{"id":1521595,"url":"https://alion.io/job/setindia-information-security-manager","title":"Information Security Manager","company":{"id":2202874,"name":"Setindia","domain":"setindia.com","url":"https://alion.io/company/setindia","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Mumbai, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":17000,"max_usd":37000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":12},"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Burp Suite","optional":false},{"name":"DLP","optional":false},{"name":"DNS","optional":false},{"name":"IAM","optional":false},{"name":"Least Privilege","optional":false},{"name":"Microsoft Defender for Cloud","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"Nessus","optional":false},{"name":"OneDrive","optional":false},{"name":"Qualys Cloud Platform","optional":false},{"name":"SharePoint","optional":false},{"name":"SIEM","optional":false},{"name":"VPN","optional":false},{"name":"Zero Trust","optional":false}],"status":"live","first_seen_at":"2026-09-30T11:11:55Z","employer_posted_date":null,"last_verified_at":"2026-09-30T11:11:55Z","board_verified":false,"closed_at":null,"days_open":4,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":4},"description":"Purpose :\n\nLead and continuously improve SPNI's information security program across governance, risk, compliance, architecture, cloud, identity, vulnerability management and incident response.\n\nAlign business needs with Sony Global policies, ISO/IEC 27001:2022, SOX/ITGC and applicable legal, regulatory and contractual requirements, including India's DPDP Act readiness, while translating security requirements into practical controls across on-premises, AWS, Azure, Microsoft 365 and hybrid environments.\n\nKey Responsibilities :\n\nGovernance, ISMS, Compliance & Assurance :\n\n- Own and continually improve the ISO/IEC 27001:2022-aligned ISMS; maintain scope, risk methodology, Statement of Applicability, treatment plans and evidence; manage certification/surveillance audits, management reviews and governance forums.\n\n- Develop and periodically review security policies, standards, procedures and frameworks; establish control ownership, review cycles, exception handling, escalation, audit readiness and remediation assurance for Sony Global requirements, SOX/ITGC and applicable obligations.\n\n- Define executive KPIs/KRAs and dashboards covering material risks, control gaps, compliance status, remediation priorities, critical exposure, aging, recurrence, vendor risk and operational performance.\n\nEnterprise & Third-Party Risk Management :\n\n- Lead periodic and change-triggered risk assessments across business processes, technology, projects and suppliers; maintain a consolidated register with owners, ratings, actions, target dates, residual risk and formal acceptance; escalate overdue or material exposures.\n\n- Assess emerging threats, technology and regulatory developments; agree proportionate mitigation with business and technology stakeholders and communicate significant weaknesses to leadership.\n\n- Own the third-party risk framework: classify vendors by criticality, data, privilege and dependency; perform security/privacy due diligence; evaluate responses and assurance reports; track gaps and residual risk; periodically reassess and monitor critical/high-risk vendors.\n\n- Partner with Procurement and Legal to embed security, confidentiality, personal-data protection, incident reporting, subcontracting and exit clauses, and report unresolved material vendor risk.\n\nSecurity Architecture, Network, Cloud & Platform Security :\n\n- Review on-premises, cloud and hybrid designs, including firewalls, VPN, proxy/SWG, IDS/IPS, DNS, TLS, load balancers, WAF, DDoS controls, AWS Direct Connect, Azure ExpressRoute and site-to-site VPN; apply Zero Trust and least privilege, validate implementation, and document exceptions/residual risk.\n\n- Oversee hardening procedures for servers, databases, workstations, laptops and mobile devices; assess backup protection, recovery access and resilience controls.\n\n- Assess AWS accounts and Azure subscriptions across IAM/Entra ID, privileged/service/workload identities, networking, compute, storage, management plane, KMS/Secrets Manager/Key Vault, CloudTrail, GuardDuty, Security Hub, Azure Activity Logs and Defender for Cloud; prioritize posture findings and support secure baselines, IaC reviews and automated checks.