Ather Energy

Information Security Management Systems Associate

IT Infrastructure · Bengaluru · Full Time · 2-4 years

Posted
11 Jun 2026
Last verified at source
4 days ago
Apply on Ather Energy
The ISMS / GRC Associate is responsible for developing and implementing information security measures and compliance programs. This includes creating and maintaining security policies, standards, and guidelines; conducting security assessments; managing third-party risk assessments; coordinating audits; and training employees on security best practices. The Associate works with other departments to integrate information security and compliance into all aspects of the organization's operations. The role must ensure compliance with all relevant laws and regulations related to information security, such as the IT Act, 2000, ISO 27001:2022,and NIST CSF. ## You will be responsible for: 1. Security Program & Compliance Implementation * Develop and maintain information security processes and policies including ISO 27001:2022, ITGC, and TPRM. * Support ISMS implementation and maintenance across the organization. * Support the implementation and operationalization of the GRC platform to automate compliance tracking and risk monitoring. * Ensure compliance with the IT Act, 2000 and other relevant legal regulations. * Coordinate audits for internal and external reviews, including ISO 27001. * Maintain compliance evidence repository, audit trails, and documentation. * Track and manage remediation of audit findings, control gaps, and compliance deficiencies. Risk & Assessment Management * Conduct risk assessments to identify and analyze potential security threats. * Support the identification, analysis, and documentation of information security risks. * Monitor and report on information security risks, incidents, and key risk indicators. * Perform security control testing and validation activities. * Manage Risk Register to ensure timely mitigation and treatment of identified risks. Third-Party Risk Management (TPRM) * Implement and manage the Third-Party Risk Management program. * Conduct vendor security assessments and due diligence reviews, focusing on artifacts like SOC 2 Type II reports, VAPT reports, and ISO 27001 certifications. * Maintain vendor risk inventory and track vendor compliance status. * Monitor third-party security controls and contractual obligations. Collaboration & Documentation * Work with other departments (IT, Engineering, HR, Legal, and business teams) to ensure that information security is integrated into all aspects of the organization's operations. * Maintain comprehensive information security documentation including policies, procedures, standards, and work instructions. * Manage and update asset inventory, data classification, and data flow mapping. * Prepare management reports, dashboards, and compliance status updates. * Act as a liaison between technical teams and business stakeholders. Awareness, Training & Continuous Improvement * Develop and deliver information security awareness training programs for employees. * Conduct role-based security training for employees and contractors. * Track and report on training completion rates and effectiveness. * Stay up-to-date on information security trends, threats, and best practices. * Research and recommend improvements to security controls and processes. * Support the adoption of security automation and GRC tools. ## What kind of experience & skills do I need for this role? ### Required Skills and Qualifications: * Professional Experience: * 2-4 years of experience in information security, GRC, compliance, or audit roles. * Demonstrated experience with security frameworks and standards (ISO 27001 and ITGC). * Prior involvement in compliance programs, audits, or certification projects. * Experience conducting risk assessments and security reviews. * GRC & Security Expertise: * Strong understanding of information security principles, concepts, and best practices. * Working knowledge of compliance and risk frameworks including: * ISO 27001:2022 * IT General Controls (ITGC) * Third-Party Risk Management (TPRM) * NIST Cybersecurity Framework * Familiarity with regulatory requirements: IT Act, 2000 and DPDPA (Good to have). * Soft Skills: * Strong analytical and problem-solving skills. * Excellent written and verbal communication skills. * Exceptional attention to detail and accuracy. * Ability to work independently and as part of a team. * Strong organizational and project management skills. * Ability to manage multiple priorities and work under pressure. * Stakeholder management and interpersonal skills. * Technical writing and documentation capabilities. * Highly motivated and proactive. * Certifications (Preferred): * ISO 27001 Lead Implementer or Lead Auditor * CISA (Certified Information Systems Auditor) ## What should I have graduated in? Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Security, or a related field.