Information Security Management Systems Associate
Ather Energy · Bengaluru, Karnataka, India
About The Role
Role: Information Security Management Systems (ISMS) Associate Location: IBC, Knowledge Park Reporting to: Information Security Manager Team name: Information Security Department About the Team and the Role The Information Security Department team at Ather is responsible for developing and implementing information security measures and compliance programs. This includes creating and maintaining security policies, standards, and guidelines; conducting security assessments; managing third-party risk assessments; coordinating audits; and training employees on security best practices. This role is for an ISMS / GRC Associate who will work with other departments to integrate information security and compliance into all aspects of the organization's operations, ensuring compliance with all relevant laws and regulations related to information security, such as the IT Act, 2000, ISO 27001:2022, and NIST CSF. Responsibilities Develop, maintain, and support the implementation of information security processes and policies including ISO 27001:2022, ITGC, and TPRM. Support the implementation and operationalization of the GRC platform to automate compliance tracking and risk monitoring. Coordinate internal and external audits, maintain compliance evidence repositories, and track the remediation of control gaps and audit findings. Conduct comprehensive risk assessments, perform security control testing, and manage the corporate Risk Register to ensure timely mitigation. Implement and manage the Third-Party Risk Management (TPRM) program, including conducting vendor security assessments and due diligence reviews of SOC 2 Type II and VAPT reports. Collaborate with technical and business stakeholders across IT, Engineering, HR, and Legal to integrate security practices and maintain comprehensive asset inventories. Prepare management reports, compliance status dashboards, data classification schemes, and data flow mapping documentation. Develop and deliver role-based information security awareness training programs while researching and recommending security automation improvements. Experience and Qualifications Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Security, or a related field. 2-4 years of experience in information security, GRC, compliance, or audit roles. Must Have Competencies Designing and auditing Information Security Management Systems in alignment with ISO 27001:2022 framework parameters. Implementing and evaluating IT General Controls (ITGC) across organizational infrastructures. Managing end-to-end Third-Party Risk Management (TPRM) lifecycles and vendor compliance validation. Performing structured information security risk assessments and engineering strategic mitigation controls. Good to Have Competencies Executing cybersecurity strategies based on the NIST Cybersecurity Framework. Interpreting and mapping organizational security practices to the IT Act, 2000 regulatory guidelines. Aligning internal data governance structures with the Digital Personal Data Protection Act (DPDPA) mandates. Deploying automated compliance workflows within dedicated Governance, Risk, and Compliance (GRC) technology platforms. Want to know more? At Ather, we’ve built India’s first intelligent scooter, from scratch. Based on the philosophy of clean design and smart technology, we are transforming the urban commute experience. We are expanding in India, and in the coming years, we look forward to scaling up and launching more products globally. Today, our product offerings include the Ather 450X, 450S, 450 Apex, and Rizta. Beyond the product, we are also setting up an extensive charging network and re-imagining end-to-end ownership experience. To know more, check out our Careers site and our Substack. Be You, With Us The Ather story doesn't write itself - our people do. We believe everyone is equal, but not the same. Diversity is our strength, and building an inclusive and equitable workplace begins with acknowledging and embracing our differences. We are an equal opportunity employer, and our team reflects a wide range of identities, experiences, and perspectives - all united by a shared passion to shape the Ather journey.
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring