Manager- ISO 27001 and SOC 2 Audits
6 days ago
Position Summary- The position is a member of Risk & Compliance org within HCL Technologies. The DCO will be aligned to critical service delivery engagements and will be responsible for ensuring compliance in accordance to client, organizational & regulatory security requirements.Key Responsibilities -Perform the following functions: Lead and manage the internal assessment program, ensuring effective facilitation of assessments. Oversee the program's execution and conduct control testing aligned with established frameworks and standards, including ISO 27001, ISO 22301, ISO 27701, SOC 1 & SOC 2. Maintain and update the enterprise risk register, ensuring accuracy and completeness of risk data, and develop consolidated risk views for reporting and analysis. Design and prepare risk dashboards to visualize key metrics and trends, and present comprehensive status reports to senior management as part of the internal risk assessment program Perform assessments of the in-scope facilities against relevant standards such as ISO 27001, ISO 22301, SOC. Collaborate closely with various stakeholders to support the entire certification lifecycle. Engage with relevant stakeholders to manage compliance requirements through awareness initiatives and regular interactions, ensuring users understand and comply with necessary procedures to maintain security. Identify gaps and non-compliances, and work with relevant stakeholders to ensure timely resolution Promote a risk-aware culture throughout the organization. Assist in scoping and develop a calendarized schedule of activities for regular monitoring. Adhere to a defined escalation matrix to manage identified risks. Coordinate and facilitate to third parties for external audits. Stay informed about the latest information security trends and threat landscapes to take proactive measures during assessments. Keep management informed of critical issues that may impact customers, suppliers, or the company. Introduce efficiencies to enhance existing programs. Actively participate in other projects / initiatives as required.Mandatory knowledge or skills - Candidates should possess prior relevant experience in risk and compliance, along with appropriate certifications. Experience in handling ISO 27001, SSAE, and PCI requirements across various industries is preferable. Additional experience with other standards and assessments such as ISO 27701, ISO 42001 and ISO 22301 is advantageous. A foundational understanding of regulatory and statutory compliance is essential. Experience in managing merger and acquisition activities from an information security perspective is desirable. Candidates are expected to have 10 years of relevant experience in information systems audit/assessment and risk management (including risk assessment and remediation). Sound knowledge of management reporting and dashboard creation is required. Proficiency in independently handling projects with strong interpersonal and excellent communication skills is necessary. Candidates should demonstrate strong analytical, Familiarity and experience with managing small to medium initiatives, including timelines, status, interdependency, and risk management, is essential. The candidate should be adept at assisting with the management of stakeholder needs and expectations, providing consistent and regular communications with support from management. The ability to effectively balance multiple tasks through careful prioritization and to work collaboratively with others to produce a quality work product is required. Education Qualification -Bachelor’s Degree - BE/B Tech/B.Sc, Master degree in any domain, preferably in Information Technology or Computer ScienceCertifications Preferred-Security Certifications like CISA/CRISC/ISO27001Attributes of Ideal Candidate – Atleast 10 years’ experience, Relevant or minimum 8-10 years of experience in in the field of ISO 27001 & SSAE 18 /assessment and Risk management (risk assessment and remediation) We are eager to discuss how your leadership skills and vision align with our organizational goals. Thank you once again for your interest in joining HCLTech. Strong analytical, problem solving, organizational, documentation; time management skills. Candidate assists with management of stakeholder needs and expectations while providing consistent and regular communications with support from management Candidate is able to effectively balance multiple tasks through careful prioritization Candidate is able to work collaboratively with others to produce a quality work product Proven ability to communicate with multiple stakeholders Proven ability to manage output from multiple teams Excellent spoken and written English Good Report Writing and Analytical Skills Proficient in MS Office Good in Data Analytics, MIS, Inferences and self-scrutiny for continuous improvement
-
SOC 2 & ISO 27001 Compliance Specialist
2 weeks ago
New Delhi, India Somnetics (Som Imaging Informatics Pvt. Ltd.) Full timeLocation: Kolkata |Mode: Work from Office |Shift: US HoursAbout the RoleWe’re seeking a detail-oriented Information Security & Compliance Specialist to support and strengthen our SOC 2 and ISO 27001 initiatives. The ideal candidate will have hands-on experience in security monitoring, compliance audits, and documentation, ensuring a robust and continuously...
