Jeavio Logo

Jeavio

Manager - Internal IT & Information Security

Posted 10 Days Ago
Be an Early Applicant
In-Office
Vadodara, Gujarat
Expert/Leader
In-Office
Vadodara, Gujarat
Expert/Leader
Leads internal IT operations and the ISO 27001 Information Security Management System. Oversees identity and access, endpoint security, infrastructure, IT support, risk management, policies, audits, vulnerability remediation, incident response, business continuity, data protection, and client security assurance. Partners with Engineering, HR, Legal, auditors, clients, and leadership to maintain secure, reliable, and audit-ready operations.
The summary above was generated by AI
Jeavio is an ISO 27001 certified software development services company. This role leads the day-to-day operation of our internal IT environment and Information Security Management System (ISMS), ensuring our people can work securely and reliably while maintaining the controls, evidence and readiness expected by our clients and auditors. The role partners closely with Engineering, HR, Legal and leadership; governance and final risk acceptance remain with the Information Security Steering Committee.

Key Responsibilities
Internal IT
Lead a reliable, secure and well-managed corporate technology environment for Jeavio’s hybrid workforce.
1. Identity, Endpoints and Access
  • Own Google Workspace, user lifecycle, SSO/MFA, privileged access and periodic access reviews; maintain secure endpoint standards, asset inventory, MDM, encryption and endpoint protection.
2. Infrastructure, Network and Resilience
  • Oversee office and remote connectivity, firewalls, VPN, internal cloud/server environments, backups, recovery, logging and monitoring; maintain appropriate hardening, patching and vulnerability remediation practices.
3. IT Service Management
  • Run the IT support function with clear service levels, prioritization and measurable performance; maintain practical change, incident and problem-management processes and a useful knowledge base.

Information Security and the ISMS
1. ISO 27001 / ISMS Management
  • Operate and continuously improve the ISO/IEC 27001:2022 ISMS, including the Statement of Applicability, required documentation, management reviews, control ownership and action tracking.
  • Coordinate certification, surveillance and internal audit activities; ensure findings and corrective actions are driven to effective closure.
2. Risk, Policy and Compliance
  • Maintain the information security risk register and treatment plans, assess material changes, and present significant or residual risks to the Steering Committee for decision.
  • Keep security policies and standards current and practical; manage security exceptions, awareness activities and applicable legal, contractual and client security obligations.
3. Security Assurance and Client Readiness
  • Coordinate vulnerability assessments and penetration testing, verify remediation, and work with Engineering on appropriate security expectations for development environments, repositories, pipelines and secrets.
  • Support client security questionnaires, due-diligence reviews and audits with clear, evidence-based responses.
4. Incident Response, Continuity and Data Protection
  • Own the security incident response process, including triage, coordination, recovery, post-incident review and timely escalation of contractual or regulatory notification requirements.
  • Maintain appropriate business continuity, disaster recovery, data classification, retention, secure deletion, DLP and client-data handling controls, with periodic testing and review.

Qualifications and Experience
Essential
  • 10+ years of experience across IT infrastructure and/or information security, including 4+ years in a leadership role.
  • Hands-on experience operating an ISO/IEC 27001 ISMS through a certification, surveillance or recertification cycle.
  • Strong working knowledge of identity and access, endpoint security, network/infrastructure security, backup/recovery and vulnerability management in a hybrid environment.
  • Experience working with Google Workspace and/or Microsoft 365 at organisational scale.
  • Ability to work confidently with auditors, clients and internal stakeholders, translating security requirements into practical actions.
  • A degree in Computer Science, IT or Engineering is useful but not required; relevant experience and demonstrated ownership matter more.

Preferred
  • ISO 27001 Lead Implementer/Lead Auditor, CISM, CISSP or CISA certification.
  • Experience in a software services or multi-client environment; exposure to SOC 2, GDPR, India & USA data-protection requirements or major cloud platforms is beneficial.

What Success Looks Like
  • A secure, dependable IT environment with responsive support and clear ownership.
  • An ISMS that is practical, current, audit-ready and supported by evidence rather than paperwork for its own sake.
  • Strong collaboration across Engineering and business teams, balancing security rigour with productivity and sound judgement.

Similar Jobs

8 Hours Ago
Easy Apply
Remote or Hybrid
India
Easy Apply
Senior level
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Monitor security alerts, detect and analyze threats, respond to security incidents, assess their scope and impact, and investigate phishing incidents. The role requires experience with SOC operations, SIEM, EDR, IDS/IPS, firewalls, antivirus tools, networks, operating systems, and endpoint fundamentals. Preferred qualifications include AI-assisted threat detection, security scripting, and certifications such as Security+, CISSP, or CISM.
Top Skills: Ai/MlAntivirusCC#ChronicleComputer NetworksCrowdstrike FalconEdrEndpoint SecurityFirewallsIds/IpsOperating SystemsPowershellPythonSIEM
13 Hours Ago
Remote or Hybrid
India
Expert/Leader
Expert/Leader
Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Senior consulting leader responsible for banking transformation, client growth, and delivery across Tier 1 financial institutions. Leads complex operations and technology transformation programs, target operating model design, executive client relationships, commercial performance, and cross-functional teams. Builds consulting capabilities and high-performing teams in India, while driving revenue, utilization, margin improvement, governance, and measurable transformation outcomes. Workforce transformation and capacity planning experience is advantageous.
13 Hours Ago
Remote or Hybrid
India
Senior level
Senior level
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Sell SailPoint's IGA identity security SaaS to $5B+ enterprises by engaging C-level stakeholders, managing long sales cycles with POCs/RFPs, collaborating with GSIs and channel partners, developing account and opportunity plans, and meeting quota using Challenger methodology.
Top Skills: AIIamIdentity SecurityIgaMachine LearningMicroservicesMulti-TenantSaaSSalesforce (Sfdc)

What you need to know about the Hyderabad Tech Scene

Because of its proximity to leading research institutions and a government committed to the city's growth, Hyderabad's tech scene is booming. With plans to establish India's first "AI city," the city is on track to become one of the world's most anticipated tech hubs, with companies like TransUnion, Schrödinger and Freshworks, among others, already calling the city home.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account