KOCHI · FULLTIME
Cyber Security Manager

PracticeSuite
Kochi · onsite · Posted today
Your match
Sign in to see your match score, skill gaps & tailored resume.
Section · 01
About this role
Cyber Security Manager Location: Kochi, Kerala, India Department: Information Technology / Security Employment Type: Full-Time Work Location: On-Site Shift: 5:30pm to 2:30am IST Reports To: Head of Engineering
About PracticeSuite PracticeSuite is a healthcare technology company providing cloud-based Electronic Health Record (EHR), Practice Management, Revenue Cycle Management (RCM), and related healthcare technology solutions. Our platforms support healthcare providers and organizations across the United States. As we continue to scale, cybersecurity, information security, data protection, and regulatory compliance are critical to protecting our customers, systems, employees, and business operations.
Position Summary PracticeSuite is seeking an experienced Cyber Security Manager to lead and strengthen the company's cybersecurity program from our Kochi, India operations. The Cyber Security Manager will be responsible for protecting PracticeSuite's applications, infrastructure, networks, endpoints, cloud environments, and sensitive healthcare and business data. This role will oversee security operations, vulnerability management, incident response, security monitoring, access controls, risk management, and cybersecurity compliance. The successful candidate will work closely with Engineering, Infrastructure, DevOps, Product, Compliance, HR, and senior leadership to identify security risks and implement practical controls that protect the organization without unnecessarily impacting business operations. This is a hands-on leadership role for a cybersecurity professional who can build processes, investigate threats, manage incidents, drive remediation, and hold technical teams accountable for security standards.
Key Responsibilities Cybersecurity Operations - Manage and continuously improve PracticeSuite's overall cybersecurity program. - Establish and maintain security policies, procedures, standards, and technical controls. - Monitor the organization's security posture across applications, infrastructure, endpoints, networks, and cloud environments. - Identify emerging cybersecurity threats and recommend appropriate defensive measures. - Establish security metrics and reporting for management. Security Monitoring & Incident Response - Lead the detection, investigation, containment, and remediation of cybersecurity incidents. - Develop and maintain an incident response process and playbooks. - Coordinate security investigations involving malware, phishing, unauthorized access, data exposure, credential compromise, and other security events. - Work with IT and Engineering teams to contain and remediate security incidents. - Conduct post-incident reviews and implement corrective actions. - Coordinate with external security vendors, SOC/MSSP providers, and other third parties when required. Vulnerability & Risk Management - Own the organization's vulnerability management program. - Coordinate vulnerability scanning, penetration testing, application security assessments, and remediation activities. - Prioritize vulnerabilities based on business impact, exploitability, and risk. - Track remediation activities and ensure security issues are resolved within defined timelines. - Perform security risk assessments for systems, applications, vendors, and infrastructure. - Maintain a cybersecurity risk register and provide regular reporting to leadership. Application & Cloud Security - Partner with Engineering and DevOps teams to integrate security throughout the software development lifecycle. - Review application architecture and infrastructure designs for security risks. - Promote secure coding practices and application security testing. - Support implementation of SAST, DAST, dependency scanning, container security, secrets management, and related security controls. - Evaluate cloud environments and ensure appropriate identity, network, encryption, logging, and access controls are implemented. - Participate in security reviews for new products, integrations, APIs, and third-party services. Identity & Access Management - Establish and enforce appropriate access-control standards. - Support implementation of least-privilege and role-based access controls. - Monitor privileged accounts and administrative access. - Coordinate periodic access reviews and user-access certification. - Work with IT/HR to ensure timely provisioning and deprovisioning of employee access. - Strengthen authentication and MFA controls across the organization. Compliance & Security Audits - Support PracticeSuite's cybersecurity and information-security compliance initiatives. - Work closely with Compliance and leadership on SOC 2, security assessments, customer audits, and other applicable frameworks. - Maintain evidence and documentation required for internal and external audits. - Support remediation of audit findings and security control deficiencies. - Assist with customer security questionnaires and technical security assessments. - Maintain security documentation, policies, procedures, risk assessments, and control evidence. Security Awareness - Develop and deliver cybersecurity awareness and training programs for employees. - Promote security-conscious behavior throughout the organization. - Conduct phishing simulations and security awareness exercises where appropriate. - Establish processes for reporting suspicious emails, security incidents, and potential security violations. Third-Party & Vendor Security - Participate in security assessments of third-party vendors and technology partners. - Review vendor security documentation, certifications, and security controls. - Identify and communicate risks associated with third-party integrations and services. - Support ongoing monitoring of critical vendors. Business Continuity & Disaster Recovery - Partner with IT and Engineering to evaluate cybersecurity aspects of business continuity and disaster recovery plans. - Ensure critical systems have appropriate backup, recovery, and security controls. - Participate in disaster recovery and security incident exercises. Leadership & Collaboration - Serve as the cybersecurity subject-matter expert for PracticeSuite. - Establish clear security ownership and accountability across technical teams. - Work closely with Engineering, DevOps, Infrastructure, Product, Compliance, HR, and executive leadership. - Communicate complex security risks clearly to both technical and non-technical stakeholders. - Challenge decisions when security risks are not adequately addressed. - Build a culture of security, accountability, and continuous improvement.
