Apply Edge Start your job search

Internal Compliance Specialist

TAC Security · Delhi, India

Apply & track with Apply Edge
. Management System & ISO ExpertiseStrong working knowledge and hands-on implementation experience with:ISO/IEC 27001:2022 – Information Security Management System (ISMS)ISO 9001:2015 – Quality Management System (QMS)ISO/IEC 17025:2017 – Testing & Calibration Laboratory CompetenceISO 27701 – Privacy Information Management SystemISO 22301 – Business Continuity Management SystemISO 31000 – Risk ManagementOther relevant ISO standards and industry-specific compliance frameworks.Must be able to understand the relationship and common requirements across multiple management systems and identify opportunities for an integrated management system.2. Lead Implementer CapabilityShould have hands-on experience leading ISO implementation projects, preferably as a Lead Implementer.Perform initial gap assessments against applicable standards.Develop implementation roadmaps and compliance plans.Establish and maintain management system processes.Define policies, procedures, SOPs, work instructions and control requirements.Define roles, responsibilities and accountability.Maintain required records and documented information.Coordinate implementation activities across different departments.Track implementation milestones and closure of gaps.3. Internal AuditCandidate should be capable of independently planning and conducting internal audits.Responsibilities include:Develop annual/monthly internal audit plans.Prepare audit checklists and audit criteria.Conduct process and control-based audits.Interview process owners and assess implementation/effectiveness.Collect and evaluate objective evidence.Identify:Non-conformitiesObservationsOpportunities for improvementRisksPrepare formal internal audit reports.Track corrective actions to closure.Verify effectiveness of corrective actions.Maintain complete audit records.4. External Audit ManagementShould be comfortable managing certification/accreditation and surveillance audits.Coordinate with external auditors and certification/accreditation bodies.Prepare the organization for Stage 1, Stage 2, surveillance and reassessment audits.Develop audit schedules and coordinate auditor requirements.Manage evidence/document requests.Coordinate responses to auditor queries.Support process owners during audits.Manage NCs and observations raised during external audits.Prepare corrective action plans and supporting evidence.Coordinate NC closure with auditors/assessors.Maintain audit history and lessons learned.For ISO/IEC 17025, experience coordinating with accreditation bodies such as A2LA, NABL, UKAS, etc. would be a strong advantage.5. Compliance & GovernanceStrong understanding of Governance, Risk & Compliance (GRC) principles.Experience with:Compliance frameworksRegulatory requirementsCorporate governanceInternal controlsRisk managementControl ownershipCompliance monitoringException managementRisk acceptanceCorrective/preventive actionsManagement reportingCompliance calendarsGovernance committeesManagement reviewsThe candidate should be able to establish a structured compliance governance program, rather than simply maintaining documentation.6. Risk ManagementConduct organizational and information security risk assessments.Maintain enterprise/process-level risk registers.Identify and evaluate risks.Define risk treatment plans.Track mitigation activities.Evaluate residual risk.Coordinate risk acceptance with management.Periodically review and update risks.Integrate risk management into ISO 27001, ISO 9001 and other management systems.7. Documentation & Management SystemStrong documentation skills with the ability to develop and maintain:PoliciesProceduresSOPsWork instructionsControl matricesRisk registersRisk treatment plansStatements of ApplicabilityQuality manualsProcess documentsInternal audit programsManagement review recordsCorrective action recordsCompliance registersTraining/competency recordsMaster document listsRecords retention requirements8. Corrective Action & Continual ImprovementManage Non-Conformity (NC) lifecycle.Perform root cause analysis.Develop corrective action plans.Identify immediate correction vs. corrective action.Track implementation.Validate objective evidence.Perform effectiveness checks.Identify systemic issues.Drive continual improvement across management systems.9. ISO 17025-Specific KnowledgeFor your requirement, I would make this a key differentiator.Candidate should understand:ImpartialityConfidentialityStructural requirementsResource requirementsPersonnel competenceEquipment managementMetrological traceabilityExternally provided products/servicesReview of requests, tenders and contractsMethod selection, verification and validationSamplingHandling of test/calibration itemsTechnical recordsReportingComplaintsNonconforming workData and information managementManagement system requirementsInternal auditsManagement reviewsCorrective actions10. ISO 9001 / Quality ManagementExperience with:Quality objectives and KPIsProcess mappingQuality risksCustomer requirementsDocument controlChange managementSupplier evaluationNon-conforming outputsCAPACustomer complaintsInternal auditsManagement reviewsContinual improvement11. ISO 27001 / Information Security GovernanceCandidate should understand:ISMS governanceInformation security risk assessmentRisk treatmentStatement of ApplicabilityAnnex A controlsAsset managementAccess controlIncident managementBusiness continuitySupplier securitySecurity awarenessVulnerability managementSecure developmentChange managementLogging and monitoringInternal auditsManagement reviews12. Stakeholder ManagementWork with CTO, CISO, Quality, HR, Legal, Finance, Engineering, Operations and other process owners.Drive compliance ownership across departments.Conduct compliance awareness/training sessions.Present compliance status and risks to senior management.Challenge process owners where controls are not adequately implemented.Coordinate cross-functional corrective actions.13. Compliance Reporting & Governance MetricsShould be able to develop management dashboards covering:Compliance statusOpen/closed NCsAudit findingsCorrective action statusRisk statusPolicy review statusTraining complianceInternal audit completionExternal audit readinessControl effectivenessUpcoming certification/accreditation activities14. Preferred CertificationsStrongly preferred:ISO 27001 Lead ImplementerISO 27001 Lead AuditorISO 9001 Lead Auditor/Lead ImplementerISO/IEC 17025 Internal Auditor / Lead AuditorCISACISMCISSPCRISCAdditional advantage:ISO 27701ISO 22301ISO 31000PCI DSSSOC 2GDPRNIST