Skip to content
← Back to job listings

Manager - Information Security Governance and Compliance

Hand Protection · Sri Lanka

Corporate LawImported listingfull-time7 days ago

About The Role

JOB ACCOUNTABILITIES

  • Evaluate the Group’s security posture of existing and proposed applications, infrastructure, and technology solutions for Information Security, risk management, and regulatory compliance.
  • Maintain and continuously improve the Group ISMS framework to ensure regulatory and organizational compliance.
  • Lead governance and coordination of information security projects with service providers, consultants, auditors, and certification bodies, ensuring compliance with Group requirements, regulatory obligations, and certification standards.
  • Govern and coordinate Hayleys and Advantis Group’s ICT Compliance requirements across Advantis SBUs through assessments, evidence validation, remediation monitoring, and compliance reporting.
  • Assist in facilitating personal data protection compliance and DPMP activities across Hayleys Advantis SBUs by coordinating with the Sector Data Protection Lead and stakeholders.
  • Represent Hayleys Advantis at the Hayleys Group IT Security Cluster Forum and ensure implementation of Group Information Security strategies, standards, guidelines, and directives across the Advantis Group.
  • Lead and coordinate Information Security Awareness across Hayleys Advantis through awareness initiatives, training programmes, phishing simulations, and security communications to strengthen employee awareness, promote a positive security culture, and support compliance.
  • Monitor and coordinate Information Security controls, vulnerability and incident management, business continuity and disaster recovery, third-party security risk management, and security performance reporting across Hayleys Advantis entities to ensure compliance and timely risk mitigation.
  • Assist in facilitating personal data protection compliance and DPMP-related activities across Hayleys Advantis SBUs by coordinating with SBU Data Protection Coordinators, tracking progress, and supporting management and Hayleys Group DPO reports and submissions.

MINIMUM KNOWLEDGE/ EXPERIENCE / TRAINING / QUALIFICATIONS REQUIRED FOR POSITION

  • Bachelor’s degree in information security approved by UGC or a UGC-recognized equivalent professional qualification.
  • Professional certifications in Information Security, Audit, Risk, Compliance, or Protection will be an added advantage (Eg: CISA, CISM, CISSP, other related)
  • Minimum 3-5 years of experience in Information Security, IT Governance, IT Audit, Risk Management, or Compliance.
  • Experience in ISO 27001 or Information Security Governance and coordination activities.
  • Experience preparing reports, dashboards, and compliance documentation.
  • Experience coordinating ISO 27001 certification and audit activities.
  • Experience managing enterprise compliance programs across multiple business entities.
  • Experience engaging senior stakeholders and managing governance initiatives.
  • Exposure to PDPA, privacy compliance, or regulatory compliance initiatives.
  • Strong knowledge of Information Security Governance, Risk Management, and policy development.
  • Strong documentation skills with the ability to manage multiple compliance initiatives simultaneously.
  • High attention to detail, follow-through, and strong coordination skills.
  • If you think you have what it takes to be successful in this challenging role, please “Click Here” to apply.
  • Pay and benefits of the above position will be competitive, and the rewards are performance driven
  • Hayleys is an Equal Opportunity Employer.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing