Information Security Consultant
4 days ago
We are seeking a detail-oriented and experienced Senior IT Compliance Associate / Analyst to strengthen our Global IT Compliance team. The ideal candidate will bridge the gap between technical IT operations and regulatory requirements, with a strong focus on ISO27001 and SOC 2 readiness, framework development, and continuous monitoring. They will be responsible for building and maintaining the Information Security framework, managing Information Security and SOC 2 Type 1 & Type 2 audits, and leveraging compliance automation tools such as
Drata
.
Responsibilities
Information Security Framework Development & Strategy
Framework Creation:
Design and implement an enterprise-wide Information Security framework aligned with SOC 2 Trust Service Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy).- Policy Development:
Draft and maintain security policies, standards, and procedures covering access control, incident response, vendor risk management, and data protection. - M&A Integration:
Ensure new entities are seamlessly integrated into the Information Security and compliance framework during mergers and acquisitions. Continuous Improvement:
Establish a roadmap for framework maturity, ensuring scalability and adaptability to evolving compliance requirements.Governance & Documentation Management
Control Mapping:
Develop and maintain Risk and Control Matrices (RACMs) aligned with SOC 2 requirements.- Process Documentation:
Create and update system process flows, control narratives, and evidence repositories. - Inventory Management:
Maintain accurate inventories of in-scope systems, applications, IT projects, and stakeholders. Template Maintenance:
Standardize templates for SOC 2 evidence collection, remediation plans, and monitoring dashboards.SOC 2 Audit Execution & Monitoring
SOC 2 Lifecycle Management:
Lead the preparation, execution, and maintenance of SOC 2 Type 1 & Type 2 audits.- Coordinate with external auditors and internal stakeholders.
- Ensure timely evidence collection and gap remediation.
- Manage readiness assessments and bridge letters.
- Audit Support:
Organize and streamline documentation for ITGC, SOX, and SOC 2 audits. Continuous Monitoring:
Implement automated monitoring of controls using
Drata
, ensuring real-time compliance visibility and reporting.Compliance Automation (Drata) & GRC Tools
Drata Administration:
Configure, manage, and optimize Drata for SOC 2 control monitoring, evidence collection, and audit readiness.- Integration:
Connect Drata with cloud platforms, HR systems, and ticketing tools to automate compliance workflows. GRC Tools:
Support broader governance initiatives using platforms such as ServiceNow GRC or AuditBoard.Training & Awareness
Curriculum Development:
Create training materials focused on SOC 2 compliance, data privacy, and security best practices.- Delivery:
Conduct regular awareness sessions for IT staff and business stakeholders to foster a culture of compliance and security accountability.
Qualifications
- Required:
Bachelor's or master's Degree. - Preferred Discipline:
Information Security, IT Operational Management, Internal Audit, or related fields.
Experience Requirements
- SOC 2 Expertise:
Minimum 5 years of hands-on experience with SOC 2 Type 1 & Type 2 audits, including framework development and evidence management. - Audit Lifecycle:
3–5 years of experience managing IT compliance audits (ISO 27001, SOC, Data Privacy). - Framework Development:
Proven track record of building Information Security frameworks from scratch. - Industry Knowledge:
Preferred experience in Sports, Entertainment, or technology-driven industries. - SDLC Proficiency:
Strong understanding of the System Development Lifecycle (scoping, planning, development, testing, migration, go-live, hypercare).
Skills & Competencies
- Compliance Automation:
Hands-on experience with
Drata
(mandatory), plus familiarity with GRC tools (ServiceNow GRC, AuditBoard). - Technical Tools:
Proficient in Microsoft Excel, Word, and PowerPoint for compliance reporting and visualization. - Communication:
Excellent interpersonal skills to engage cross-functional teams and auditors. - Data Handling:
Skilled in managing highly confidential and sensitive information securely. - Project Management:
Ability to deliver compliance initiatives on time and within budget.
Success Metrics
- Timely completion of ISO 27001, SOC 2 Type 1 & Type 2 audits with zero major findings.
- 100% accuracy in RACM documentation and evidence mapping.
