GRC Consultant – (Azpirantz)

InfosecTrain A Brand of AZPIRANTZ TECHNOLOGIES LLP

Ernakulam

On-site

INR 1,200,000 - 1,800,000

Full time

25 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

InfosecTrain A Brand of AZPIRANTZ TECHNOLOGIES LLP is seeking a security consultant experienced in information security, business continuity and data privacy management systems. You will lead consulting engagements, assess current controls, and help clients implement policies aligned to ISO27001/ISOs and other standards.

Strong communication, project management, and the ability to translate business requirements into technical IT security deliverables are essential.

Qualifications

  • Extensive experience with ISO 27001 and ISO 27002 standards.
  • Accreditations/Certifications e.g. ISO 27001 LA/LI, ISO 22301 LA/LI, CISA, CISSP, PMP, CASP, CRISC, CCSK.
  • Strong ability to define and implement security processes across departments and stakeholders.
  • Experience with application security controls, monitoring, SIEM, and network/server security.

Responsibilities

  • Consult on information security, business continuity, data privacy, and related management systems.
  • Lead AS-IS assessments, gap analyses, and recommendations.
  • Develop, implement policies, processes, and procedures aligned to standards.
  • Advise on standards, methods, tools, and technologies for business benefits.
  • Produce technical reports, risk assessments, and client-ready deliverables.

Skills

Client facing
Pres-sales
Project management
Technical report writing
Security risk assessments

Education

Degree in Computer Science or Engineering
Master's degree desirable
Certifications: ISO 27001 LA/LI, ISO 22301 LA/LI, CISA, CISSP, PMP, CASP, CRISC, CCSK

Job description

Key Pre-requisites:

Knowledge in Information Security, Business Continuity, IT Service Management & IT Governance & Strategy
Desired Certification: CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), ISO 27001 Lead Auditor, or similar

Job Description:

The consultant shall be responsible for consulting engagements for the information security, business continuity, data privacy, and similar management systems service offerings. The role requires a strong background in Information Security, ISO 27000, ISO22301, ISO 27701, and similar standards and frameworks.
The role requires broad high level technical knowledge and the ability to recommend advisory solutions based on customer business problems or requirements.
Influencing organization, customers, suppliers, partners and peers in areas of expertise.
Advising on the available standards, methods, tools and technologies relevant to area of expertise and how business benefits can be realized.
Lead customer through consulting engagements by assembling information to determine, document and agree customer requirements, conducting AS-IS assessment in line with applicable standards and frameworks, conducting gap analysis and producing recommendations.
Defining, developing, and implementing policies, processes, and procedures aligned to standards, and frameworks.
Developing templates, guidelines and other job aids to use the implemented policies, processes and procedures.
Assessing and formulating tool requirements to execute the processes and ensuring that all the processes are institutionalized within the customer environment.
Conducting periodic compliance audits / assessments against defined processes and various compliance frameworks such as CIS, NIST, ISO 31000, ISO 22301, and ISO27000 series.
Reporting, ensuring and facilitating closure of all non-conformities by driving/initiating corrective actions within the customer environment.
Developing Metrics/KPIs and performing data collection related to the processes deployed, driving analysis and improvements based on recommendations
Contributing to internal best practices, processes and methodology documents pertaining to areas of specialization.

Key Personal Attributes:
  • Client facing experience is a must.
  • Pres-sales and delivery experience is a must.
  • Interpersonal skills to interact in a team environment and foster client relationships.
  • Ability to communicate technical risk issues effectively, to customers who may, at times, have a nontechnical background.
  • Ability to write technical reports, detailed presentations and documentation.
  • Demonstrable understanding of the importance of business ethics.
  • Must be able to handle highly confidential information in a strictly professional manner.
  • Must be able to maintain professional demeanor in times of high stress.
  • Open to travel as per the job requirements. It would depend upon the assignment as well.
  • Project management skills and an ability to translate business requirements into technical IT security deliverables.
Qualification and Skills:
  • Extensive experience with ISO 27001 and ISO 27002 standards.
  • Degree in Computer Science or Engineering (Master Degree is desirable).
  • Accreditations/Certifications e.g. ISO 27001 LA/LI, ISO 22301 LA/LI, CISA,CISSP, PMP, CompTIA CASP, CRISC, CCSK.
  • Extensive experience with performing security risk assessments.
  • Ability to define and implement security processes across different departments and work with different stakeholders.
  • Experience with Application Security controls, tools and processes.
  • Experience with security monitoring and SIEM solutions.
  • Experience with network, endpoint, server security.
  • Familiar with common security vulnerabilities and mitigating techniques.
  • Familiar with EU regulatory requirements as well as other relevant international security standards.
  • Strong IT technical knowledge.
  • Excellent communication skills - both written and verbal.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Consultant – Information Security
GRC Consultant – Information Security

Infosec Train • Thiruvananthapuram

Hybrid
INR 406,000 - 487,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000
GRC/Information Security Analyst
GRC/Information Security Analyst

Synclature Consultancy Pvt. Ltd. • Mumbai

On-site
INR 300,000 - 600,000
Grc Consultant
Grc Consultant

Indrasol • Hyderabad

On-site
INR 1,200,000 - 1,800,000
GRC Solution Consultant
GRC Solution Consultant

LTM • Dadri

On-site
INR 3,000,000 - 5,500,000
Business Continuity Manager @ Mumbai
Business Continuity Manager @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,400,000 - 2,000,000
Senior Consultant - GRC L3 | Experience: 6-8 Years
Senior Consultant - GRC L3 | Experience: 6-8 Years

Aujas Networks Pvt. Ltd. • Mumbai

On-site
INR 800,000 - 1,500,000
Cyber Security GRC Consultant @ Mumbai
Cyber Security GRC Consultant @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,600,000 - 2,800,000
GRC Consultant
GRC Consultant

Lonvec Technologies Private Limited • Hyderabad

On-site
INR 1,200,000 - 2,200,000
Information Security GRC Manager
Information Security GRC Manager

Mount Talent Consulting • Mumbai

On-site
INR 3,000,000 - 5,000,000