Anovia Inc. Logo

Anovia Inc.

Program Manager-Security Operations & Compliance

Posted 2 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in India
Mid level
Remote
Hiring Remotely in India
Mid level
Manage information security compliance and operational initiatives, including ISO 27001, SOC 2, and HIPAA programs; coordinate audits, evidence, policies, controls, risk remediation, vendor assessments, access reviews, vulnerability management, incident response, security awareness, and business continuity activities. Lead ambiguous technical initiatives through planning, stakeholder coordination, implementation, and completion while serving as a key contact for auditors and business partners.
The summary above was generated by AI

Anovia (formerly Innovatia Technical Services) is an industry-leading technology outsourcing support provider with expertise in the telecommunications industry. Operating for over 20 years, we specialize in workflow and knowledge processes, as well as technical support, helpdesk and multilingual support services. With over 200 professional experts across the globe, we service some of the worlds’ most successful Fortune 500 and Fortune 1000 companies.

About the Role

Anovia is looking for a hands-on information security and compliance professional with practical experience working with ISO/IEC 27001, SOC 2, HIPAA, or similar security and compliance programs.

The successful candidate will have experience helping an organization prepare for and work through an audit or certification process, including developing and maintaining policies and controls, supporting evidence collection, coordinating activities and meetings, tracking actions, and working with internal and external auditors.

This is also a build and delivery role. Anovia has a number of technical and operational initiatives that require more structure, planning, coordination, and follow-through. The successful candidate will be comfortable taking an initiative that is not yet well defined, establishing a practical plan, coordinating the people involved, and driving the work through to completion. Examples could include implementing a new security tool, improving security monitoring or vulnerability management, or helping establish a NOC/SOC capability.

Responsibilities

  • Maintain and continue to develop Anovia's ISO/IEC 27001 Information Security Management System (ISMS), including policies, procedures, controls, risks, objectives, evidence, and ongoing improvement activities.
  • Support ISO 27001, SOC 2, HIPAA, and other security and compliance initiatives as they are introduced and developed.
  • Coordinate internal and external audit activities, including preparing evidence, scheduling and facilitating meetings, maintaining action items, and ensuring audit findings and resulting actions are addressed.
  • Maintain the information asset inventory and data classification program, including assigning and tracking ownership.
  • Support identity and access management activities, including provisioning and de-provisioning, access reviews, least-privilege requirements, and privileged access controls.
  • Monitor and improve security tooling and processes, including Microsoft 365 security capabilities, Microsoft Defender, Intune, Entra ID, security monitoring, endpoint protection, and vulnerability management.
  • Coordinate vulnerability identification, remediation tracking, and escalation of significant findings.
  • Coordinate third-party and vendor security assessments, including security questionnaires and contract review support.
  • Develop, maintain, and support adoption of information security policies, standards, and operating procedures.
  • Coordinate security awareness training and phishing simulation programs.
  • Support security incident response activities, including detection, containment, investigation, root-cause analysis, and post-incident reporting.
  • Support business continuity and disaster recovery activities, including maintenance of recovery requirements, testing, and related evidence.
  • Lead or coordinate technical and operational initiatives from initial scope through implementation, establishing plans, identifying dependencies and owners, coordinating stakeholders, tracking risks and issues, and driving work to completion.
  • Serve as a primary point of contact for internal and external auditors and coordinate responses with relevant business and technical stakeholders.

Required Qualifications

  • 4+ years of progressively responsible experience in information security, IT compliance, GRC, security operations, or a related field.
  • Practical experience working with ISO/IEC 27001, SOC 2, or a comparable security and compliance framework. Experience should include meaningful participation in an audit or certification process and familiarity with activities such as policy development, control implementation, evidence collection, audit preparation, management meetings, action tracking, and remediation.
  • Experience with GRC processes and tools, including risk and control management, evidence collection, compliance tracking, audit preparation, and remediation or corrective-action management.
  • Working experience with the Microsoft 365 security environment, including familiarity with Microsoft Defender, Intune, Entra ID, and related security and compliance capabilities.
  • Demonstrated ability to take an ambiguous technical or operational initiative and bring structure to it, including defining scope, developing a practical plan, coordinating stakeholders, managing dependencies and issues, and driving the work through to completion.
  • Working knowledge of information security principles, risk management, access control, vulnerability management, incident response, and security awareness.
  • Comfortable working directly with auditors, technical teams, business stakeholders, vendors, and leadership.
  • Strong organizational and communication skills, with the ability to manage multiple ongoing activities and follow through on commitments.
  • Bachelor's degree in Information Security, Computer Science, IT, or a related field, or equivalent practical experience.

