Associate Manager - Information & Cyber Security

Apply now »

Posted On: 29 Jun 2026

Location: Noida, UP, India

Company: Iris Software

Why Join Iris?
Are you ready to do the best work of your career at one of India’s Top 25 Best Workplaces in IT industry? Do you want to grow in an award-winning culture that truly values your talent and ambitions?
Join Iris Software — one of the fastest-growing IT services companies — where you own and shape your success story.
 
About Us  
At Iris Software, our vision is to be our client’s most trusted technology partner, and the first choice for the industry’s top professionals to realize their full potential.
With over 4,300 associates across India, U.S.A, and Canada, we help our enterprise clients thrive with technology-enabled transformation across financial services, healthcare, transportation & logistics, and professional services.
Our work covers complex, mission-critical applications with the latest technologies, such as high-value complex Application & Product Engineering, Data & Analytics, Cloud, DevOps, Data & MLOps, Quality Engineering, and Business Automation.

Working with Us
At Iris, every role is more than a job — it’s a launchpad for growth.
Our Employee Value Proposition, “Build Your Future. Own Your Journey.” reflects our belief that people thrive when they have ownership of their career and the right opportunities to shape it.
We foster a culture where your potential is valued, your voice matters, and your work creates real impact. With cutting-edge projects, personalized career development, continuous learning and mentorship, we support you to grow and become your best — both personally and professionally.
Curious what it’s like to work at Iris? Head to this video for an inside look at the people, the passion, and the possibilities. Watch it here.

Job Description

Key Responsibilities

Governance & Compliance

  • Manage and maintain Information Security policies, standards, procedures, and guidelines.
  • Ensure compliance with industry standards such as SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, and client contractual requirements.
  • Monitor compliance obligations and track remediation of identified gaps.
  • Support the implementation and continuous improvement of the Information Security Management System (ISMS).

Risk Management

  • Conduct enterprise and information security risk assessments.
  • Maintain the risk register and track mitigation plans.
  • Facilitate risk reviews with business and technology stakeholders.
  • Perform third-party/vendor risk assessments and due diligence reviews.

Audit & Assurance

  • Coordinate internal and external audits, including SOC 2, ISO 27001, and client audits.
  • Manage audit evidence collection and control validation activities.
  • Track audit findings and ensure timely closure of corrective actions.
  • Support the preparation of bridge letters, compliance reports, and audit responses.

Client Security & Regulatory Requirements

  • Respond to client security questionnaires and due diligence requests.
  • Support client assessments and security reviews.
  • Manage contractual security obligations and compliance commitments.
  • Collaborate with delivery and business teams to address client security concerns.

Security Awareness & Metrics

  • Drive security awareness and compliance training programs.
  • Develop and present security metrics, KRIs, and compliance dashboards to management.
  • Prepare monthly and quarterly governance reports for leadership review.

Incident & Control Management

  • Support security incident governance activities and post-incident reviews.
  • Monitor compliance with access management, vulnerability management, endpoint security, and other security controls.
  • Track remediation of control deficiencies and compliance exceptions.

Required Qualifications

  • 5–8 years of experience in Information Security, Risk Management, Compliance, or Audit.
  • Strong understanding of information security frameworks and standards.

Preferred Certifications

  • ISO 27001 Lead Auditor/Lead Implementer
  • CISA
  • CRISC
  • CISM

Required Skills

  • Knowledge of SOC 2, ISO 27001, NIST, GDPR, HIPAA, and vendor risk management.
  • Experience managing audits and compliance programs.
  • Strong risk assessment and control evaluation skills.
  • Excellent stakeholder management and communication abilities.
  • Experience with GRC tools and compliance tracking platforms.
  • Strong analytical, reporting, and documentation skills.

Key Competencies

  • Leadership and team collaboration
  • Risk-based decision making
  • Attention to detail
  • Problem-solving and analytical thinking
  • Client-facing communication
  • Project and stakeholder management

Mandatory Competencies

Perks and Benefits for Irisians
Iris provides world-class benefits for a personalized employee experience. These benefits are designed to support financial, health and well-being needs of Irisians for a holistic professional and personal growth. Click here to view the benefits.

Apply now »