-
SOC 2 & ISO 27001 Compliance Specialist
2 weeks ago
New Delhi, India Somnetics (Som Imaging Informatics Pvt. Ltd.) Full timeLocation: Kolkata |Mode: Work from Office |Shift: US HoursAbout the RoleWe're seeking a detail-oriented Information Security & Compliance Specialist to support and strengthen our SOC 2 and ISO 27001 initiatives. The ideal candidate will have hands-on experience in security monitoring, compliance audits, and documentation, ensuring a robust and continuously...
-
GRC Specialist
5 days ago
New Delhi, India NopalCyber Full timeRole: Advisory(GRC)-L2/L3Location: Hyderabad-WFONumber of roles: 3Experience: 4–6 (L2) years or 5-8 years (L3)Notice Period: Immediate preferred; 30 days.Join NopalCyber’s advisory team to help shape resilient cybersecurity practices for global clients. We're looking for a GRC professional with hands-on experience in SOC 2 (Type 1 & 2), NIST CSF / SP...
-
GRC Specialist
10 hours ago
New Delhi, India NopalCyber Full timeRole: Advisory(GRC)-L2/L3 Location: Hyderabad-WFO Number of roles: 3 Experience: 4–6 (L2) years or 5-8 years (L3) Notice Period: Immediate preferred; 30 days.Join NopalCyber’s advisory team to help shape resilient cybersecurity practices for global clients. We're looking for a GRC professional with hands-on experience inSOC 2 (Type 1 & 2) ,NIST CSF / SP...
-
Iso Auditor- 27001
4 weeks ago
New Delhi, India Whatjobs IN C2 Full timeJob Summary: The ISO Auditor will be responsible for conducting internal audits, ensuring compliance with ISO standards (such as ISO 27001, ISO 9001, and other relevant standards), and supporting the organisation in maintaining certifications. The role involves assessing processes, identifying non- conformities, and recommending improvements to strengthen...
-
We’re Hiring – GRC Consultant
2 days ago
New Delhi, India Matayo Solutions Full timeMatayo AI Solutions Pvt Ltd(Matayo 360° GRC Service Division) is looking for a passionateGRC Consultantto join our fast-growing compliance advisory team. If you live and breatheISO 27001 , can think like anauditor , and love solvingrisk managementpuzzles — we want to meet you!Position: GRC Consultant Location:Hybrid (Bangalore/ Remote – India)...
-
Iso 27001 Auditor
2 weeks ago
New Delhi, India Whatjobs IN C2 Full timeAbout TAC Security: TAC Security is a global leader in cybersecurity risk and vulnerability management. We help enterprises identify, assess, and mitigate security risks through advanced solutions and compliance practices. Role Overview: We are looking for a skilled ISO Auditor to evaluate, implement, and maintain ISO compliance frameworks within the...
-
ISO 27001 Auditor
2 weeks ago
New Delhi, India TAC Security Full timeAbout TAC Security:TAC Security is a global leader in cybersecurity risk and vulnerability management. We help enterprises identify, assess, and mitigate security risks through advanced solutions and compliance practices.Role Overview:We are looking for a skilled ISO Auditor to evaluate, implement, and maintain ISO compliance frameworks within the...
-
ISO 27001 Auditor
3 weeks ago
Delhi, India TAC Security Full timeAbout TAC Security: TAC Security is a global leader in cybersecurity risk and vulnerability management. We help enterprises identify, assess, and mitigate security risks through advanced solutions and compliance practices. Role Overview: We are looking for a skilled ISO Auditor to evaluate, implement, and maintain ISO compliance frameworks within the...
-
ISO 27001 Auditor
3 weeks ago
Delhi, India TAC Security Full timeAbout TAC Security: TAC Security is a global leader in cybersecurity risk and vulnerability management. We help enterprises identify, assess, and mitigate security risks through advanced solutions and compliance practices. Role Overview: We are looking for a skilled ISO Auditor to evaluate, implement, and maintain ISO compliance frameworks within the...