Role Overview
We are looking for an experienced ISMS Lead to drive end-to-end ISO 27001 implementation in a biotechnology environment, ensuring alignment with GxP, data integrity (ALCOA+), DPDP Act, IT Act 2003 etc.The role will be responsible not only for documentation and audit readiness but also for hands-on deployment of Annex A controls in coordination with the infrastructure, application team & business teams.
1. ISMS Implementation (ISO 27001 + DPDP Act + IT Act 2000 Alignment)
a. Lead end-to-end ISMS deployment aligned with ISO 27001 standards
b. Ensure alignment with DPDP Act, IT ACT 2000 and ALCOA+ principles
c. Integrate ISMS controls QA systems
2. Annex A Controls Deployment (Hands-on)
a. Possess strong practical knowledge of ISO 27001 Annex A controls
b. Drive actual implementation of controls (not just documentation) across IT and business environments
c. Work closely with businesses, business users, infrastructure, and application teams to:
i. Implement access controls, endpoint security, network security, logging & monitoring
ii. Ensure backup, DR, patching, vulnerability management, and hardening practices
iii. Validate effectiveness of controls through testing and periodic reviews
3. Policy, SOP & Documentation Framework
a. Develop and maintain:
i. Information Security Policies
ii. SOPs and Work Instructions
iii. Templates, logs, and records
b. Ensure documentation meets audit expectations
c. Align with Quality Management System (QMS) documentation
4. Audit Readiness & Compliance
a. Prepare for and manage ISO 27001 certification audits (Stage 1 & Stage 2)
b. Support regulatory audits and inspections
c. Ensure timely closure of audit observations and CAPAs
5. Data Integrity & Security Controls
a. Ensure implementation of controls supporting:
i. ISO 27001 ISMS
ii. ALCOA+ principles
iii. Audit trails, electronic records, and traceability
6. Evidence Management & Validation Support
a. Collect and maintain ISMS evidences aligned with audits
b. Support validation lifecycle documentation
c. Ensure controls are documented, implemented, and auditable
7. Cross-functional Collaboration
a. Liaise with:
i. QA/QMS teams for compliance alignment
ii. HCD, QC, Production, R&D teams for system-level controls
iii. IT Infrastructure / Security team for technical implementation
b. Ensure practical deployment of controls, not just theoretical compliance
8. Risk Management & Governance
a. Conduct risk assessments
b. Maintain risk register and mitigation plans
c. Establish governance dashboards and compliance tracking
9. Training & Awareness
a. Drive ISMS and cybersecurity awareness programs
b. Educate users on data integrity, phishing, and secure practices
c. Build a culture of compliance and security ownership