Information Security Manager at Simpplr developing, implementing, and managing security policies and procedures. Overseeing security systems and leading incident response while ensuring compliance with industry standards.
Responsibilities
Develop, implement, and maintain security policies, procedures, and guidelines to protect information assets and to ensure compliance.
Assess system vulnerabilities, identify security risks, and implement risk mitigation strategies. Ensure that the risk register is kept up to date.
Ensure that all IT systems are up to date with required patches and configuration and required controls are in place to manage and monitor corporate devices.
Manage and respond to security incidents, conduct investigations and coordinate recovery efforts.
Ensure the organization adheres to industry standards and relevant regulations, and conduct regular security audits and security committee meetings.
Closely collaborate with internal and external parties to manage internal and external audits towards successful ISO 27001, ISO 27701 and SOC 2 certifications.
Data Privacy Framework: Ensure compliance with Data Privacy Framework.
Develop and deliver security awareness training to educate employees on best security practices and policies.
Manage and support vendor onboarding process including vendor evaluation and security assessment.
Requirements
10+ years of experience in IT with a focus on information security.
Prior experience with managing and orchestrating security audits and certifications (ISO 27001, ISO 27701, SOC 2 at a minimum).
Prior experience with policies and procedures management.
Knowledge of controls related to the use, processing, storage, and transmission of data.
Proficiency in identifying, assessing, and mitigating security risks and maintaining the risk register.
Leadership & Management: Ability to lead and manage IT and information security programs.
Effectively communicate security risks, policies, and procedures to stakeholders and employees.
A bachelor's degree in cybersecurity, computer science, or a related field.
Security Guard ensuring safety and security at Lincoln Electric facility in Euclid, Ohio. Monitoring access control systems, alarm systems, and coordinating emergency responses effectively.
Cybersecurity & Data Security Junior Associate supporting organizations in data protection through risk assessments and policy development. Collaborating with teams for meaningful contributions in cybersecurity.
Senior Security Consultant delivering complex cybersecurity engagements for high - profile clients. Advising organizations on critical national infrastructure security and compliance.
Safety Specialist focused on fortifying safety culture through engineering and efficiency measures. Managing compliance and conducting training in a hybrid work setting.
Manufacturing Security Specialist ensuring safe and secure satellite manufacturing at ICEYE. Focused on protecting facilities, production, and sensitive information from threats.
Information Security Specialist responsible for implementing security solutions in Tokio Marine. Analyzing and enhancing cybersecurity architectures and tools for diverse IT projects.
Security Engineer responsible for managing Microsoft Sentinel and Defender XDR systems at Cyderes, a cybersecurity service provider. Focused on detection engineering and platform optimization in a hybrid work setting.
Entra ID Security Specialist developing Identity & Access Management solutions focusing on Microsoft Entra ID. Strategically enhancing modern identity and security architectures in a hybrid work environment.
Senior Staff IT Security Auditor leading complex audit engagements for WGU. Strengthening security posture while mentoring junior analysts and collaborating across teams.