Upload Button Icon Add office photos
Engaged Employer

i

This company page is being actively managed by Quinnox Team. If you also belong to the team, you can get access from here

Quinnox Verified Tick

Compare button icon Compare button icon Compare
3.8

based on 333 Reviews

filter salaries All Filters

26 Quinnox Jobs

Information Security Lead

6-11 years

Mumbai

1 vacancy

Information Security Lead

Quinnox

posted 1hr ago

Job Role Insights

Flexible timing

Job Description

Job duties / Role:

1. Information Security Management

  • Assist CISO in implementation and management of entire ISMS life cycle
  • Responsible for development, Periodic review, control and management of ISMS policies and procedure
  • Monitor the adequacy of operational procedures, policies and process, create and monitor compliance
  • Coordinate the Organizations ISO 27001:2013 recertification and SOC2 attestation process in terms of Planning, Coordination with Business owners and stakeholders and scheduling Audit meetings, Audit execution and Closure.
  • Ensure compliance at an organizational level, achieved through identifying the applicable requirements which in the case of Quinnox are the ISO 27001 standard, Customer Contractual Security obligations and defined internal policies and procedures.
  • Monitor performance of GDPR controls and respond to the quarterly compliance checklist.
  • Ensure GDPR Data Processing Impact assessments are carried out periodically and gaps are addressed
  • Plan and conduct the annual Management Review meeting. Demonstrate the performance of ISMS through the year and seek feedback / advice from the Leadership Council.
  • Review and respond to risk assessment questionnaire by our clients
  • Review MSA Security clauses of the existing clients and prospects
  • Participate in POC of new security tools and implementation

2. Information Security Risk Management

  • Carrying out Organization Wide Information Security Risk Management exercise on an Annual Basis to Quantify the Risks associated with the Information Assets and accordingly devise the Risk Mitigation strategies.
  • Developing and Maintaining Risk Registers of all the Projects/Support Functions.
  • Creating a Risk Summary report for the executive management.

3. Technical Vulnerability Management

  • Monitor and review anti-virus and patch report across all endpoints and ensure that all endpoints are up-to-date with latest AV patches.
  • Ensure SIEM and DLP alerts are monitored and corrective actions taken to address potential threats
  • Ensure monthly scanning of infrastructure is carried out and vulnerabilities are remediated in time
  • Defining the Scope of external VAPT and facilitating the VAPT vendor personnel with the requisite information.
  • Facilitate the external VAPT exercise at org level, reviewing the VAPT findings for verifying the authenticity of the reported observations and ensure timely mitigation.

4. Audit Management:

  • Act as point of contact for all external audits of ITIM to define scope and parties necessary to participate. Act as a repository of audit data to prevent duplication of audited processes
  • Based on known annual audits, develop a schedule for audits which allows for distribution of audits throughout the course of the year
  • Plan, schedule and execute internal ISMS audits twice a year
  • Record the audit findings and track the closure of NC after following up with the concerned departments
  • Summarize the audit findings and associated CAPA to include in steering committee meetings.
  • Act as point contact during external audits and ensure smooth execution through careful planning ahead of time.

5. Change Management; Incident Management; ISMS Document Control:

  • Ensure that all changes to critical infrastructure takes place through appropriate change control
  • Reviewing change records for appropriateness and ensure that all they are filled in with the correct and relevant information by the responsible teams. Approve or reject changes in line with our change control policy
  • Work and Incident Response Coordinator who, in consultation of IT head/CISO will be responsible for timely escalation and reporting of security incidents.
  • Reviewing incident records for appropriateness and ensure that RCA and corrective actions are captured appropriately.
  • Ensure all Incidents and security events are reviewed on an ongoing basis and appropriate corrective measures taken to remediate the issues.
  • Maintaining, tracking and updating Change and Incident records (Record Management).
  • Control of ISMS Documents and Records

6. Information Security Training & Awareness:

  • Ensure dissemination of knowledge on our ISMS policies and procedures through awareness campaigns. Ensure the ISMS training compliance across all locations. Publishing security updates through newsletters on a periodic and ongoing basis.

7. Business Continuity:

  • Perform business impact analysis, risk assessment, mitigation plans / recovery strategies and BCP testing for the companys critical business processes, operations and the technology that supports them.
  • Ensure BCP tests, DR Drills conducted as per schedule
  • Conduct BCP training to the crisis response team and project managers at least once a year
  • Identify single point of failures through risk assessment and propose controls

Competencies/Skills required:

Must have managed Information Security in a medium / large size organization. Should be well versed with all aspects of Information security and risk management.

Could have worked as an information security consultant in any of the consultancy service provider firms.


Qualifications and Education Requirements:

Minimum education – Bachelor of Engineering

Certifications such as CISSP, ISO 27001 (ISMS) Implementer / Lead Auditor, CISA, CISM will be an added advantage.