Required Qualifications - Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Security, or a related field. - 6+ years of professional experience in cybersecurity, information security, or a closely related field. - At least 2–3 years of experience in a cybersecurity leadership, management, or senior security engineering role. - Strong understanding of security architecture, network security, endpoint security, cloud security, and application security. - Hands-on experience with vulnerability management and security assessments. - Strong experience with incident response and security investigations. - Experience implementing and managing security controls in a technology/SaaS environment. - Experience working with security monitoring, SIEM, EDR/XDR, vulnerability scanners, and related security technologies. - Strong understanding of IAM, MFA, privileged access, encryption, logging, and access controls. - Experience supporting SOC 2 or similar security/compliance frameworks. - Strong knowledge of security best practices and frameworks such as NIST CSF, CIS Controls, ISO 27001, and OWASP. - Strong analytical, problem-solving, and communication skills. - Experience in a healthcare technology, SaaS, EHR, RCM, or other regulated technology environment. - Experience protecting PHI/PII and other sensitive healthcare data. - Experience with HIPAA security requirements. - Experience with cloud platforms such as AWS, Azure, or GCP. - Experience with DevSecOps and CI/CD security. - Experience managing or working with an external SOC/MSSP. - Experience with penetration testing and remediation management. - Experience with security automation and scripting. - Experience responding to customer security questionnaires and enterprise security reviews. - Experience preparing organizations for SOC 2 audits.
Certifications One or more of the following certifications is preferred: - CISSP - CISM - CEH - Security+ - CCSP - GIAC certifications - ISO 27001 Lead Implementer / Lead Auditor - Other recognized cybersecurity certifications Certifications are preferred but not mandatory when the candidate demonstrates strong practical cybersecurity experience.
Technical Skills The candidate should have practical experience with several of the following: - SIEM platforms - EDR/XDR solutions - Vulnerability management platforms - Firewalls and network security - IDS/IPS - IAM and PAM - MFA - Endpoint security - Cloud security - Application security - SAST/DAST - API security - Penetration testing - Security logging and monitoring - Encryption and key management - Security automation - Incident response platforms - Microsoft security ecosystem - Linux and Windows security - AWS/Azure/GCP security controls - Security assessment and GRC platforms
Key Performance Indicators Success in this position will be measured through: - Reduction in critical and high-risk vulnerabilities. - Timely remediation of identified security issues. - Improved security monitoring and incident detection capabilities. - Effective response and resolution of security incidents. - Successful completion of security audits and assessments. - Improvement in SOC 2 and other security-control maturity. - Security awareness and training completion. - Improved access-control and privileged-access management. - Reduction of security risks across applications, infrastructure, and third-party vendors. - Implementation of measurable cybersecurity improvements across the organization.
Sourced from linkedin · view original
Let the agent run this one for you.
Tailored resume, auto-apply, and referral lookup — in under 2 minutes.
Section · 02
Skills
Section · Company
About PracticeSuite

PracticeSuite
IT Services & Consulting
51-200
employees
2004
22 years old
Tampa, Florida
headquarters
₹7.2L PA avg
Avg at PracticeSuite
About
Industries
Employee ratings
10 reviews
Culture
2.4
Career growth
1.5
Work-life
3.5
Employees rate it well for
Find them on