The Role
Build and improve information security and GRC processes, policies, controls, and procedures. Support ISO 27001 and SOC 2 readiness, audits, risk assessments, remediation tracking, customer security questionnaires, vendor assessments, and compliance initiatives. Collaborate with leadership, DevOps, Cloud, IT, Security teams, and auditors to strengthen security controls and establish scalable processes.
Summary Generated by Built In
Information Security & Compliance Lead
About the Role
What You’ll Work On
What We’re Looking For
Why This Role?
Location: Gurugram
Experience: 3-5 Years
Employment Type: Full-time
About the Role
Infra360 is growing, and we’re looking for an Information Security & Compliance Lead to help build and strengthen our InfoSec & GRC practices.
This is a hands-on, high-ownership opportunity for someone who wants to take the next step in their career by working across Information Security, Compliance, Risk, and Governance.
You’ll work closely with Leadership, DevOps, Cloud, IT, and Security teams to build practical security processes, support compliance initiatives, and prepare the organization for certifications, audits, and customer security requirements.
What You’ll Work On
- Build and improve Infra360’s Information Security & GRC processes.
- Develop and maintain security policies, controls, and procedures.
- Support ISO 27001 and SOC 2 readiness, audits, and compliance activities.
- Conduct security risk assessments and track remediation.
- Coordinate with internal teams and auditors for evidence, assessments, and audits.
- Support customer security questionnaires, RFPs, and due diligence.
- Help establish vendor and third-party security assessment processes.
- Work with DevOps, Cloud and IT teams to strengthen and document security controls.
- Support security awareness and compliance initiatives across the organization.
- Help create simple, scalable processes as Infra360 continues to grow.
What We’re Looking For
- 3-5 years of experience in Information Security, GRC, Risk & Compliance.
- Practical experience with ISO 27001 / ISMS and exposure to SOC 2.
- Understanding of security policies, controls, risk management, and audits.
- Working knowledge of HIPAA, PCI DSS, GDPR or DPDP is a plus.
- Basic technical understanding of Cloud, IAM, Endpoint Security, Vulnerability Management and Security Operations.
- Good communication and stakeholder-management skills.
- Strong ownership and documentation skills.
- Someone who enjoys building processes, solving problems, and working in a fast-moving environment.
ISO 27001 Lead Implementer/Auditor, CISA, CISM, CISSP, CRISC or CCSP.
Why This Role?
An opportunity to build and shape Infra360’s InfoSec & GRC function, work closely with technical and leadership teams, and grow with a fast-scaling cloud and cybersecurity organization.
Skills Required
- 3-5 years of experience in Information Security, GRC, Risk, or Compliance
- Practical experience with ISO 27001 and ISMS
- Exposure to SOC 2
- Understanding of security policies, controls, risk management, and audits
- Basic technical understanding of Cloud, IAM, Endpoint Security, Vulnerability Management, and Security Operations
- Good communication and stakeholder-management skills
- Strong ownership and documentation skills
- Working knowledge of HIPAA, PCI DSS, GDPR, or DPDP
- ISO 27001 Lead Implementer or Lead Auditor certification
- CISA, CISM, CISSP, CRISC, or CCSP certification
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Infra360 is a fast-growing cloud, DevOps, and infrastructure services company headquartered in Gurugram (Gurgaon), India, that helps startups and enterprises modernize, secure, and scale their platforms across AWS, Azure, and GCP. Founded in 2022 by Deepak Agrawal, it provides customer-centric cloud consulting for technology-driven organizations, focusing on cloud excellence and business resilience, and is recognized as a DPIIT-recognized startup.








