'
: - ( - )
Experience: 5+ yrs
Location: Remote (India)
Job Type: Full-time
We are looking for an experienced Information Security & Compliance Specialist to strengthen security operations, incident response, information governance, risk management, and compliance initiatives. The role is suited for a security professional with strong hands-on experience in incident response, ISO 27001, PDPL, information governance, privileged access management, and security operations.
You will play an important role in maintaining the organisation's security posture, responding to security incidents, supporting regulatory and audit requirements, managing information risks, and ensuring security governance processes are effectively implemented.
Requirements
Key Responsibilities
- Provide first response and operational support for information security incidents.
- Execute defined incident containment, response, escalation, and recovery activities.
- Develop, maintain, and improve security incident response runbooks and procedures.
- Coordinate with MDR/SOC teams to investigate, contain, and resolve security incidents.
- Support incident investigation, documentation, root-cause analysis, and post-incident reviews.
- Monitor and track security incidents, actions, escalations, and remediation activities.
- Support ISO 27001 information security management and compliance activities.
- Contribute to PDPL compliance initiatives, security controls, assessments, and documentation.
- Support information classification, handling requirements, records management, and information governance processes.
- Coordinate and provide evidence for internal and external security audits.
- Maintain and update security risk registers and track mitigation and remediation activities.
- Prepare and maintain monthly security metrics, dashboards, and management reports.
- Support periodic security and governance reviews, including Y1.2 reviews and related assessment activities.
- Administer and support BeyondTrust Privileged Access Management (PAM).
- Review privileged access, access controls, approvals, and governance requirements.
- Coordinate with governance, compliance, IT, security, and business stakeholders on security initiatives.
- Support security control assessments, compliance reviews, and remediation tracking.
- Maintain accurate security policies, procedures, records, evidence, and governance documentation.
- Identify opportunities to strengthen security operations, incident readiness, information governance, and compliance processes.
What Makes You a Great Fit
- 5+ years of professional experience in IT security, information security, cybersecurity, security governance, or compliance.
- 3+ years of hands-on experience in incident response and security operations.
- 2+ years of experience with ISO 27001 and PDPL compliance or related information-security regulatory frameworks.
- 2+ years of experience in information governance, including information classification and records management.
- Strong understanding of security incident response processes, containment, escalation, investigation, and recovery.
- Experience developing and maintaining incident response runbooks and operational procedures.
- Experience coordinating with SOC, MDR, or managed security service providers.
- Hands-on experience with BeyondTrust PAM administration.
- Strong understanding of privileged access management, access governance, and security controls.
- Experience maintaining security risk registers and supporting risk assessments and remediation.
- Experience preparing security metrics, management reports, audit evidence, and compliance documentation.
- Strong understanding of ISO 27001, information security governance, risk management, and audit processes.
- Practical knowledge of PDPL requirements and information governance principles.
- Strong coordination skills with the ability to work across security, governance, compliance, IT, and business teams.
- Excellent written and verbal communication skills.
- Strong analytical, documentation, and problem-solving abilities.
- Ability to work independently in a remote environment and manage multiple security and compliance priorities.

