Fractal Logo

Fractal

BISO (Senior manager)

Posted 21 Days Ago
Be an Early Applicant
2 Locations
Senior level
2 Locations
Senior level
The Senior Manager for Business Information Security Officer will design, manage, and enhance the cyber defense strategy focusing on risk and compliance. Responsibilities include maintaining GRC frameworks, conducting risk assessments, managing audits for compliance certifications, developing training programs, and ensuring effective communication of policies and compliance requirements across the organization.
The summary above was generated by AI

It's fun to work in a company where people truly BELIEVE in what they are doing!

We're committed to bringing passion and customer focus to the business.

Business Information Security Officer
Gurgaon , India
 

Job Description

Role Overview

We are seeking a highly skilled and experienced Security GRC to join our dynamic team. The candidate will be responsible for designing, managing, and enhancing our cyber defense strategy, with a focus on risk and compliance.  

Key Responsibilities

Governance, Risk, Compliance (GRC) and Investigations: 

  • Maintain a comprehensive GRC framework aligned with industry standards, regulatory requirements, and organisational objectives. 
  • Provide strategic direction and oversight for all aspects of governance, risk management and compliance activities in Fractal. 
  • Develop and implement policies and procedures to promote a culture of compliance across Fractal.
  • Help business to cater security requirements from the client side related to new engagement and help to conduct risk assessments for existing business processes.
  • Ensure that policies are effectively communicated, understood, and enforced.
  • Conduct risk assessments to identify and prioritise risks across Fractal. Develop and implement risk mitigation strategies and controls to minimise exposure to potential threats and vulnerabilities.
  • Conduct internal audits and assessments to evaluate the effectiveness of security controls. Collaborate to address findings and remediate any identified deficiencies.
  • Manage external audits and compliance for certifications including ISO 27001, SOC2 type2 PCIDSS and cloud security related audits.
  • Develop and deliver training programs and materials to educate employees on GRC policies, procedures, emerging threats, and best practices.
  • Promote awareness of compliance requirements through regular communication and training initiatives 
  • Develop and execute comprehensive data monitoring strategy and tool to detect anomalies, unusual patterns, suspicious activities,  
  • Protect sensitive data and mitigate the risk of data loss or leakage.
  • Lead efforts to implement fraud prevention measures, controls, and procedures to mitigate fraud risks and protect company assets.
  • Oversee employee investigations ensuring compliance with legal and regulatory requirements. Collaborate with Legal, HR teams to address fraud and employee investigation matters.
  • Evaluate security posture of vendors and third-party partners through due diligence assessments and establish a process for ongoing monitoring.
  • Stay up to date and informed on developing regulatory concerns and changing IT and information security trends. 

Required Skills: 

  • Proven experience in managing GRC and risk management roles with at least 10 years of relevant experience. 
  • Strong knowledge on  
  • applicable information security management, governance, and compliance principles, standards, practices, laws, rules, and regulations (ISO 27001, PCI DSS, NIST, GDPR, CCPA, IT Act, etc) 
  • cyber and cloud security standard frameworks, architecture, design, operations, controls, technology, solutions, and service orchestration. 
  • Information systems auditing, monitoring, controlling, and assessment process; 
  • Risk assessment and management methodology.
  • Detail-oriented, ability to consistently provide high-quality products that are concise, thorough and accurate. 
  • Strong attention to detail with an analytical mind and outstanding problem-solving skills. 
  • Excellent leadership, communication, and interpersonal skills with the ability to effectively engage and influence stakeholders at all levels of the organisation.

If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!

Not the right fit?  Let us know you're interested in a future opportunity by clicking Introduce Yourself in the top-right corner of the page or create an account to set up email alerts as new job postings become available that meet your interest!

Top Skills

Ccpa
Cloud Security
Compliance
Cyber Security
Gdpr
Governance
Iso 27001
Nist
Pci Dss
Risk

Similar Jobs

9 Hours Ago
Hybrid
Navi Mumbai, Thane, Maharashtra, IND
Mid level
Mid level
Enterprise Web • Fintech • Financial Services
As a Senior Internal Auditor, you will evaluate the company's business and IT processes, assess internal control effectiveness, and perform operational, compliance, and financial reviews, while providing recommendations to enhance governance and reduce risks.
10 Hours Ago
Easy Apply
Remote
3 Locations
Easy Apply
Senior level
Senior level
Cloud • Information Technology • Security • Software
As a Senior Security Engineer, you will design and develop software solutions to protect data and infrastructure in the cloud, collaborate with various security teams, and help monitor and mitigate vulnerabilities across JumpCloud products and services.
Top Skills: AutomationCloudDevsecops
22 Hours Ago
Pune, Maharashtra, IND
Entry level
Entry level
Healthtech • Logistics • Pharmaceutical
The Administrator I is responsible for system and application administration, providing routine maintenance, system support, and ensuring data integrity. Duties include patching and upgrading databases, administering user access, and participating in software change testing. The role involves monitoring system performance, providing technical support, and collaborating with teams to meet BI requirements and manage infrastructure components.

What you need to know about the Mumbai Tech Scene

From haggling for the best price at Chor Bazaar to the bustle of Crawford Market, the energy of Mumbai's traditional markets is a key part of the city's charm. And while these markets will always have their place, the city also boasts a thriving e-commerce scene, ranking among the largest in the region. Driven by online sales in everything from snacks to licensed sports merchandise to children's apparel, the local industry is worth billions, with companies actively recruiting to meet the demands of continued growth.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account