Apply Edge Start your job search

Sr. Consultant - Compliance

TAC Security · Delhi, India

Apply & track with Apply Edge
Job Description:Hands-on experience in SOC 2 Type I and Type II implementation/readiness and delivery.Strong understanding of AICPA Trust Services Criteria (TSC).Experience with control mapping, gap assessments, evidence collection and validation.Understanding of Type II observation periods, control operating effectiveness and exceptions.Experience coordinating with external auditors/CPA firms.Ability to manage SOC 2 engagements from kickoff through audit closure.2. ISO 27001 ExpertiseStrong understanding of ISO/IEC 27001:2022 requirements.Experience implementing and maintaining an Information Security Management System (ISMS).Conducting ISO 27001 gap assessments and readiness assessments.Understanding of Annex A controls and applicability assessment.Experience with:Risk assessment and risk treatmentStatement of Applicability (SoA)Information security policies and proceduresInternal auditsManagement reviewsCorrective actions / NC managementContinual improvementISMS metrics and monitoringExperience supporting organizations through ISO 27001 certification audits.Understanding of Stage 1 and Stage 2 audit processes.3. Governance, Risk & Compliance (GRC)Strong understanding of GRC frameworks and principles.Ability to establish and maintain governance processes.Experience with:Risk managementControl frameworksCompliance assessmentsRegulatory requirementsPolicy governanceException managementRisk acceptanceCorrective and preventive actionsCompliance monitoringAbility to map controls across multiple frameworks such as SOC 2, ISO 27001, PCI DSS, GDPR, HIPAA, etc.4. Compliance & Audit ManagementManage internal and external compliance assessments.Prepare organizations for certification and attestation audits.Develop audit plans, evidence trackers and compliance calendars.Review audit evidence for completeness and adequacy.Manage audit observations, non-conformities and corrective actions.Coordinate with auditors and stakeholders to resolve audit queries.Maintain appropriate audit trails and compliance documentation.5. Risk ManagementConduct information security risk assessments.Identify, assess and prioritize organizational risks.Develop Risk Treatment Plans (RTPs).Maintain risk registers.Evaluate residual risk and risk acceptance.Support business owners in implementing appropriate risk mitigation measures.6. Policies & DocumentationCandidate should be comfortable creating/reviewing:Information Security PolicyISMS documentationRisk Management PolicyAccess Control PolicyIncident Management PolicyBusiness Continuity/DR policiesVendor Risk Management PolicyChange Management PolicySecure SDLC policiesData Protection/Privacy policiesBusiness Continuity documentationControl procedures and work instructions7. Client & Stakeholder ManagementConduct client discovery and kickoff meetings.Understand business processes, technology environments and compliance requirements.Act as the primary delivery contact for clients.Conduct regular status meetings.Track milestones, dependencies, risks and deliverables.Communicate compliance requirements clearly to technical and non-technical stakeholders.Manage escalations and ensure timely closure of deliverables.8. Technical Security UnderstandingCandidate should have a good working understanding of:AWS / Azure / GCPIAM, SSO and MFAVulnerability managementSecure SDLCChange managementIncident responseLogging and monitoringEncryptionBackup and DREndpoint securityNetwork securityAsset managementVendor/third-party securityData protectionThey don't need to be a penetration tester or security engineer, but should be able to understand technical controls and assess their compliance implications.Key SkillsMust Have:SOC 2 Type I/IIISO 27001:2022ISMS implementationGRCRisk assessment & treatmentControl assessmentAudit managementEvidence reviewCompliance managementPolicy/procedure developmentClient managementStrong documentation and communication skillsGood to Have:CISA / CISSP / CRISCISO 27001 Lead Auditor / Lead ImplementerISO 27701PCI DSSHIPAAGDPRNIST CSF / NIST 800-53CSA CCMExperience with GRC platforms such as Vanta, Drata, Secureframe, OneTrust, etc.