with GDPR and NIS2 requirements.
Nice to Have
- Experience in a global services or managed services environment.
- Prior experience building a security function from an early stage.
16. Experience Requirements
- 10-12 years of experience in information security, with a track record of both hands-on execution and programme ownership.
- Demonstrated experience running or contributing to ISO 27001 or SOC2 compliance programmes.
- Hands-on experience with SIEM platforms, vulnerability management tools, and IAM solutions.
- Experience communicating security risk to non-technical stakeholders, including leadership and clients.
- Exposure to global or managed services environments is a strong advantage.