{"id":1249739,"url":"https://alion.io/job/employee-forums-lead-information-security","title":"Lead - Information Security","company":{"id":3800192,"name":"Employee Forums","domain":"employeeforums.com","url":"https://alion.io/company/employee-forums","size_band":null,"is_staffing_agency":true,"employer_type":"agency","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":null},"role":"Security","role_family":"Security","seniority":"lead","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Mumbai, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":20000,"max_usd":50000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":10},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"ISO 27001","optional":false},{"name":"PCI DSS","optional":false}],"status":"live","first_seen_at":"2026-08-13T11:24:44Z","employer_posted_date":null,"last_verified_at":"2026-08-13T11:24:44Z","board_verified":false,"closed_at":null,"days_open":58,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":58},"description":"Role Summary:\n\nWe are seeking an experienced Information Security professional to support the Governance, Risk, Compliance (GRC), Vulnerability Management, and Security Assurance functions at BillDesk. The ideal candidate will be responsible for developing robust security policies and procedures, conducting risk assessments, managing end-to-end security audits, tracking vulnerabilities, performing infrastructure security gap assessments, and ensuring strict compliance with ISO 27001, PCI DSS, RBI guidelines, and various customer security requirements.\n\nKey Responsibilities:\n\n1. Governance & Compliance:\n\n- Develop, implement, and maintain Information Security Policies, Standards, Procedures, and Guidelines.\n\n- Support, optimize, and enhance the overall Information Security Management System (ISMS).\n\n- Ensure absolute compliance with ISO 27001, PCI DSS, RBI regulations, and internal security requirements.\n\n- Act as the primary coordinator for internal, external, customer, banking partner, and regulatory audits.\n\n2. Risk Management & Security Assessments:\n\n- Conduct comprehensive Information Security Risk Assessments for applications, core infrastructure, cloud, and third-party environments.\n\n- Perform detailed infrastructure and security control gap assessments against regulatory and industry benchmarks.\n\n- Own and maintain the organization's risk registers while rigorously tracking remediation activities.\n\n3. Vulnerability Management:\n\n- Review Vulnerability Assessment and Penetration Testing (VAPT) reports and oversee systematic vulnerability remediation activities.\n\n- Track the closure of vulnerabilities identified through scans, penetration tests, audits, and routine assessments.\n\n- Monitor patch management compliance and ensure strict adherence to security remediation timelines.\n\n- Prepare actionable vulnerability dashboards and high-level management reports.\n\n4. Third-Party Security & Audit Management:\n\n- Conduct rigorous vendor and third-party security risk assessments.\n\n- Review third-party security certifications, audit reports, and compliance evidence.\n\n- Manage audit observations and drive the timely, verified closure of findings.\n\n5. Reporting & Governance:\n\n- Prepare security governance dashboards, audit reports, key risk metrics, and compliance status reports.\n\n- Present the current security posture and compliance updates clearly to management and key stakeholders.\n\nRequired Skills & Qualifications:\n\n- Experience: 5-10 years of dedicated experience in Information Security Governance, GRC, IT Audit, or Security Assurance.\n\n- Domain Knowledge: Strong, working knowledge of ISO 27001, PCI DSS, RBI Cyber Security Guidelines, and Digital Payment Security Controls.\n\n- Audit Experience: Proven track record of independently handling bank audits, customer audits, and regulatory assessments.\n\n- Technical Understanding: Good understanding of vulnerability management life cycles, VAPT remediation steps, and core infrastructure security controls.\n\n- Soft Skills: Excellent documentation, communication, and stakeholder management skills.\n\nSkills\nCyber Security, Information Security, IT Security, IT Governance, IT Risk Management, IT Compliance","description_format":"text","description_chars":3197,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Information Security"],"lifecycle":[{"event":"open","at":"2026-09-25T18:00:00Z"}],"visa":[],"liveness":{"score":5,"band":"cold","label":"Long shot","p_open":0.4,"p_active":0.33,"p_room":0.35,"age_days":57,"expected_fill_days":23,"reasons":["seen:57","agency","velocity","win:tail"],"computed_at":"2026-10-10T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/employee-forums-lead-information-security","json_url":"https://alion.io/job/employee-forums-lead-information-security.json","meta":{"generated_at":"2026-10-11T01:12:34Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1760,"day_limit":5000,"remaining_today":3240,"minute_limit":60,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":3800192},"rest":"https://alion.io/mcp/rest/get_company?id=3800192"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Femployee-forums-lead-information-security"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Femployee-forums-lead-information-security"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Femployee-forums-lead-information-security"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/employee-forums-lead-information-security\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Femployee-forums-lead-information-security"}]}