Live opening · Posted 11 hours ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
About Taggd
Taggd is a digital recruitment platform that provides Ready-to-Hire talent to India Inc. Combining the power of human knowledge and data, Taggd has successfully fulfilled talent mandates of more than 100+ clients and ensured hiring managers' success for half a million jobs from 14+ sectors. With a vision to fulfil 1 million jobs through our talent platform by 2030, we strive to connect people with people, people with companies, and people with opportunities.
For more information, please visit www.taggd.in.
Role details:
Location: Gurgaon (HQ: M3M Broadway, Sector 71, Gurgaon)
Reports to: CTO
Work mode: 5 days' Work from Office
The role
You own information security, cybersecurity, and GRC for Taggd and group companies, and you are the person enterprise customers talk to when they diligence TARA, Taggd's agentic AI recruitment engine.
You will define the Information Security policies and set the cybersecurity standard (identity, endpoint, network, cloud, logging, incident response). IT runs the estate to the policies & standards. You work with the DPO on privacy, and with Product and Engineering when a customer or auditor asks how TARA handles data, residency, and model use.
More on TARA: https://taggd.in/recruitment-model/tara-ai/
What you will do
Write and run information security policy across Taggd and group companies.
Extend ISO 27001, SOC 2 Type II, and ISO 42001 across Taggd and group companies as needed.
Own DPDP readiness with the DPO.
Lead TARA customer security questionnaires and RFP security responses: data residency, model-training claims, DPDP, and related due diligence.
Build third-party risk management (TPRM) for vendors that touch Taggd and group companies’ data.
Run risk assessments. Keep a live risk register, track remediation, and report to stakeholders.
Own the audit lifecycle for internal, customer, and certification audits: evidence collection, control testing, and response.
Set cybersecurity controls: identity and access, endpoint, network, and cloud. IT implements. You do not run that team.
Own identity and access: access reviews, privileged access, joiners / movers / leavers.
Own vulnerability and patch posture: the standard, the tracking, the exceptions. IT executes.
Own incident response: playbook, severity, who is called, post-incident review.
What you need
10+ years in information security and GRC, including hands-on cybersecurity, not paper GRC only.
Practical depth in at least two of: incident response, identity and access, vulnerability management, cloud security.
ISO 27001 program ownership: you have built an ISMS, not only audited one.
SOC 2 Type II program or evidence work.
Audit lifecycle management: internal and external, including evidence collection and control testing.
Hands-on enterprise customer due diligence: security questionnaires, RFPs, and security reviews.
DPDP (or equivalent privacy law) in a real operating context.
SaaS / multi-tenant product experience.
Comfort speaking with enterprise CISOs and security reviewers.
Based in Gurgaon / NCR, or willing to work from Taggd HQ.
Nice to have
CISA, CISM, CISSP, or CIPP.
Hands-on cloud security (AWS or equivalent).
ISO 42001.
Security review of GenAI or agentic systems.
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.