Source description
About the role
As an experienced Information Security professional, you will be responsible for a wide range of security strategy, governance, operations, regulatory compliance, risk management, team leadership, technology management, and reporting. Here is a breakdown of your key responsibilities: - Develop, execute, and continuously improve the enterprise information security strategy, policies, and procedures aligned with business objectives. - Lead the implementation and maintenance of the ISO 27001 Information Security Management System (ISMS) and ensure ongoing compliance with relevant regulatory standards. - Conduct internal audits, gap analyses, and readiness assessments for certifications. - Establish crisis management, business continuity, and incident reporting frameworks. - Oversee SOC operations, SIEM monitoring, threat detection, and incident response. - Lead vulnerability management and penetration testing programs. - Coordinate response to cyber incidents and forensic investigations. - Manage third-party security risks and vendor assessments. - Ensure compliance with pharmaceutical and healthcare regulatory requirements. - Support internal and external audits, inspections, and certifications. - Collaborate with Quality Assurance and Regulatory Affairs teams during validation activities. - Maintain documentation for CSV/CSA-related security controls. - Manage enterprise risk assessment and mitigation strategies. - Oversee day-to-day security operations, including monitoring, detection, and response to breaches. - Lead investigations of security incidents and develop mitigation and remediation plans. - Monitor emerging security technologies and recommend upgrades or enhancements. - Lead, mentor, and manage the IT Security team. - Collaborate with IT, DevOps, and business teams to integrate security into the software development lifecycle. - Provide guidance and training to employees on security best practices. - Evaluate, recommend, and oversee the deployment of cybersecurity solutions. - Ensure continuous improvement of security tools and processes to protect sensitive data. - Implement security controls for various environments including On-prem data centres, Cloud platforms, SaaS platforms, and Laboratory systems. - Prepare and present detailed reports on security metrics, risk posture, compliance status, and remediation plans. - Maintain detailed incident reports, compliance documentation, and audit records. Qualifications & Skills: - Bachelors or Masters degree in Computer Science, Information Security, or related field. - 12+ years of experience in information security. - Strong knowledge of cybersecurity frameworks, risk management, and regulatory compliance. - Hands-on experience with security technologies such as SIEM, firewalls, IDS/IPS, DLP, IAM, encryption, and endpoint security. Preferred Certifications: - CISSP (Certified Information Systems Security Professional) - CISM (Certified Information Security Manager) - ISO 27001 Lead Implementer / Auditor - CEH (Certified Ethical Hacker) or equivalent Skills & Competencies: - Strong leadership and team management abilities. - Strategic thinking and ability to align security initiatives with business objectives. - Excellent analytical, problem-solving, and decision-making skills. - Effective communication skills for both technical and non-technical audiences. - Ability to manage multiple priorities and lead complex security projects. As an experienced Information Security professional, you will be responsible for a wide range of security strategy, governance, operations, regulatory compliance, risk management, team leadership, technology management, and reporting. Here is a breakdown of your key responsibilities: - Develop, execute, and continuously improve the enterprise information security strategy, policies, and procedures aligned with business objectives. - Lead the implementation and maintenance of the ISO 27001 Information Security Management System (ISMS) and ensure ongoing compliance with relevant regulatory standards. - Conduct internal audits, gap analyses, and readiness assessments for certifications. - Establish crisis management, business continuity, and incident reporting frameworks. - Oversee SOC operations, SIEM monitoring, threat detection, and incident response. - Lead vulnerability management and penetration testing programs. - Coordinate response to cyber incidents and forensic investigations. - Manage third-party security risks and vendor assessments. - Ensure compliance with pharmaceutical and healthcare regulatory requirements. - Support internal and external audits, inspections, and certifications. - Collaborate with Quality Assurance and Regulatory Affairs teams during validation activities. - Maintain documentation for CSV/CSA-related security controls. - Manage enterprise risk assessment and mitigation strategies. - Oversee day-to-day security operations, including monitoring, detection, and response to brea
More at Sai Life Sciences Limited