Information Security Manager
About this role
Job Title: Cybersecurity Manager
Location: Bengaluru / Hybrid
Department: Information Security
Role Overview
We are seeking an experienced Cybersecurity Manager to lead and mature enterprise security programs across governance, cyber risk management, compliance, cloud security, AI security governance, and certification initiatives.
This role will be responsible for cyber risk management, IT audits, vulnerability governance, certification ownership, and enterprise security programs across key standards including SOC 2 Type II, ISO 27001, PCI-DSS, and HIPAA.
The role will also lead AI risk management and Responsible AI initiatives to ensure secure adoption of emerging technologies.
Key Responsibilities
- Security Strategy & Governance
- Define and execute enterprise cybersecurity strategy aligned to business objectives and regulatory requirementsÂ
- Establish security policies, standards, and governance frameworksÂ
- Drive adoption of security frameworks including NIST CSF, ISO 27001, and CIS ControlsÂ
- Govern security operations from risk and governance perspectiveÂ
- Review security incidents, operational risks, trends, and management reportingÂ
- Support incident readiness and post-incident governance activitiesÂ
- Cyber Risk Management
- Lead enterprise cyber risk management programs including risk identification, assessment, treatment, and reportingÂ
- Maintain risk registers and executive reportingÂ
- Integrate cyber risks across cloud, applications, AI systems, infrastructure, and third partiesÂ
- IT Audits & Compliance Ownership
Own enterprise certification and audit programs including:
- SOC 2 Type IIÂ
- ISO 27001 / ISO 27701Â
- PCI-DSSÂ
- HIPAAÂ
Responsibilities include: Responsibilities include IT audits, certification readiness, evidence management, remediation tracking, and client assurance support.
- Vulnerability Governance
- Govern enterprise vulnerability management programsÂ
- Oversee VAPT activities and remediation trackingÂ
- Drive risk-based prioritization and exposure reduction initiativesÂ
- AI Risk Management & Responsible AI
- Define AI security and AI risk management frameworksÂ
- Identify risks related to AI systems including data leakage, model manipulation, privacy, and bias risksÂ
- Drive Responsible AI governance and policy implementationÂ
- Support secure AI lifecycle initiativesÂ
- Security Architecture & Engineering Governance
- Collaborate with IT and engineering teams on secure architecture initiativesÂ
- Promote Zero Trust, identity-first security, and secure SDLC practicesÂ
- Vendor Risk Management & Security Awareness
- Conduct vendor risk assessments and third-party reviewsÂ
- Support supplier security governance and contractual security requirementsÂ
- Lead enterprise awareness programs and phishing initiativesÂ
- Promote organization-wide security culture initiativesÂ
Required Qualifications
- Bachelor’s degree in Cybersecurity / IT / Engineering or related fieldsÂ
- 8–12+ years cybersecurity experienceÂ
- 3–5 years in leadership rolesÂ
- Experience in cyber risk, audits, certifications, cloud security, and governance programsÂ
- Experience supporting client assurance and regulatory initiativesÂ
Preferred Certifications
CISSP | CISM | CISA | CRISC | CCSP | ISO 27001 Lead Implementer / Lead Auditor | SC-100 | AZ-500
Key Skills
- Cyber Risk ManagementÂ
- IT Audit & Compliance (SOC2, ISO, PCI-DSS, HIPAA)Â
- Vulnerability Governance & VAPTÂ
- Cloud Security GovernanceÂ
- AI Risk Management & Responsible AIÂ
- Security GovernanceÂ
- Vendor Risk ManagementÂ
- Leadership & Stakeholder Management
Note:
By submitting your application, you consent to being contacted by our Talent Acquisition team via phone call, email, SMS, WhatsApp, or other communication channels regarding your application and relevant career opportunities.
Frequently Asked Questions
Is the salary disclosed for the Information Security Manager position at sigmoid?
Where is the Information Security Manager position at sigmoid located?
Which team or department does the Information Security Manager at sigmoid belong to?
How do I apply for the Information Security Manager position at sigmoid?
When was the Information Security Manager job at sigmoid posted?
You'll be redirected to sigmoid's official application page on Greenhouse.