
Program Manager – Security Operations, Compliance
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in India.
• Oversee and enhance Anovia's ISO/IEC 27001 Information Security Management System, which includes policies, procedures, controls, risks, objectives, evidence, and ongoing improvement efforts.
• Assist with ISO 27001, SOC 2, HIPAA, and other security and compliance programs.
• Manage internal and external audit processes, including evidence preparation, meeting scheduling and facilitation, action item tracking, and ensuring that findings and subsequent actions are addressed.
• Maintain the inventory of information assets and the data classification program, including the assignment and tracking of ownership.
• Support identity and access management functions, including provisioning and de-provisioning, access reviews, least-privilege mandates, and privileged access controls.
• Monitor and enhance security tools and processes, including Microsoft 365 security features, Microsoft Defender, Intune, Entra ID, security monitoring, endpoint protection, and vulnerability management.
• Facilitate vulnerability identification, remediation tracking, and escalation of significant findings.
• Coordinate security assessments of third parties and vendors, including support for security questionnaires and contract reviews.
• Develop, maintain, and promote the adoption of information security policies, standards, and operational procedures.
• Organize security awareness training and phishing simulation initiatives.
• Assist in security incident response efforts, including detection, containment, investigation, root cause analysis, and post-incident reporting.
• Contribute to business continuity and disaster recovery initiatives, including maintaining recovery requirements, conducting tests, and gathering related evidence.
• Lead or coordinate technical and operational projects from initial scope through implementation, establishing plans, identifying dependencies and owners, coordinating stakeholders, tracking risks and issues, and ensuring project completion.
• Act as the main point of contact for internal and external auditors, coordinating responses with relevant business and technical stakeholders.
• A minimum of 4 years of progressively responsible experience in information security, IT compliance, GRC, security operations, or a related discipline.
• Practical experience with ISO/IEC 27001, SOC 2, or a similar security and compliance framework.
• Significant involvement in an audit or certification process, encompassing policy development, control implementation, evidence collection, audit preparation, management meetings, action tracking, and remediation.
• Familiarity with GRC processes and tools, including risk and control management, evidence gathering, compliance tracking, audit preparation, and corrective action management.
• Hands-on experience with the Microsoft 365 security ecosystem, including Microsoft Defender, Intune, Entra ID, and associated security and compliance features.
• Capability to structure ambiguous technical or operational projects by defining scope, developing plans, coordinating stakeholders, managing dependencies and issues, and driving completion.
• Solid understanding of information security principles, risk management, access control, vulnerability management, incident response, and security awareness.
• Proficient in collaborating directly with auditors, technical teams, business stakeholders, vendors, and leadership.
• Excellent organizational and communication skills, with the ability to manage multiple concurrent activities and follow through on commitments.
• Bachelor's degree in Information Security, Computer Science, IT, or a related field, or equivalent practical experience.
• Experience with HIPAA Security and Privacy Rule requirements or other healthcare security and privacy regulations.
• Familiarity with GRC platforms such as Secureframe, Vanta, Drata, or OneTrust.
• Experience with SIEM, EDR/endpoint protection, vulnerability scanners, or similar security tools beyond the Microsoft 365 environment.
• Knowledge of NIST CSF or other complementary security frameworks.
• Experience in managing contractors or vendors during technical or security projects.
• Experience in establishing or enhancing security monitoring, NOC, SOC, or similar operational capabilities.
• Prior involvement in business continuity and disaster recovery planning.
• Certifications can support evidence of knowledge but do not replace practical experience.
• Relevant certifications are advantageous but not mandatory, including ISO/IEC 27001 Lead Implementer or Lead Auditor, CISA, CISSP, and CISM.
• Comprehensive Health Insurance policy.
• Employee Wellness Program focused on mental health.
• Robust reward and recognition programs.
• Company incentive programs available.
• Attractive leave policy: Holiday Leave, Maternity Leave, Paternity Leave, Birthday Leave, Bereavement Leave, and Paid Leave for personal time off.
• Ample opportunities for growth and learning.
• Opportunities for remote work.
• A focus on work/life balance.
• Immigration Program supporting relocation to Canada for eligible employees.
OSIbeyond
It4us Cyber Security
CFA Institute
Get handpicked remote jobs straight to your inbox weekly.