Enable job alerts via email!

GRC Consultant (ISO 27001, SOC 2 & Pentesting)

GISPL

New Delhi

Hybrid

INR 12,00,000 - 18,00,000

Full time

25 days ago

Job summary

A cybersecurity consultancy firm in New Delhi is hiring a GRC Consultant to handle ISO/IEC 27001 and SOC 2 assessments. The role requires over 5 years of experience in information security and strong client management skills. This position offers a hybrid work model and involves direct collaboration with client stakeholders.

Qualifications

  • Minimum 5 years of experience in Information Security / GRC roles.
  • Strong hands-on experience with ISO/IEC 27001 and SOC 2 frameworks.
  • Excellent communication and client management skills.

Responsibilities

  • Lead and conduct ISO 27001 and SOC 2 readiness assessments.
  • Guide clients through ISMS implementation.
  • Prepare reports and documentation for management.

Skills

ISO/IEC 27001 expertise
SOC 2 implementation
Penetration testing
Client management
Risk management
Data protection

Education

Relevant certifications (ISO 27001 LA, CEH, Security+, CISA)

Tools

Burp Suite
Nmap
Nessus

Job description

GRC Consultant (ISO 27001, SOC 2 & Pentesting)

Join to apply for the GRC Consultant (ISO 27001, SOC 2 & Pentesting) role at GISPL

GRC Consultant (ISO 27001, SOC 2 & Pentesting)

Join to apply for the GRC Consultant (ISO 27001, SOC 2 & Pentesting) role at GISPL

Job Title: GRC Consultant (ISO 27001, SOC 2 & Pentesting)

Location:Hybrid

Employment Type:Full-time / Contract (as applicable)

Role Overview:

We are seeking a highly motivated and experienced GRC Consultant with strong expertise in ISO/IEC 27001 and SOC 2 implementation and assessments. The ideal candidate should also have a solid understanding of penetration testing and be comfortable handling client engagements independently.

This role will involve working closely with clients to assess, design, implement, and manage security governance frameworks, conduct audits, and provide actionable recommendations for compliance and risk mitigation.

Key Responsibilities:

  • Lead and conduct ISO 27001 and SOC 2 readiness assessments, gap analyses, risk assessments, and control validations
  • Guide clients through ISMS implementation and SOC 2 Trust Services Criteria alignment
  • Prepare and present reports, documentation, and dashboards for management and auditors
  • Work directly with client stakeholders including CISOs, IT Heads, and Audit/Compliance teams
  • Support clients in creating and refining security policies, procedures, and evidence collection
  • Conduct or support penetration testing and vulnerability assessments as needed
  • Coordinate with internal technical teams and external auditors
  • Stay updated with global security compliance standards, frameworks, and threat landscape
  • Assist in proposal writing and client scoping calls when needed

Required Skills & Qualifications:

  • Minimum 5 years of experience in Information Security / GRC roles
  • Strong hands-on experience with ISO/IEC 27001 and SOC 2 frameworks
  • Knowledge of risk management, data protection, business continuity, and audit lifecycle
  • Experience conducting internal audits, security gap assessments, and control testing
  • Basic to intermediate Pentesting skills (e.g., using Burp Suite, Nmap, Nessus, etc.)
  • Excellent communication and client management skills
  • Ability to work independently and drive deliverables in consulting environments
  • Relevant certifications preferred: ISO 27001 LA, CEH, Security+, CISA, or equivalent

Nice to Have:

  • Experience with other compliance frameworks like HIPAA, PCI-DSS, GDPR
  • Familiarity with cloud security standards (e.g., AWS, Azure benchmarks)
  • Exposure to tools like Metasploit, OWASP ZAP, SIEM platforms, etc.
  • Knowledge of risk scoring tools and GRC platforms (e.g., Archer, ServiceNow GRC)
Seniority level
  • Seniority level
    Mid-Senior level
Employment type
  • Employment type
    Full-time
Job function
  • Job function
    Consulting, Information Technology, and Sales
  • Industries
    Computer and Network Security

Referrals increase your chances of interviewing at GISPL by 2x

Get notified about new Consultant jobs in New Delhi, Delhi, India.

Domain Consultant (Presales) - (SASE/NGFW), North India
Solutions Consultant - Defense and Central Government
Senior Associate Security Consultant (GRC)
Additional Education Needs Consultant (TBS_ANC) [Whole School]
Consultant - TAX - National - TAX - ITTS - Advisory - New Delhi

Delhi Cantonment, Delhi, India 1 month ago

Consultant, Public Affairs & Public Advocacy | Strategic Communications | New Delhi
Talent Acquisition Associate - Remote Work
Pre-sales Business Analyst - Insurance (Fully Remote)
Senior Business Analyst - Insurance (Fully Remote)
Consultant - Business Consulting PI - GOV - CNS - BC - Transformation Delivery - New Delhi
Senior Business Analyst - Health Insurance (Fully Remote, Night Shift)
Senior Consultant - Business Consulting PI - GOV - CNS - BC - Transformation Delivery - New Delhi
Consultant - Business Consulting PI - GOV - CNS - BC - Transformation Delivery - New Delhi
Consultant - Tax - AMI - TAX - Indirect Tax - Core - New Delhi

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.