Nice to Have

  • Experience with HIPAA Security and Privacy Rule requirements or other healthcare security and privacy requirements.
  • Experience with GRC platforms such as Secureframe, Vanta, Drata, or OneTrust.
  • Experience with SIEM, EDR/endpoint protection, vulnerability scanners, or related security tooling beyond the Microsoft 365 environment.
  • Experience with NIST CSF or other complementary security frameworks.
  • Experience managing contractors or vendors during technical or security initiatives.
  • Experience helping establish or improve security monitoring, NOC, SOC, or similar operational capabilities.
  • Experience with business continuity and disaster recovery planning.

Certifications

Certifications are useful supporting evidence of knowledge, but are not a substitute for practical experience. Relevant certifications include:

  • ISO/IEC 27001 Lead Implementer or Lead Auditor
  • CISA (Certified Information Systems Auditor)
  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)

Relevant certifications are preferred but not require

Benefits at Anovia

  • Comprehensive Health Insurance policy
  • Employee Wellness Program with focus on mental health
  • Robust reward and recognition programs
  • Company incentive programs offered
  • Attractive leave policy: Holiday Leave, Maternity Leave, Paternity Leave, Birthday leave, Bereavement Leave and Paid Leave for personal time off
  • Ample growth and learning opportunities
  • Remote work opportunities
  • Focus on work/life balance
  • Immigration Program supporting immigration to Canada for eligible employees

We thank all candidates for their interest, however, only those selected for an interview will be contacted.
Anovia is an equal opportunity employer.

Similar Jobs

Yesterday
In-Office or Remote
IN
Senior level
Senior level
Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
Lead Circle’s brand evolution across product launches, campaigns, events, advertising, social, motion, and digital experiences. Develop scalable visual identity systems, campaign concepts, illustrations, storyboards, and launch assets. Collaborate with Marketing, Product Marketing, Content, Motion, and Leadership to communicate complex software and AI products through compelling visual storytelling. Present concepts, maintain high craft standards, and explore AI-powered creative workflows.
Top Skills: Adobe Creative SuiteFigma
Yesterday
In-Office or Remote
IN
Senior level
Senior level
Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
Lead the AI Quality engineering team while building evaluation infrastructure, observability tooling, datasets, annotation workflows, and diagnostic systems for production AI agents. Design CI/CD evaluation pipelines, run experiments across prompts and models, diagnose agent failures, improve latency and cost, and partner with AI Core engineering. This is a hands-on player-coach role requiring production software experience and expertise in evaluating complex, tool-using LLM systems.
Top Skills: Ai AgentsBraintrustCi/CdLangsmithLlmsPythonRubyRuby On Rails
Yesterday
In-Office or Remote
IN
Mid level
Mid level
Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
Provide first-line technical customer support through email, troubleshoot Circle’s web, desktop, mobile, and branded applications, advise creators, escalate product feedback, identify support trends, and collaborate with engineering and design teams. The role requires expertise in Circle’s platform, strong communication, SaaS support experience, and availability to work remotely Tuesday through Saturday during 8:00 AM–5:00 PM IST.
Top Skills: AndroidAPIsiOSNotionSingle Sign-On (Sso)SlackZapierZendesk

What you need to know about the Mumbai Tech Scene

From haggling for the best price at Chor Bazaar to the bustle of Crawford Market, the energy of Mumbai's traditional markets is a key part of the city's charm. And while these markets will always have their place, the city also boasts a thriving e-commerce scene, ranking among the largest in the region. Driven by online sales in everything from snacks to licensed sports merchandise to children's apparel, the local industry is worth billions, with companies actively recruiting to meet the demands of continued growth.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account