The Role
Lead end-to-end ISO 27001 ISMS implementation within a biotechnology environment. Deploy Annex A security controls across infrastructure, applications, and business teams; develop policies and SOPs; manage audit readiness, evidence, risk registers, CAPAs, data integrity, validation support, governance dashboards, and cybersecurity awareness programs. Ensure alignment with GxP, ALCOA+, DPDP Act, IT Act, and QMS requirements.
Summary Generated by Built In
Role Overview
We are looking for an experienced ISMS Lead to drive end-to-end ISO 27001 implementation in a biotechnology environment, ensuring alignment with GxP, data integrity (ALCOA+), DPDP Act, IT Act 2003 etc.The role will be responsible not only for documentation and audit readiness but also for hands-on deployment of Annex A controls in coordination with the infrastructure, application team & business teams.
1. ISMS Implementation (ISO 27001 + DPDP Act + IT Act 2000 Alignment)
a. Lead end-to-end ISMS deployment aligned with ISO 27001 standards
b. Ensure alignment with DPDP Act, IT ACT 2000 and ALCOA+ principles
c. Integrate ISMS controls QA systems
2. Annex A Controls Deployment (Hands-on)
a. Possess strong practical knowledge of ISO 27001 Annex A controls
b. Drive actual implementation of controls (not just documentation) across IT and business environments
c. Work closely with businesses, business users, infrastructure, and application teams to:
i. Implement access controls, endpoint security, network security, logging & monitoring
ii. Ensure backup, DR, patching, vulnerability management, and hardening practices
iii. Validate effectiveness of controls through testing and periodic reviews
3. Policy, SOP & Documentation Framework
a. Develop and maintain:
i. Information Security Policies
ii. SOPs and Work Instructions
iii. Templates, logs, and records
b. Ensure documentation meets audit expectations
c. Align with Quality Management System (QMS) documentation
4. Audit Readiness & Compliance
a. Prepare for and manage ISO 27001 certification audits (Stage 1 & Stage 2)
b. Support regulatory audits and inspections
c. Ensure timely closure of audit observations and CAPAs
5. Data Integrity & Security Controls
a. Ensure implementation of controls supporting:
i. ISO 27001 ISMS
ii. ALCOA+ principles
iii. Audit trails, electronic records, and traceability
6. Evidence Management & Validation Support
a. Collect and maintain ISMS evidences aligned with audits
b. Support validation lifecycle documentation
c. Ensure controls are documented, implemented, and auditable
7. Cross-functional Collaboration
a. Liaise with:
i. QA/QMS teams for compliance alignment
ii. HCD, QC, Production, R&D teams for system-level controls
iii. IT Infrastructure / Security team for technical implementation
b. Ensure practical deployment of controls, not just theoretical compliance
8. Risk Management & Governance
a. Conduct risk assessments
b. Maintain risk register and mitigation plans
c. Establish governance dashboards and compliance tracking
9. Training & Awareness
a. Drive ISMS and cybersecurity awareness programs
b. Educate users on data integrity, phishing, and secure practices
c. Build a culture of compliance and security ownership
Skills Required
- Experience leading end-to-end ISO 27001 ISMS implementation
- Strong practical knowledge of ISO 27001 Annex A controls
- Hands-on experience implementing access, endpoint, network, logging, monitoring, backup, disaster recovery, patching, vulnerability management, and hardening controls
- Experience developing information security policies, SOPs, work instructions, templates, logs, and records
- Experience preparing for and managing ISO 27001 Stage 1 and Stage 2 certification audits
- Knowledge of GxP, ALCOA+, DPDP Act, IT Act 2000, data integrity, audit trails, electronic records, and traceability
- Experience conducting risk assessments and maintaining risk registers and mitigation plans
- Experience delivering ISMS, cybersecurity awareness, data integrity, phishing, and secure-practice training
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Yashraj Biotechnology Limited develops and manufactures high-purity native and recombinant protein biomarkers for diagnostic applications. Established in 1999, the company also addresses preclinical drug-discovery needs and operates as an emerging contract research organization specializing in preclinical research. Its biotechnology solutions support diagnostic development and related life-science workflows, with operations headquartered in Mumbai and offices in the United States and Germany for international customers.







