Information Security Consultant

Soffit Infrastructure Services (p) Ltd

Ernakulam

On-site

INR 1,800,000 - 3,600,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Soffit Infrastructure Services (p) Ltd seeks an Information Security Consultant to lead ISO 27001/2022 and SOC 2 initiatives for clients, providing guidance and hands-on implementation. The role includes risk assessment, policy development, and post-audit support to maintain ongoing compliance.

The consultant will work with clients to identify appropriate controls, develop procedures, and deliver vCISO support to enhance information security governance and resilience across various environments.

Qualifications

  • Proficient in auditing, policy development and risk analysis.
  • Experience with information security frameworks (ISO, SOC 2, NIST, CIS, PCI DSS).
  • Hands-on with ISO 27001:2022 and SOC 2 implementations and assessments.

Responsibilities

  • Assist clients in ISO 27001/2022 and ISO frameworks compliance and certification.
  • Assist clients in SOC 2 compliance by identifying and implementing Trust Service Criteria.
  • Conduct risk assessments and provide remediation strategies until closure or acceptance.

Skills

Auditing
Policy development
Risk analysis
Identity management
Access control
Web security
Cybersecurity
ISO 27001/2022

Job description

Job Overview: The Information Security Consultant will be responsible for the implementation, assessment, and management of ISO **:2022, ISO **, and SOC 2 standards for clients. This role involves working independently or alongside senior consultants to help clients achieve and maintain information security compliance and other best practices. The consultant will focus on assessing and ensuring compliance with key security frameworks and will provide vCISO support to various clients.

Key Responsibilities
  • ISO **/** Compliance: Assist clients in achieving ISO ** certification by identifying and implementing the appropriate controls within the audit scope. Verify compliance with ISO **/** controls and provide recommendations for improvement.
  • SOC 2 Compliance: Assist clients in achieving SOC 2 compliance by identifying and implementing the appropriate Trust Service Criteria (TSCs). Conduct SOC 2 compliance assessments and ensure the proper implementation of required controls.
  • Risk Assessment and Mitigation: Conduct risk assessments of business activities, collaborating with stakeholders to manage risks until closure or acceptance. Provide actionable recommendations to mitigate identified risks.
  • Policy and Procedure Development: Define, develop, and review information security policies, procedures, guidelines, forms, and templates in line with best practices. Ensure documentation is up-to-date and aligned with industry standards.
  • Baseline Standards Review: Create and review baseline standards for operating systems, databases, web servers, and applications. Recommend improvements based on security assessments.
  • Post-Implementation Audits: Support post-implementation audits for ISO **:2022 to ensure ongoing compliance. Monitor and assess adherence to established information security standards.
  • Information Security Awareness: Create and execute organizational information security awareness programs. Conduct training sessions to ensure employees are knowledgeable about security best practices.
  • Security Standards Compliance: Assist clients in ensuring compliance with various security standards (ISO **, SOC 2, HIPAA, NIST, CIS, PCI DSS, etc.). Recommend strategies to ensure long-term adherence to security best practices.
  • Incident Response: Develop and implement incident response plans to handle security breaches and cyberattacks. Ensure that clients have clear, actionable plans to address potential security incidents.
  • Gap Assessment: Conduct gap assessments to identify areas of non-compliance and provide remediation strategies.
  • vCISO Support: Provide virtual Chief Information Security Officer (vCISO) support to clients, advising on information security strategy and governance.
Skills and Qualifications
Technical Skills

Strong background in Information Technology and/or Cybersecurity . Proficiency in auditing, policy development, database security, firewall design, risk analysis, identity management, access control, and web security. Knowledge of security frameworks including ISO **, SOC 2, HIPAA, NIST, CIS, PCI DSS, and other industry best practices. Hands-on experience with ISO **:2022 and SOC 2 implementations and assessments. Strong understanding of risk management and the ability to assess and mitigate security risks.

Presales and Communication Skills

Excellent client-facing communication skills. Strong problem-solving abilities and the capacity to work effectively in a team environment. Ability to communicate complex technical concepts to both technical and non-technical audiences. Demonstrated ability to deliver presentations and conduct training sessions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Manager
Information Security Manager

Rahi Platform Technologies • Pune District

On-site
INR 1,000,000 - 1,500,000
Information Security Manager
Information Security Manager

Altraize • Mumbai

On-site
Information Security - Manager
Information Security - Manager

Promaynov Advisory Services Pvt. Ltd • Delhi

On-site
INR 3,500,000 - 5,500,000
InfoSec Executive
InfoSec Executive

QualityKiosk Technologies • Navi Mumbai

On-site
INR <4,500,000
Sr. Consultant - Compliance
Sr. Consultant - Compliance

TAC Security • Delhi

On-site
INR 1,500,000 - 2,100,000
Chief Information Security Officer
Chief Information Security Officer

Smartstream • India

On-site
INR 3,000,000 - 5,000,000
Technical Architect
Technical Architect

ESP Engineered • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Manager- ISO 27001 and SOC 2 Audits (FEMALE)
Manager- ISO 27001 and SOC 2 Audits (FEMALE)

HCLTech • Bengaluru

On-site
INR 1,500,000 - 2,000,000
Security, Risk & Compliance Lead
Security, Risk & Compliance Lead

RedDoorz • Dadri

On-site
INR 2,400,000 - 4,800,000
Information Security Engineer
Information Security Engineer

Tredence • Bengaluru

On-site
INR 1,200,000 - 1,800,000