Additional Notes:

Ideal candidate for this position would be one who has completed an entire lifecycle of Information Security Management System in a medium or large organization.



Thank You,

Rajashri


Employment Type: Full Time, Permanent

Read full job description

Prepare for Information Security Lead roles with real interview advice

People are getting interviews at Quinnox through

(based on 17 Quinnox interviews)
Job Portal
Campus Placement
Referral
58%
18%
6%
18% candidates got the interview through other sources.
High Confidence
?
High Confidence means the data is based on a large number of responses received from the candidates.

What people at Quinnox are saying

Information Security Lead salary at Quinnox

reported by 5 employees with 4-8 years exp.
₹8.5 L/yr - ₹12.5 L/yr
50% less than the average Information Security Lead Salary in India
View more details

What Quinnox employees are saying about work life

based on 333 employees
77%
94%
69%
91%
Flexible timing
Monday to Friday
No travel
Day Shift
View more insights

Quinnox Benefits

Submitted by Company
Hybrid Work Schedule
Employee Engagement Activities
Health and Wellness
Submitted by Employees
Work From Home
Cafeteria
Soft Skill Training
Health Insurance
Job Training
Team Outings +6 more
View more benefits

Compare Quinnox with

TCS

3.7
Compare

Infosys

3.7
Compare

Wipro

3.7
Compare

HCLTech

3.5
Compare

Tech Mahindra

3.6
Compare

LTIMindtree

3.9
Compare

Mphasis

3.4
Compare

Persistent Systems

3.5
Compare

Hexaware Technologies

3.6
Compare

Xoriant

4.2
Compare

Photon Interactive

4.0
Compare

CitiusTech

3.4
Compare

Iris Software

4.1
Compare

HERE Technologies

3.9
Compare

BT Business

4.1
Compare

HTC Global Services

3.6
Compare

iOPEX Technologies

3.6
Compare

Tietoevry

4.3
Compare

Evalueserve

3.3
Compare

Unisys

3.7
Compare

Similar Jobs for you

GRC Analyst at SMC Global Securities

Delhi/Ncr

2-7 Yrs

₹ 5-12 LPA

Security at Dharampal Satyapal Group (DS Group)

Noida

3-6 Yrs

₹ 7-15 LPA

Information Security Manager at Transformative Learning Solutions

5-6 Yrs

₹ 15-18 LPA

Information Security Analyst at Increff

Bangalore / Bengaluru

3-5 Yrs

₹ 10-15 LPA

Information Security Manager at Serving Skill

Mumbai

4-10 Yrs

₹ 13-15 LPA

Assistant Vice President at BOB Financial Solutions Ltd

10-16 Yrs

₹ 20-40 LPA

Information Security Lead at Amdocs Development Center India Pvt. Ltd.

Pune

8-14 Yrs

₹ 12-18 LPA

Security Analyst at Ericsson India Global Services Pvt. Ltd.

Noida

10-12 Yrs

₹ 12-14 LPA

Information Security Lead at Naukari Wale

Bangalore / Bengaluru

4-7 Yrs

₹ 12-25 LPA

Governance Analyst at Vichara Technologies

Pune, Delhi/Ncr + 1

7-12 Yrs

₹ 22.5-35 LPA

Quinnox Mumbai Office Location

View all
Andheri Office
Unit 170, SDF VI, Santacruz Electronic Export Processing Zone, Andheri East, Mumbai, Maharashtra 400096, India Andheri
View on map

Information Security Lead

6-11 Yrs

Mumbai

16hr ago·via naukri.com

.Net and Python Developer

6-9 Yrs

₹ 15 - 20L/yr

Mumbai, Bangalore / Bengaluru

1d ago·via naukri.com

Manual Test Engineer

7-10 Yrs

Bangalore / Bengaluru, Mumbai

2d ago·via naukri.com

Calypso Developer

4-9 Yrs

Bangalore / Bengaluru, Mumbai

2d ago·via naukri.com

Angular & Python Developer

3-8 Yrs

Bangalore / Bengaluru

4d ago·via naukri.com

Sr. AI Engineer

3-8 Yrs

Bangalore / Bengaluru

4d ago·via naukri.com

SAP PP - (immediate Joiners)

8-13 Yrs

₹ 15 - 25L/yr

Mumbai, Bangalore / Bengaluru

4d ago·via naukri.com

Data Engineer

3-8 Yrs

Bangalore / Bengaluru

4d ago·via naukri.com

.Net Core Developer

7-12 Yrs

Mumbai, Bangalore / Bengaluru

6d ago·via naukri.com

Python Backend Developer (AWS Serverless)

7-12 Yrs

Mumbai, Bangalore / Bengaluru

6d ago·via naukri.com
write
Share an Interview