Information Security Manager (Dy. Manager)
Mumbai Area, India
As an Information Security Manager, shouldered responsibilities of Chief Information Security Officer (CISO) towards Information Security Governance, for the organization.Strategic Planning : • Spearheaded development and deployment of comprehensive security strategy explicitly aligned with Business and IT objectives; applicable legal, regulatory and contractual requirement by establishing and enforcing framework for,- Information Security Risk Management- Information Security Performance Monitoring- Information Security Incident Management- Continual Improvement- Business Continuity and Disaster RecoveryInformation Security Management :• Lead and coordinated development of organization specific information security policies, procedures, guideline and processes in consultation with various stake holders and in accordance with ISO/IEC 27001, QMS Standard, J-Sox, applicable legal, regulatory and contractual requirement.• Monitored compliance with information security policies and procedures, Monitoring information security incidents and breaches; Advising the organization with current information about information security technologies & related regulatory issues.• Ensured remedial action to reduce / diminish the impact of information security incidents and breaches. Issued alerts and advisories with respect to new vulnerabilities / threats to all concerned.Audit: Played pivotal role in multiple certification audit cycles of ISO 27001. Managed Information Security Audit programs. Prepared information security audit reports providing recommendations for improving information security.Management Communication :Appraised the management about performance and effectiveness of the established Information Security System with periodic updates on changes in internal and external environment including technology, process and regulatory requirement; changes due to dynamic risk scenarios.