Information Security Manager
Job in
442606, Mohali, Maharashtra, India
Listed on 2026-09-24
Listing for:
AVASO Technology Solutions
Full Time
position Listed on 2026-09-24
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Job Description & How to Apply Below
Job Title - Manager Information Security
Location - Mohali
Role Summary / Job Purpose
The Info Sec Lead is the security conscience of the Enterprise Technology & Enablement function. This is a player-coach role: the lead owns the security strategy and executes it. AVASO is building its security posture and this person sets the tone. The lead establishes the foundation, including compliance programmes, access controls, incident response, and security awareness across the organisation.
The Info Sec Lead owns AVASO's security posture end to end. This means being hands-on across vulnerability management, access controls, compliance programmes, and incident response while simultaneously building the policies, standards, and frameworks that govern the function. The lead works closely with the Head of ET&E and across all technology towers to embed security into how the organisation operates, not as a gatekeeper, but as a partner.
Technical depth matters, and so does the ability to communicate risk clearly to leadership and to grow into a strategic security leader as the organisation matures.
Key Responsibilities
Security Strategy & Posture
Own and communicate AVASO's security posture, identifying gaps and building a prioritised roadmap to close them.
Define and maintain security policies, standards, and controls across the enterprise.
Drive security architecture decisions in alignment with infrastructure and application delivery.
Compliance Programmes
Lead ISO 27001 and SOC2 compliance programmes, from gap assessment through evidence collection and audit coordination.
Maintain the risk register and track control gap remediation.
Ensure AVASO is ready to respond to client security questionnaires in RFPs without delay.
Hands-On Security Operations
Manage or oversee SIEM monitoring, vulnerability scanning, and remediation tracking.
Own identity and access management: policies, access reviews, and joiner/mover/leaver processes.
Lead incident response when security events occur, including escalation and post-incident review.
Security Awareness
Design and deliver a security awareness programme across the organisation.
Build a security-conscious culture without creating friction for day-to-day operations.
Additional Areas of Focus
Contribute to vendor security assessments for key technology suppliers.
Support client-facing security audits and due diligence processes.
Provide security input into AI and data initiatives as they develop.
Required Skills
Technical Skills
Security architecture and the design of policies, standards, and controls across an enterprise.
ISO 27001 and SOC2 compliance programme delivery, including gap assessment, evidence collection, and audit coordination.
SIEM monitoring, vulnerability management, and remediation tracking.
Identity and access management, including access reviews and joiner/mover/leaver processes.
Incident response leadership: containment, escalation, and post-incident review.
Risk management, including risk register maintenance and control gap remediation.
Familiarity with GDPR and NIS2 requirements.
Functional Knowledge
Breadth across multiple security domains, comfortable operating end to end without a large team behind the role.
Clear communicator who can translate technical risk into business language for leadership and non-technical stakeholders.
Self-directed and structured, able to build programmes with limited support.
Collaborative by nature: security that works with the business, not against it.
Growth mindset: motivated to develop strategic security leadership skills as the organisation scales.
Comfortable in a player-coach posture, balancing hands-on execution with programme ownership.
Tools / Systems / Technical Knowledge
SIEM platforms (e.g. Microsoft Sentinel, Splunk, or equivalent).
Vulnerability management tooling (e.g. Tenable, Qualys, Rapid7, or equivalent).
Identity and access management (IAM) platforms, including Microsoft Entra equivalents.
Endpoint detection and response (EDR) and email security tooling.
GRC tooling for ISO 27001 and SOC2 evidence and risk register management.
Microsoft 365 security stack (Defender, Purview) and cloud security tooling for Azure and equivalents.
Frameworks: ISO 27001, SOC2, NIST CSF, GDPR, NIS
2.
Decision-Making Authority
Final authority on AVASO's security policies, standards, and controls across the enterprise.
Owns the security roadmap, including prioritisation of gap remediation and investment recommendations.
Authority over incident response decisions during active security…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×