Anovia Inc. Logo

Anovia Inc.

Program Manager-Security Operations & Compliance

Posted 8 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in India
Mid level
Remote
Hiring Remotely in India
Mid level
Manage information security compliance and operational initiatives, including ISO 27001, SOC 2, and HIPAA programs; coordinate audits, evidence, policies, controls, risk remediation, vendor assessments, access reviews, vulnerability management, incident response, security awareness, and business continuity activities. Lead ambiguous technical initiatives through planning, stakeholder coordination, implementation, and completion while serving as a key contact for auditors and business partners.
The summary above was generated by AI

Anovia (formerly Innovatia Technical Services) is an industry-leading technology outsourcing support provider with expertise in the telecommunications industry. Operating for over 20 years, we specialize in workflow and knowledge processes, as well as technical support, helpdesk and multilingual support services. With over 200 professional experts across the globe, we service some of the worlds’ most successful Fortune 500 and Fortune 1000 companies.

About the Role

Anovia is looking for a hands-on information security and compliance professional with practical experience working with ISO/IEC 27001, SOC 2, HIPAA, or similar security and compliance programs.

The successful candidate will have experience helping an organization prepare for and work through an audit or certification process, including developing and maintaining policies and controls, supporting evidence collection, coordinating activities and meetings, tracking actions, and working with internal and external auditors.

This is also a build and delivery role. Anovia has a number of technical and operational initiatives that require more structure, planning, coordination, and follow-through. The successful candidate will be comfortable taking an initiative that is not yet well defined, establishing a practical plan, coordinating the people involved, and driving the work through to completion. Examples could include implementing a new security tool, improving security monitoring or vulnerability management, or helping establish a NOC/SOC capability.

Responsibilities

  • Maintain and continue to develop Anovia's ISO/IEC 27001 Information Security Management System (ISMS), including policies, procedures, controls, risks, objectives, evidence, and ongoing improvement activities.
  • Support ISO 27001, SOC 2, HIPAA, and other security and compliance initiatives as they are introduced and developed.
  • Coordinate internal and external audit activities, including preparing evidence, scheduling and facilitating meetings, maintaining action items, and ensuring audit findings and resulting actions are addressed.
  • Maintain the information asset inventory and data classification program, including assigning and tracking ownership.
  • Support identity and access management activities, including provisioning and de-provisioning, access reviews, least-privilege requirements, and privileged access controls.
  • Monitor and improve security tooling and processes, including Microsoft 365 security capabilities, Microsoft Defender, Intune, Entra ID, security monitoring, endpoint protection, and vulnerability management.
  • Coordinate vulnerability identification, remediation tracking, and escalation of significant findings.
  • Coordinate third-party and vendor security assessments, including security questionnaires and contract review support.
  • Develop, maintain, and support adoption of information security policies, standards, and operating procedures.
  • Coordinate security awareness training and phishing simulation programs.
  • Support security incident response activities, including detection, containment, investigation, root-cause analysis, and post-incident reporting.
  • Support business continuity and disaster recovery activities, including maintenance of recovery requirements, testing, and related evidence.
  • Lead or coordinate technical and operational initiatives from initial scope through implementation, establishing plans, identifying dependencies and owners, coordinating stakeholders, tracking risks and issues, and driving work to completion.
  • Serve as a primary point of contact for internal and external auditors and coordinate responses with relevant business and technical stakeholders.

Required Qualifications

  • 4+ years of progressively responsible experience in information security, IT compliance, GRC, security operations, or a related field.
  • Practical experience working with ISO/IEC 27001, SOC 2, or a comparable security and compliance framework. Experience should include meaningful participation in an audit or certification process and familiarity with activities such as policy development, control implementation, evidence collection, audit preparation, management meetings, action tracking, and remediation.
  • Experience with GRC processes and tools, including risk and control management, evidence collection, compliance tracking, audit preparation, and remediation or corrective-action management.
  • Working experience with the Microsoft 365 security environment, including familiarity with Microsoft Defender, Intune, Entra ID, and related security and compliance capabilities.
  • Demonstrated ability to take an ambiguous technical or operational initiative and bring structure to it, including defining scope, developing a practical plan, coordinating stakeholders, managing dependencies and issues, and driving the work through to completion.
  • Working knowledge of information security principles, risk management, access control, vulnerability management, incident response, and security awareness.
  • Comfortable working directly with auditors, technical teams, business stakeholders, vendors, and leadership.
  • Strong organizational and communication skills, with the ability to manage multiple ongoing activities and follow through on commitments.
  • Bachelor's degree in Information Security, Computer Science, IT, or a related field, or equivalent practical experience.

