Compliance Manager - Information Security

  • Bengaluru
  • Leadsquared

Location: Bangalore


Reports to: Director - IT


Position Overview: As an Information Security Compliance Manager at LeadSquared, you will play a critical role in overseeing and maintaining our information security compliance program. The ideal candidate will have at least 8 years of hands-on experience in managing compliance with ISO 27001, SOC 2, and HIPAA standards. You will be responsible for implementing, monitoring, and continuously improving our information security policies, procedures, and controls to safeguard our data assets, customer information, and meet regulatory requirements.


Key Responsibilities:

1. Compliance Management: Develop and maintain a comprehensive understanding of ISO 27001, SOC 2, and HIPAA requirements. Lead efforts to ensure the organization's compliance with these standards and regulations. Conduct regular audits and assessments to identify compliance gaps and areas for improvement. Create compliance dashboards and report the compliance health to Top Management on a monthly basis Good understanding of regulatory requirements like GDPR, CCPA, DPDP etc.


2. Policy and Procedure Development: Create, update, and maintain information security policies, procedures, and guidelines to align with best practices and regulatory requirements. Communicate and enforce policies and procedures across the organization.


3. Risk Assessment and Management: Perform risk assessments to identify potential security risks and vulnerabilities. Develop and implement risk mitigation strategies and action plans. Have a good understanding of OWASP top 10 cloud security, web application security, and DevOps security risks Have a good understanding on SDLC workflow and its infosec requirements from and ISO27001 standard perspective


4. Training and Awareness: Provide training and awareness programs to educate employees about information security best practices and compliance requirements.


5. Incident Response and Management: Develop and maintain an incident response plan to address security incidents and breaches promptly. Coordinate and lead incident response efforts when necessary.


6. Vendor and Third-Party Risk Management: Evaluate the security practices of third-party vendors and partners to ensure they meet compliance requirements. Manage vendor risk assessments and due diligence processes.


7. Reporting and Documentation: Prepare and submit compliance reports to regulatory authorities and internal stakeholders as applicable Maintain comprehensive documentation of security controls and compliance activities.


8. Continuous Improvement: Stay up-to-date with industry trends, emerging threats, and regulatory changes. Drive continuous improvement initiatives to enhance the security posture and compliance framework of the organization.


9. Handling Customer’s InfoSec queries: Respond to customer RFIs, assessments and infosec related queries Streamline the RFI response process and response ETA Engage in client meetings and discussions related to Information Security at LeadSquared and provide the relevant inputs and solutions as applicable


10. Compliance Automation: Experience in working with GRC tools like Archer, Audit Board, Hyperproof etc to automate and streamline audit activities, risk assessment, employee awareness and vendor management


Qualifications:

  • Bachelor's degree in information security, Computer Science, or a related field.
  • A master's degree in cyber security is a plus.
  • At least 8 years of relevant experience in information security compliance management.
  • Experience in auditing and risk assessment of SDLC and DevOps functions is a must Strong expertise in ISO 27001 , SOC 2 , and HIPAA standards.
  • Professional certifications such as CISSP, CISM, CISA, or equivalent are highly desirable.
  • Must have worked on Risk assessment and audits of AWS infrastructure for a product/solution
  • Excellent communication and leadership skills.
  • Must have conducted at least 1 SoC2 Type1 and Type 2 internal audits and represented the organization in SoC2, HIPAA external audits.
  • Experience in responding to customer RFIs on infosec is a must Strong analytical and problem-solving abilities.
  • Ability to work collaboratively with cross-functional teams.