SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Simpplr is an AI-powered intranet platform that unifies the digital workplace for over 1,000 organizations including AAA, NHS, Penske, and Moderna. The company is seeking an Information Security Manager to lead and strengthen its security posture across IT infrastructure and cloud applications.
In this hybrid role based in Gurugram, you will develop, implement, and maintain comprehensive security policies, procedures, and guidelines to protect information assets and ensure compliance. You'll assess system vulnerabilities, identify security risks, and implement mitigation strategies while maintaining an up-to-date risk register. Key responsibilities include managing security incidents, conducting investigations, and coordinating recovery efforts.
You will lead the organization's compliance efforts with industry standards and regulations, conducting regular security audits and chairing security committee meetings. A critical focus area is orchestrating internal and external audits toward successful ISO 27001, ISO 27701, and SOC 2 certifications, working closely with both internal stakeholders and external audit partners. You'll also ensure compliance with Data Privacy Framework requirements and manage vendor onboarding processes including security assessments.
Additional responsibilities include developing and delivering security awareness training to employees, ensuring all IT systems maintain current patches and required controls, and managing corporate device security and monitoring. This is a highly collaborative role requiring excellent communication skills to articulate security risks, policies, and procedures to diverse stakeholders.
Required qualifications include 8+ years of IT experience with a focus on information security, prior experience managing and orchestrating security audits and certifications (ISO 27001, ISO 27701, SOC 2 minimum), expertise in policies and procedures management, and knowledge of data controls. You must demonstrate proficiency in identifying, assessing, and mitigating security risks, with strong leadership and management capabilities. A bachelor's degree in cybersecurity, computer science, or related field is required.
Preferred qualifications include experience with ISO 42001, understanding of data governance and compliance in US, EU, Australia, and Canada, relevant certifications (CISM, CISSP, CRISC), and experience in SaaS and multi-tenant environments.