Information Security Engineer (GRC)
OSTTRA · Gurugram, Haryana, India
Financial Services · 1,001-5,000 employees
About the role
The Information Security Engineer will manage the ISO 27001 framework, facilitate security audits, and oversee compliance operations including access reviews and policy management. They will also collaborate with cross-functional teams to embed security practices and lead security awareness initiatives.
What they look for
Requirements
Candidates must have 3-5 years of direct experience in an InfoSec GRC role with hands-on expertise in ISO 27001 ISMS management. Strong communication skills and the ability to translate complex compliance requirements for non-technical stakeholders are essential.
Full description
Job Overview
About the Role:
The team:
The Information Security team is responsible for security controls relating to protecting information in all formats. We maintain a number of policies and an Information Security Management System which dictates how infosec is integrated into processes as well as tools and technical controls to directly protect against cyber security threats.
Responsibilities and impact:
We are seeking a dedicated and collaborative Information Security Engineer to join our growing Governance, Risk, and Compliance (GRC) team. In this role, you will play a pivotal part in maintaining, maturing, and auditing our information security management framework.
The ideal candidate has 3–5 years of direct experience within an InfoSec GRC function and thrives in a team-oriented environment. You will be responsible for ensuring our policies remain up-to-date, driving our ISO 27001 certification lifecycle, and executing core compliance operations like user access reviews, exception management, and security awareness programs.
Key Responsibilities
Governance & ISO 27001 Management
• ISMS Governance: Manage and maintain our ISO 27001 Information Security Management System (ISMS) to ensure continuous compliance.
• Audit Facilitation: Lead internal security audits and act as a point of contact for external certification audits.
• Policy Management: Regularly review, update, and draft information security policies, standards, and procedures to align with evolving regulatory landscapes and business needs.
GRC Operations & Risk Management
• Access Governance: Coordinate and oversee periodic user access reviews across critical systems.
• Exception Management: Evaluate, log, and monitor security policy exceptions, ensuring compensating controls are effectively implemented and tracked.
• Risk Culture: Administer the company-wide security awareness training program and orchestrate routine phishing simulations to strengthen our human firewall.
Collaboration & Communication
• Partner closely with cross-functional teams (IT, Legal, HR, and Engineering) to embed security compliance into daily operations.
• Translate complex compliance requirements into actionable, easy-to-understand guidance for non-technical stakeholders.
What we’re looking for:
Required Experience & Skills
• Experience: 3–5 years of proven experience specifically within an Information Security GRC role.
• ISO 27001 Expertise: Hands-on experience managing an ISO 27001 ISMS, including active participation in both internal and external certification audits.
• Core GRC Competencies: Direct experience executing user access reviews, phishing simulations, security training, and policy exception workflows.
• Communication: Exceptional verbal and written communication skills, with the ability to document clear policies and present findings to various business units.
• Soft Skills: A strong team player with a highly collaborative mindset, excellent problem-solving abilities, and a proactive approach to security culture.
Preferred Qualifications (Nice-to-Have)
• Relevant industry certifications (e.g., ISO 27001 Internal/Lead Auditor, CISA, CRISC, Security+, or CISM).
• Experience with the ISO 42001 AIMS standard.
• Experience utilizing GRC automation platforms/tools.
The location: Gurgaon, India