Job Title: Information Security Manager
Experience: 5+ Years
Location: Ahmedabad, Gujarat
Department: Administration
About Simform:
Simform is a premier digital engineering company specialising in Cloud, Data, AI/ML, and Experience Engineering to create seamless digital experiences and scalable products. Simform has strong capabilities across Microsoft, Google Cloud, and Databricks. With a presence in 6 countries, Simform primarily serves North America, the UK, and the Northern European market. Simform is well-recognised as one of the most reputed employers in the region, having created a thriving work culture with a high work-life balance that gives a sense of freedom and opportunity to grow.
Role Overview:
We are looking for a hands-on Information Security Manager to strengthen and manage the organization's overall security posture.
The ideal candidate should have strong experience in Information Security and Cybersecurity operations, with expertise across one or more security domains such as Security Operations, Identity & Access Management, Data Security, Cloud Security, Endpoint Security, Threat Detection & Response, Governance Risk & Compliance (GRC), and Security Architecture.
While experience with Microsoft 365 security technologies such as Entra ID, Defender, Purview, Intune, Sentinel, SharePoint, and Exchange Online is valuable, we are not specifically seeking an M365-only profile. Candidates should possess broad Information Security expertise and be comfortable working across diverse security tools, platforms, and environments.
Key Responsibilities
Cybersecurity Operations & Technical Security
Manage and improve the organization's overall security posture.
Monitor, investigate, and respond to security incidents, threats, and vulnerabilities.
Conduct security assessments, risk reviews, and remediation activities.
Implement and maintain security controls across cloud, endpoint, network, identity, and data security domains.
Manage threat detection, security monitoring, incident response, and security operations processes.
Drive continuous improvement in security visibility, detection, and response capabilities.
Identity, Data & Application Security
Implement and manage Identity & Access Management (IAM) controls.
Manage MFA, Privileged Access Management (PAM/PIM), Conditional Access, Identity Governance, and Zero Trust initiatives.
Protect organizational data through Data Loss Prevention (DLP), Information Protection, Encryption, Classification, and Retention controls.
Review application security practices and collaborate with engineering teams on secure implementation.
Cloud & Infrastructure Security
Secure cloud environments across Microsoft Azure or hybrid infrastructures.
Assess and improve security configurations, access controls, and monitoring capabilities.
Collaborate with Infrastructure and IT teams to ensure secure deployment and operations.
Governance, Risk & Compliance
Develop and maintain security policies, standards, procedures, and security baselines.
Conduct security risk assessments and compliance reviews.
Support audits and compliance initiatives.
Drive security awareness and security best practices across the organization.
Required Skills & Experience
5+ years of experience in Information Security / Cybersecurity.
Strong hands-on experience in Information Security domains
Strong understanding of security principles, risk management, and security operations.
Experience investigating and responding to security incidents.
Good understanding of modern security frameworks and best practices.
Preferred Certifications
SC-100, SC-200, SC-300, SC-400, CISSP or CISM.
Why Join Us:
Young Team, Thriving Culture
Flat-hierarchical, friendly, engineering-oriented, and growth-focused culture.
Well-balanced learning and growth opportunities
Free health insurance.
Office facilities with a game zone, in-office kitchen with affordable lunch service, and free snacks.
Sponsorship for certifications/events and library service.
Flexible work timing, leaves for life events, WFH and hybrid options
Skills Required
- 5+ years of experience in information security or cybersecurity
- Strong hands-on experience with Microsoft 365 Security
- Experience with Microsoft Entra ID, Conditional Access, MFA, and PIM
- Experience with Microsoft Defender XDR and Microsoft Defender security solutions
- Strong knowledge of Microsoft Purview, DLP, and Information Protection
- Experience with Microsoft Intune and endpoint security
- Understanding of incident response, IAM, cloud security, and security governance
- Knowledge of ISO 27001, NIST, or CIS frameworks
- SC-100, SC-200, SC-300, SC-400, CISSP, or CISM certification
What We Do
Simform is a tech company with a mission to help successful companies extend their tech capacity. Founded in October 2010, we have helped organizations ranging from Startups that went public, to Fortune 500 companies, and WHO backed NGOs. Simform helps companies become innovation leaders by delivering software teams on demand. We help you - choose the right technologies to invest in, decide on the best architecture and processes to follow, and oversee the successful delivery of their software projects.









