Join KDK Software as an IT Compliance Officer and play a key role in ensuring our products, systems, and infrastructure meet the highest standards of Information Security and regulatory compliance.
In this role, you will drive compliance initiatives related to SOC 2, ISO 27001, VAPT, and other industry standards while helping strengthen our security posture and maintain customer trust. You will collaborate with IT, Development, QA, Product, and Operations teams to implement, audit, and continuously improve compliance controls across the organization.
If you have a strong understanding of Data Protection, Risk Management, IT Governance, and Information Security within a Software Product or SaaS environment, this is an opportunity to contribute to a growing technology organization and make a meaningful impact on its governance and compliance framework.
- Develop, implement, and monitor the organization's IT compliance framework in line with SOC 2, ISO 27001, GDPR, and other regulatory standards.
- Coordinate internal and external Information Security Audits and ensure timely closure of non-conformities.
- Lead and support Vulnerability Assessment and Penetration Testing (VAPT) initiatives, ensuring identified gaps are remediated effectively.
- Collaborate with internal stakeholders to maintain and update IT Security Policies, SOPs, and Risk Registers.
- Conduct regular Risk Assessments, identify control weaknesses, and recommend mitigation measures.
- Ensure adherence to Data Protection, Access Control, and Incident Response best practices.
- Manage documentation and evidence collection for compliance certifications and renewals.
- Provide training and awareness sessions to teams on IT Compliance and Data Security practices.
- Stay updated on changes in compliance requirements and cybersecurity trends to ensure continued alignment with global standards.
Desired Candidate Profile
Must Have
- Minimum 5 years of experience in IT Compliance, Information Security, or Audit roles (preferably in a SaaS or Software Product company).
- Working knowledge of SOC 2, ISO 27001, and ITGC frameworks.
- Hands-on experience managing VAPT processes, Risk Assessments, and Compliance Audits.
- Familiarity with Security Tools, Documentation Standards, and Audit Methodologies.
- Strong analytical, documentation, and communication skills.
- Excellent troubleshooting, communication, documentation, problem-solving, and collaboration skills.
Preferred
- Understanding of Six Sigma Protocols.
- Relevant certifications such as ISO 27001 Lead Auditor, CISA, CISM, or CompTIA Security+ will be an added advantage.
Pay: ₹700,000.00 - ₹1,008,727.88 per year
Benefits:
Work Location: In person