Padmi

IT Risk & Compliance Specialist

HyderabadPosted 3 months ago
CybersecuritySeniorFull Time; Regular
Apply at Sai Life Sciences Limited

Opens the source posting on shine.com

Source description

About the role

View original

As an experienced Information Security professional, you will be responsible for a wide range of security strategy, governance, operations, regulatory compliance, risk management, team leadership, technology management, and reporting. Here is a breakdown of your key responsibilities: - Develop, execute, and continuously improve the enterprise information security strategy, policies, and procedures aligned with business objectives. - Lead the implementation and maintenance of the ISO 27001 Information Security Management System (ISMS) and ensure ongoing compliance with relevant regulatory standards. - Conduct internal audits, gap analyses, and readiness assessments for certifications. - Establish crisis management, business continuity, and incident reporting frameworks. - Oversee SOC operations, SIEM monitoring, threat detection, and incident response. - Lead vulnerability management and penetration testing programs. - Coordinate response to cyber incidents and forensic investigations. - Manage third-party security risks and vendor assessments. - Ensure compliance with pharmaceutical and healthcare regulatory requirements. - Support internal and external audits, inspections, and certifications. - Collaborate with Quality Assurance and Regulatory Affairs teams during validation activities. - Maintain documentation for CSV/CSA-related security controls. - Manage enterprise risk assessment and mitigation strategies. - Oversee day-to-day security operations, including monitoring, detection, and response to breaches. - Lead investigations of security incidents and develop mitigation and remediation plans. - Monitor emerging security technologies and recommend upgrades or enhancements. - Lead, mentor, and manage the IT Security team. - Collaborate with IT, DevOps, and business teams to integrate security into the software development lifecycle. - Provide guidance and training to employees on security best practices. - Evaluate, recommend, and oversee the deployment of cybersecurity solutions. - Ensure continuous improvement of security tools and processes to protect sensitive data. - Implement security controls for various environments including On-prem data centres, Cloud platforms, SaaS platforms, and Laboratory systems. - Prepare and present detailed reports on security metrics, risk posture, compliance status, and remediation plans. - Maintain detailed incident reports, compliance documentation, and audit records. Qualifications & Skills: - Bachelors or Masters degree in Computer Science, Information Security, or related field. - 12+ years of experience in information security. - Strong knowledge of cybersecurity frameworks, risk management, and regulatory compliance. - Hands-on experience with security technologies such as SIEM, firewalls, IDS/IPS, DLP, IAM, encryption, and endpoint security. Preferred Certifications: - CISSP (Certified Information Systems Security Professional) - CISM (Certified Information Security Manager) - ISO 27001 Lead Implementer / Auditor - CEH (Certified Ethical Hacker) or equivalent Skills & Competencies: - Strong leadership and team management abilities. - Strategic thinking and ability to align security initiatives with business objectives. - Excellent analytical, problem-solving, and decision-making skills. - Effective communication skills for both technical and non-technical audiences. - Ability to manage multiple priorities and lead complex security projects. As an experienced Information Security professional, you will be responsible for a wide range of security strategy, governance, operations, regulatory compliance, risk management, team leadership, technology management, and reporting. Here is a breakdown of your key responsibilities: - Develop, execute, and continuously improve the enterprise information security strategy, policies, and procedures aligned with business objectives. - Lead the implementation and maintenance of the ISO 27001 Information Security Management System (ISMS) and ensure ongoing compliance with relevant regulatory standards. - Conduct internal audits, gap analyses, and readiness assessments for certifications. - Establish crisis management, business continuity, and incident reporting frameworks. - Oversee SOC operations, SIEM monitoring, threat detection, and incident response. - Lead vulnerability management and penetration testing programs. - Coordinate response to cyber incidents and forensic investigations. - Manage third-party security risks and vendor assessments. - Ensure compliance with pharmaceutical and healthcare regulatory requirements. - Support internal and external audits, inspections, and certifications. - Collaborate with Quality Assurance and Regulatory Affairs teams during validation activities. - Maintain documentation for CSV/CSA-related security controls. - Manage enterprise risk assessment and mitigation strategies. - Oversee day-to-day security operations, including monitoring, detection, and response to brea

One address, no account. We’ll tell you when matching roles go live.

More at Sai Life Sciences Limited

Related open roles

View all roles
IT Risk & Compliance Specialist at Sai Life Sciences Limited · Padmi