Information Security Manager at Simpplr developing, implementing, and managing security policies and procedures. Overseeing security systems and leading incident response while ensuring compliance with industry standards.
Responsibilities
Develop, implement, and maintain security policies, procedures, and guidelines to protect information assets and to ensure compliance.
Assess system vulnerabilities, identify security risks, and implement risk mitigation strategies. Ensure that the risk register is kept up to date.
Ensure that all IT systems are up to date with required patches and configuration and required controls are in place to manage and monitor corporate devices.
Manage and respond to security incidents, conduct investigations and coordinate recovery efforts.
Ensure the organization adheres to industry standards and relevant regulations, and conduct regular security audits and security committee meetings.
Closely collaborate with internal and external parties to manage internal and external audits towards successful ISO 27001, ISO 27701 and SOC 2 certifications.
Data Privacy Framework: Ensure compliance with Data Privacy Framework.
Develop and deliver security awareness training to educate employees on best security practices and policies.
Manage and support vendor onboarding process including vendor evaluation and security assessment.
Requirements
10+ years of experience in IT with a focus on information security.
Prior experience with managing and orchestrating security audits and certifications (ISO 27001, ISO 27701, SOC 2 at a minimum).
Prior experience with policies and procedures management.
Knowledge of controls related to the use, processing, storage, and transmission of data.
Proficiency in identifying, assessing, and mitigating security risks and maintaining the risk register.
Leadership & Management: Ability to lead and manage IT and information security programs.
Effectively communicate security risks, policies, and procedures to stakeholders and employees.
A bachelor's degree in cybersecurity, computer science, or a related field.
Cloud Security Engineer supporting and securing client environments across AWS and hybrid infrastructures. Collaborating with Cloud Operations to monitor, investigate, and remediate security events.
Account Cybersecurity Lead providing cybersecurity governance and oversight at Capgemini. Leading client relationships, security management systems, and risk compliance oversight.
Cybersecurity Risk Coordinator at Globo ensuring operational security across digital content. Analyzing risks and developing strategies to enhance business resilience.
Senior SAP Security Specialist managing SAP Security responsibilities and projects. Collaborating on security tools and conducting workshops in Hamburg.
Sales Account Manager for Cyber Security and Awareness role at HvS - Consulting GmbH. Providing holistic consulting on Cyber Security services and managing client relationships.
Security Engineer at PRC - Saltillo safeguarding IT infrastructure from cyber threats. Collaborating with IT teams to design and maintain security controls in a hybrid work environment.
Information Security Manager leading cyber security initiatives at NVISO, enhancing clients’ security posture and managing a team of consultants in Germany.
Cybersecurity Assessment Expert at IT - Strat managing A&A of information systems for U.S. federal clients. Ensuring compliance with DOD cybersecurity policies and standards in complex IT environments.
Senior Security Engineer responsible for deploying and maintaining endpoint security solutions. Collaborating across teams to enhance security posture and supporting incident response activities.