Nice to Have

  • Experience with HIPAA Security and Privacy Rule requirements or other healthcare security and privacy requirements.
  • Experience with GRC platforms such as Secureframe, Vanta, Drata, or OneTrust.
  • Experience with SIEM, EDR/endpoint protection, vulnerability scanners, or related security tooling beyond the Microsoft 365 environment.
  • Experience with NIST CSF or other complementary security frameworks.
  • Experience managing contractors or vendors during technical or security initiatives.
  • Experience helping establish or improve security monitoring, NOC, SOC, or similar operational capabilities.
  • Experience with business continuity and disaster recovery planning.

Certifications

Certifications are useful supporting evidence of knowledge, but are not a substitute for practical experience. Relevant certifications include:

  • ISO/IEC 27001 Lead Implementer or Lead Auditor
  • CISA (Certified Information Systems Auditor)
  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)

Relevant certifications are preferred but not require

Benefits at Anovia

  • Comprehensive Health Insurance policy
  • Employee Wellness Program with focus on mental health
  • Robust reward and recognition programs
  • Company incentive programs offered
  • Attractive leave policy: Holiday Leave, Maternity Leave, Paternity Leave, Birthday leave, Bereavement Leave and Paid Leave for personal time off
  • Ample growth and learning opportunities
  • Remote work opportunities
  • Focus on work/life balance
  • Immigration Program supporting immigration to Canada for eligible employees

We thank all candidates for their interest, however, only those selected for an interview will be contacted.
Anovia is an equal opportunity employer.

Similar Jobs

2 Hours Ago
Remote or Hybrid
India
Senior level
Senior level
Digital Media • Information Technology • News + Entertainment
Designs and customizes software applications, manages releases, gathers stakeholder requirements, mentors junior engineers, maintains technical documentation, evaluates performance metrics, and partners with Quality Assurance to ensure reliable, compliant software. The role also uses market trends to guide product improvements and participates in peer programming, design sprints, and prototyping. Requires independent judgment, consistent attendance, and flexibility to work nights, weekends, and variable schedules.
3 Hours Ago
In-Office or Remote
Mid level
Mid level
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Build and ship scalable backend features and RESTful microservices in a distributed cloud environment. Responsibilities include code review, testing, documentation, monitoring, error reporting, reliability and performance improvements, Agile participation, and mentoring teammates. The role requires experience with backend application development, object-oriented programming, databases, public cloud platforms, and cloud architecture patterns.
Top Skills: AWSAzureCassandraDynamoDBGoGoogle App EngineIaasJavaKotlinMicroservicesOraclePaasPostgresPythonRestSaaSScala
Yesterday
Remote
Gujarat, IND
Entry level
Entry level
Artificial Intelligence • Hardware • Information Technology • Machine Learning
Maintains and troubleshoots semiconductor test equipment, performs preventive maintenance and calibration, monitors equipment and process data, investigates performance deviations, documents activities, communicates issues across engineering and production teams, and supports yield improvement and continuous improvement projects using data and Generative AI insights.
Top Skills: Generative Ai

What you need to know about the Pune Tech Scene

Once a far-out concept, AI is now a tangible force reshaping industries and economies worldwide. While its adoption will automate some roles, AI has created more jobs than it has displaced, with an expected 97 million new roles to be created in the coming years. This is especially true in cities like Pune, which is emerging as a hub for companies eager to leverage this technology to develop solutions that simplify and improve lives in sectors such as education, healthcare, finance, e-commerce and more.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account