Key Responsibilities
- Provide end-to-end support for ISO 27001:2013/ISO 27001:2022 implementation and compliance activities.
- Support Internal and External ISO 27001 Audits, including preparation of compliance documentation, audit evidence, and stakeholder coordination.
- Act as the primary liaison between auditors and client stakeholders to ensure smooth audit execution and timely closure of audit observations.
- Provide Empanelled Audit Support, ensuring end-to-end involvement throughout the audit lifecycle until successful compliance closure.
- Coordinate and support Third-Party Security Audits, including audit planning, evidence collection, stakeholder communication, and remediation tracking.
- Track audit findings, compliance gaps, and corrective actions, ensuring timely closure and reporting.
- Develop, review, and maintain Information Security Policies, Standards, Procedures, Guidelines, and SOPs.
- Perform compliance assessments and gap analysis against security frameworks and recommend remediation measures.
- Support Governance, Risk, and Compliance (GRC) initiatives aligned with business and regulatory requirements.
- Plan, coordinate, and conduct Disaster Recovery (DR) Drills, document test results, identify gaps, and monitor closure of improvement actions.
- Collaborate with business, IT, and security teams to ensure compliance with organizational security objectives.
- Prepare audit reports, compliance dashboards, management presentations, and governance metrics.
Required Skills
- Strong understanding of ISO 27001:2013/ISO 27001:2022 Information Security Management System (ISMS).
- Experience supporting Internal, External, and Third-Party Security Audits.
- Knowledge of Information Security Governance, Risk Management, and Compliance processes.
- Good understanding of the following compliance and security frameworks:
- ISO 27001
- NIST Cybersecurity Framework
- IT General Controls (ITGC)
- Data Privacy and Data Protection regulations
- Business Continuity Management (BCM) and Disaster Recovery (DR)
- Experience in audit documentation, evidence management, compliance reporting, and issue tracking.
- Strong documentation, analytical, communication, and stakeholder management skills.
- Ability to manage multiple audits and governance activities simultaneously.
Preferred Qualifications
- ISO 27001 Lead Implementer or Lead Auditor Certification.
Pay: ₹700,000.00 - ₹800,000.00 per year
Work Location: In person