Skip to Content

Assistant Manager, Information Security

Head office IBL-Unisys / Networks & Infrastructure Permanent

Assistant Manager – Information Security

Job Summary

Responsible for developing, implementing, and maintaining the organization’s information security program to protect information assets, manage cybersecurity risks, and ensure compliance with regulatory and industry standards.

Work Responsibilities

  • Develop and maintain Information Security policies, standards, procedures, and strategy aligned with business objectives.
  • Manage security risk assessments, risk registers, mitigation, and remediation tracking.
  • Coordinate Vulnerability Assessments, Penetration Testing (VAPT), and security assessments.
  • Monitor and manage security solutions including SIEM, EDR/XDR, Email Security, and vulnerability management platforms.
  • Manage security incidents including investigation, containment, recovery, root-cause analysis, and reporting.
  • Ensure compliance with ISO 27001, NIST, CIS Controls, and applicable regulatory requirements.
  • Conduct third-party/vendor security assessments and support internal/external audits.
  • Develop, maintain, and test Incident Response Plans and conduct periodic tabletop exercises.
  • Coordinate with IT, Infrastructure, Network, and Application teams for vulnerability remediation and security improvements.
  • Drive security awareness, management reporting, KPIs/KRIs, and continuous improvement.
  • Assign tasks, monitor team performance, and provide guidance and feedback.

Requirements

  • Bachelor’s degree in Information Security, Cybersecurity, IT, Computer Science, or related field.
  • 3+ years of relevant Information Security/Cybersecurity experience.
  • Strong knowledge of ISO 27001, NIST, CIS Controls, VAPT, Risk Management, Incident Response, and Security Operations.
  • Experience with SIEM, EDR/XDR, Email Security, and security assessment tools is preferred.

  • Strong analytical, communication, coordination, and problem-solving skills.

Technical Certification / Courses Required

Training or ISO 27001, CIS, CEH, or any relevant cybersecurity certification would be an added advantage.