\n\n- Assess Microsoft 365, including Exchange Online, SharePoint, OneDrive and Teams; review MFA, Conditional Access, PIM, authentication methods, legacy authentication, guest/external access, application consent, enterprise apps and service principals.\n\n- Review phishing, malicious attachment, impersonation and BEC protection; evaluate Defender for Office 365/XDR; validate audit logging and centralized monitoring; review sensitivity labels, DLP and external sharing with data owners/compliance teams.\n\nVulnerability, Monitoring & Incident Response :\n\n- Continuously improve vulnerability platforms, processes and coverage across servers, endpoints, network devices, cloud workloads, web applications and internet-facing assets; perform authenticated scans, configuration reviews and authorized validation using Qualys, Nessus and Burp Suite.\n\n- Validate findings and false positives; prioritize by exploitability, criticality, exposure and business impact; agree SLAs, compensating controls and risk acceptance; retest fixes, preserve closure evidence and coordinate with Global Vulnerability Management/regional teams.\n\n- Monitor and investigate SIEM, endpoint, network, cloud, identity and Microsoft 365 alerts; correlate telemetry, distinguish false positives/configuration issues/incidents, determine scope and attack paths, and execute authorized containment and remediation.\n\n- Support recovery, evidence preservation, root-cause analysis and accurate timelines; improve detections, queries, playbooks, alert tuning and log onboarding; conduct threat hunting, simulations/tabletops, document lessons and track corrective actions.\n\n- Escalate personal-data or regulatory matters to Legal, Privacy and GRC.\n\n- Investigate identity compromise, suspicious sign-ins, malicious inbox rules, risky OAuth apps and unauthorized sharing.\n\nAI Security, Awareness, Reporting & Collaboration :\n\n- Assess AI-enabled services for sensitive-data exposure, permissions, third-party processing, insecure connectivity, prompt injection, unsafe tool access and unintended disclosure; review approved use, access restrictions, logging and protection settings with Architecture, Legal, Privacy and GRC.\n\n- Run a risk-based security/privacy awareness program using LMS training, phishing simulations and targeted education; measure completion, reporting behavior and repeat susceptibility, and promote good practice among employees, vendors and stakeholders.\n\n- Maintain architecture reviews, assessment reports, incident records, technical procedures and remediation evidence; support audits with technical evidence and control validation; communicate clearly to technical and non-technical audiences.\n\n- Collaborate with Global Information Security Operations, Global Vulnerability Management, Infrastructure, Cloud, Network, Applications and local teams; automate assessments, alert enrichment and reporting through scripting/APIs; stay current on threats, attack techniques and security technologies.\n\nExperience, Qualifications & Success Measures :\n\n- Minimum 8+ years of cybersecurity experience, including enterprise GRC ownership and at least 5 years of substantive vulnerability-management and incident-response experience.\n\n- Hands-on ownership of an ISO/IEC 27001-aligned ISMS, audits, security risk/control assurance, policy governance, audit remediation, third-party risk and executive reporting.\n\n- Hands-on security across AWS, Azure and Microsoft 365, with depth in at least one cloud; cloud IAM/Entra ID, PIM, MFA and Conditional Access; infrastructure, application, identity and data-protection controls.\nSkills\nSecurity, Information Security, GRC, Security Operations Center, ISMS, TPRM, Cloud Security, Vulnerability Management, Security Risk Management","description_format":"text","description_chars":6938,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":[],"lifecycle":[{"event":"open","at":"2026-09-30T12:00:00Z"}],"visa":[],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":3,"expected_fill_days":24,"reasons":["seen:3","velocity","win:early"],"computed_at":"2026-10-04T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/setindia-information-security-manager","json_url":"https://alion.io/job/setindia-information-security-manager.json","meta":{"generated_at":"2026-10-05T01:56:45Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2546,"day_limit":5000,"remaining_today":2454,"minute_limit":60,"resets_at":"2026-10-06T00:00:00Z"}}}