- Continuous monitoring of controls via Drata or
Manual
with automated alerts and dashboards. - Positive feedback from auditors and cross-functional teams on compliance guidance and training.
-
Information Security Consultant
2 days ago
Bengaluru, Karnataka, India Scrut Automation Full timeJob Description: Information Security ConsultantRole DetailsPosition : Information Security ConsultantLocation:BangaloreAbout SCRUT AutomationScrut Automation is an information security and compliance monitoring platform, aimed at helping small and medium cloud-native enterprises develop and maintain a robust security posture, and comply with various infosec...
-
Information Security Consultant
1 week ago
Bengaluru, Karnataka, India endava Full time ₹ 6,00,000 - ₹ 12,00,000 per yearCompany DescriptionTechnology is our how. And people are our why. For over two decades, we have been harnessing technology to drive meaningful change. By combining world-class engineering, industry expertise and a people-centric mindset, we consult and partner with leading brands from various industries to create dynamic platforms and intelligent digital...
-
Information Security Consultant
1 week ago
Bengaluru, Karnataka, India Endava Full time ₹ 12,00,000 - ₹ 36,00,000 per yearCompany Description Technology is our how. And people are our why. For over two decades, we have been harnessing technology to drive meaningful change.By combining world-class engineering, industry expertise and a people-centric mindset, we consult and partner with leading brands from various industries to create dynamic platforms and intelligent digital...
-
Senior Information Security Consultant
2 weeks ago
Bengaluru, Karnataka, India Sprinto Full time ₹ 12,00,000 - ₹ 36,00,000 per yearSprinto is a leading platform that automates information security compliance. By raising the bar on information security, Sprinto ensures compliance, healthy operational practices, and the ability for businesses to grow and scale with unwavering confidence. We are a team of 200+ employees & helping 1000+ Customers across 75+ Countries. We are funded by top...
-
Information Security Officer
4 days ago
Bengaluru, Karnataka, India dentsu Full time ₹ 6,00,000 - ₹ 18,00,000 per yearYou will be responsible for delivering information security initiatives through the region, for ensuring controls and culture are maintained, and for supporting business security requirements, leveraging global and regional capabilities. Led by the APAC CISO, our APAC Security team are responsible for driving global security initiatives across the APAC...
-
Lead – Information Security
4 hours ago
Bengaluru, Karnataka, India Cysigil Full timeRole OverviewWe are seeking an experienced Information Security Consultant – GRC to strengthen our information security posture and ensure compliance with regulatory and client requirements. The role involves handling client RFPs and audits, collaborating with cross-functional teams, and conducting ITGC control testing to maintain security assurance and...
-
Information Security Manager
3 hours ago
Bengaluru, Karnataka, India SandboxSecurity Full timeHiring AlertInformation Security Professional - PCI QSA & Data Privacy ExpertLocation: Remote, IndiaTravel Required: 50%-70%Position Type: PermanentBudget 15-20lpa(slightly negotiable )Experience: Minimum 6 years in Information Security (including at least 3 years as a PCI QSA and Data Privacy Framework Implementation)Certification Required: Current or...
-
Security Consultant
1 week ago
Bengaluru, Karnataka, India Cyberium Labs Private Limited Full timeCompany DescriptionAt Cyberium Labs, we help organizations navigate the complex cybersecurity landscape with confidence. Our mission is to provide not just protection, but strategic guidance and custom-built security solutions. We specialize in strategic cybersecurity consulting, product security advisory, and hands-on training programs designed to empower...
-
Information Security Specialist
1 week ago
Bengaluru, Karnataka, India NTT Ltd. Full time ₹ 20,00,000 - ₹ 25,00,000 per yearMake an impact with NTT DATAJoin a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive. Your day at NTT DATAThe Information...
-
Information Security Analyst
2 weeks ago
Bengaluru, Karnataka, India Exotel Techcom Full time ₹ 12,00,000 - ₹ 24,00,000 per yearAbout Us:Exotel is the emerging market's leading full-stack customer engagement platform and business-focused virtual telecom operator. Incorporated in 2011, Exotel's cloud-based product suite powers 50 million daily engagements across voice, video and messaging channels. Exotel powers unified customer engagement to over 6000 companies in 60+ countries,...