ISO Consultant (Part Time)

Karma CPA

Gujarat

On-site

INR 1,000,000 - 1,500,000

Part time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Karma CPA in India is seeking a part-time independent consultant to enhance their IT and security posture to meet audit-grade standards. The role focuses on building and certifying an ISMS according to ISO/IEC 27001:2022 and mentoring in-house IT engineers for long-term sustainability.

Applicants must have over 8 years of experience in information security, relevant certifications, and a strong track record of ISMS implementation. This role is a unique opportunity for professionals seeking to make a significant impact in a dynamic environment.

Qualifications

  • 8+ years in IT/information security with hands-on ISMS implementation experience.
  • Strong technical depth in IAM, endpoint/network security, logging, and backup/DR.
  • Experience in BPO/KPO/ITES or financial services handling third-party client data.

Responsibilities

  • Diagnose current IT/security posture against ISO 27001:2022 and identify real gaps.
  • Build a certifiable ISMS — scope, risk assessment, Statement of Applicability, policies.
  • Mentor two in-house IT engineers to independently operate and maintain the ISMS.

Skills

ISO/IEC 27001:2022 Implementation
IT Security Management
Mentorship
Technical Depth in IAM
BPO/KPO/ITES Experience

Education

ISO/IEC 27001:2022 Lead Implementer/Auditor Certification
CISM / CISA / CISSP

Job description

Karma Global Solutions (a ~150-person accounting/back-office firm serving US CPA and property-management companies) is hiring a part-time/retainer independent consultant to raise their IT and security posture to audit-grade standard, build and certify an ISMS aligned to ISO/IEC 27001:2022, and upskill in-house IT engineers for long‑term sustainability. It's explicitly a build‑and‑transfer role — not a paperwork/template exercise.

2. Mandate / Objectives

Five core objectives:

  • Diagnose current IT/security posture against ISO 27001:2022 (Annex A controls) and identify real gaps
  • Build a certifiable ISMS — scope, risk assessment, Statement of Applicability, policies, and technical controls
  • Harden actual infrastructure (identity, access, endpoints, network, remote access, logging, backup/DR)
  • Mentor two in-house IT engineers to independently operate and maintain the ISMS
  • Drive certification through Stage 1 and Stage 2 audits with zero major non-conformities

Broken into four areas:

  • A. Assessment & Strategy — Gap assessment, asset inventory, risk assessment, ISMS scope, and Statement of Applicability
  • B. Implementation — Author core policies (access control, incident response, DR, vendor management, etc.) and implement technical controls (MFA, EDR, network segmentation, logging, encryption, DLP, etc.)
  • C. Governance & Audit Readiness — Internal audit programme, management reviews, vendor due diligence, certification body management
  • D. Capability Building — Hands‑on IT engineer mentoring, company‑wide security awareness training, and leaving behind runbooks/SOPs
4. Required Qualifications

Mandatory:

  • 8+ years in IT/information security with hands‑on ISMS implementation experience
  • ISO/IEC 27001:2022 Lead Implementer and/or Lead Auditor certification
  • Personally taken at least one organisation end‑to‑end through ISO 27001 certification (references required)
  • Strong technical depth in IAM, endpoint/network security, logging, and backup/DR
  • BPO/KPO/ITES or financial services experience handling third‑party client data
Strongly Preferred:
  • CISM / CISA / CISSP
  • SOC 2 Type II readiness experience
  • Exposure to US-client delivery environments and US data‑privacy expectations
  • Familiarity with cloud and self-hosted infrastructure tooling
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Manager
Information Security Manager

Altraize • Mumbai

On-site
Deputy General Manager-GRC
Deputy General Manager-GRC

SupportFinity™ • Ahmedabad District

On-site
INR 1,200,000 - 2,000,000
IT Security & ISO Implementation Support Engineer
IT Security & ISO Implementation Support Engineer

PrivacyPillar Inc. • Gurgaon

On-site
INR 600,000 - 900,000
GAIN Central IT - Information Security Manager
GAIN Central IT - Information Security Manager

GAIN • Maharashtra

On-site
INR 1,000,000 - 1,500,000
ISO 27001 Auditior
ISO 27001 Auditior

TAC Security • Delhi

On-site
INR 1,200,000 - 2,400,000
ISO Auditor- 27001
ISO Auditor- 27001

TAC Security • Delhi

On-site
INR 700,000 - 900,000
Technical Architect
Technical Architect

ESP Engineered • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Compliance Associate - ISO 27001 Implementation
Compliance Associate - ISO 27001 Implementation

IAMOPS | Growth Fanatics DevOps • Pune District

On-site
INR 800,000 - 1,400,000
Senior Manager – IT Governance
Senior Manager – IT Governance

Concept Medical Inc. • Surat

On-site
INR 2,500,000 - 4,500,000
Serious Delivery Manager (ISO 27001, SOC 2 & IT Security)
Serious Delivery Manager (ISO 27001, SOC 2 & IT Security)

hotsourced • India

On-site
INR 2,800,000 - 3,500,000