Role Overview
We are looking for an experienced ISMS Lead to drive end-to-end ISO 27001 implementation in a biotechnology environment, ensuring alignment with GxP, data integrity (ALCOA+), DPDP Act, IT Act 2003 etc.The role will be responsible not only for documentation and audit readiness but also for hands-on deployment of Annex A controls in coordination with the infrastructure, application team & business teams.
- ISMS Implementation (ISO 27001 + DPDP Act + IT Act 2000 Alignment) a. Lead end-to-end ISMS deployment aligned with ISO 27001 standards b. Ensure alignment with DPDP Act, IT ACT 2000 and ALCOA+ principles c. Integrate ISMS controls QA systems
- Annex A Controls Deployment (Hands-on) a. Possess strong practical knowledge of ISO 27001 Annex A controls b. Drive actual implementation of controls (not just documentation) across IT and business environments c. Work closely with businesses, business users, infrastructure, and application teams to: i. Implement access controls, endpoint security, network security, logging & monitoring ii. Ensure backup, DR, patching, vulnerability management, and hardening practices iii. Validate effectiveness of controls through testing and periodic reviews
- Policy, SOP & Documentation Framework a. Develop and maintain: i. Information Security Policies ii. SOPs and Work Instructions iii. Templates, logs, and records b. Ensure documentation meets audit expectations c. Align with Quality Management System (QMS) documentation
- Audit Readiness & Compliance a. Prepare for and manage ISO 27001 certification audits (Stage 1 & Stage 2) b. Support regulatory audits and inspections c. Ensure timely closure of audit observations and CAPAs
- Data Integrity & Security Controls a. Ensure implementation of controls supporting: i. ISO 27001 ISMS ii. ALCOA+ principles iii. Audit trails, electronic records, and traceability
- Evidence Management & Validation Support a. Collect and maintain ISMS evidences aligned with audits b. Support validation lifecycle documentation c. Ensure controls are documented, implemented, and auditable
- Cross-functional Collaboration a. Liaise with: i. QA/QMS teams for compliance alignment ii. HCD, QC, Production, R&D teams for system-level controls iii. IT Infrastructure / Security team for technical implementation b. Ensure practical deployment of controls, not just theoretical compliance
- Risk Management & Governance a. Conduct risk assessments b. Maintain risk register and mitigation plans c. Establish governance dashboards and compliance tracking
- Training & Awareness a. Drive ISMS and cybersecurity awareness programs b. Educate users on data integrity, phishing, and secure practices c. Build a culture of compliance and security ownership