Home › HRMS › Job roles › Information Technology › IT Security Manager
Information Technology · Manager

IT Security Manager job description

An IT Security Manager runs a company's day-to-day security programme: vulnerability management, access reviews, security monitoring, incident response, awareness training and audit readiness. They manage security analysts and engineers, push IT and engineering teams to close findings, and keep policies aligned with ISO 27001 and client or regulator requirements. In Indian IT firms, banks, NBFCs, hospitals and BPOs the role reports to the CISO or IT Head. A good IT Security Manager keeps findings closing faster than they open and handles incidents without panic.

DetailFor this role
DepartmentInformation Technology
LevelManager
Reports toChief Information Security Officer
Direct reportsSecurity Analyst, SOC Analyst, Cyber Security Engineer, Firewall Engineer
Experience8 to 12 years in IT security, with 3 or more years leading a security operations or compliance team

IT Security Manager job description template

Copy this job description, replace the text in square brackets and post it on your careers page or a job portal.

Job title: IT Security Manager

Department: Information Technology

Reports to: Chief Information Security Officer

Location: [City], [office, branch or site]

About the role

An IT Security Manager runs a company's day-to-day security programme: vulnerability management, access reviews, security monitoring, incident response, awareness training and audit readiness. They manage security analysts and engineers, push IT and engineering teams to close findings, and keep policies aligned with ISO 27001 and client or regulator requirements. In Indian IT firms, banks, NBFCs, hospitals and BPOs the role reports to the CISO or IT Head. A good IT Security Manager keeps findings closing faster than they open and handles incidents without panic.

Key responsibilities

  • Run the vulnerability management cycle: monthly scans, risk rating, assignment to IT owners and follow-up until closure.
  • Oversee security monitoring by the SOC or a managed security provider, and review alert quality and missed detections.
  • Lead incident response for phishing, malware, data leaks and account compromise, covering containment, evidence and reporting to management.
  • Run quarterly user access reviews for critical systems with application owners, and remove access that is no longer needed.
  • Keep security policies and procedures aligned with ISO 27001, and get them reviewed and approved every year.
  • Plan security awareness training and phishing simulations for all staff, including every batch of new joiners.
  • Prepare for internal, ISO 27001, client and regulator audits, collect evidence and track findings to closure.
  • Manage security tools and vendors, such as endpoint protection, email security, SIEM and firewall support contracts.
  • Report security metrics and the top risks to the CISO or IT head every month.
  • Guide security analysts and engineers, plan monitoring shift cover and build their skills.

Requirements

  • B.E., B.Tech, B.Sc IT or MCA
  • CISM, CISSP or ISO 27001 Lead Implementer certification
  • CEH or CompTIA Security+ is an advantage
  • 8 to 12 years in IT security, with 3 or more years leading a security operations or compliance team

KRAs and KPIs for a IT Security Manager

Key result areas for the appraisal form, each with a KPI you can measure every month or quarter.

Key result areaHow to measure it
Vulnerability closureCritical vulnerabilities closed within 15 days and high ones within 30 days of detection
Incident responseSecurity incidents contained within 4 hours of detection, with a written report within 3 working days
Access reviewsQuarterly access review completed for every critical system, with removals done within 5 working days
Security awarenessPhishing simulation click rate lower each quarter, and every employee trained once a year
Audit resultsNo major non-conformity in ISO 27001 or client security audits
Endpoint coverageEndpoint protection active on at least 98 percent of company devices

Skills and tools

Vulnerability managementSecurity incident responseISO 27001 ISMSSIEM and SOC operationsIdentity and access reviewsEndpoint and email securitySecurity awareness programmesAudit handlingTeam leadershipCalm communication in incidents

Tools used day to day: Splunk, QRadar or Microsoft Sentinel, Qualys, Nessus or Rapid7, CrowdStrike or Microsoft Defender, Microsoft 365 security portal, KnowBe4 or another phishing simulation tool, GRC tool or Excel risk register.

Reporting line and career path

Chief InformationSecurity OfficerIT Security ManagerSecurity AnalystSOC AnalystCyber SecurityEngineerFirewall Engineer

Interview questions for a IT Security Manager

  1. An employee's mailbox is sending phishing emails to clients. Walk me through your first hour.
  2. How do you get IT teams to close vulnerabilities when they say there is no downtime window?
  3. What evidence do you prepare for an ISO 27001 surveillance audit?
  4. Your phishing simulation click rate has stopped improving. What would you change?
  5. Which alerts should the SOC escalate to you at night, and which can wait?
  6. Tell me about a security incident you handled and what you changed afterwards.

Managing a IT Security Manager in ZeniaHR

Hire and manage your information technology team in one place

Post the role, onboard the new hire, and track attendance, leave and KRAs in ZeniaHR. Free for your first 50 employees.

Book a free demoSee pricing

Frequently asked questions

What does an IT security manager do?

An IT security manager runs a company's everyday security work. They manage vulnerability scanning and fixes, oversee monitoring and incident response, run access reviews and awareness training, maintain security policies and prepare for ISO 27001 and client audits. They lead the security analysts and engineers and report risks to the CISO or IT head.

What is the difference between an IT security manager and a CISO?

The CISO sets security strategy, owns security risk at leadership level and reports to the CEO or board. The IT security manager runs the programme day to day: scans, incidents, access reviews, training and audits. In mid-sized companies without a CISO, the IT security manager often reports to the IT head and covers both jobs.

Which certifications are best for an IT security manager?

CISM suits the management side of the role and CISSP covers broad security knowledge, and both are widely recognized in India. ISO 27001 Lead Implementer or Lead Auditor helps where audits are frequent. Hands-on certifications such as CEH or Security+ are useful earlier in the career.