Manager- ISO 27001 and SOC 2 Audits (FEMALE)

HCLTech

Bengaluru

On-site

INR 1,500,000 - 2,000,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

A leading IT services firm in Bengaluru is seeking a Mid-Senior Risk & Compliance Consultant. The ideal candidate will have at least 10 years of experience in risk management, particularly with ISO standards. Responsibilities include managing the internal assessment program, updating risk registers, and presenting status reports. Knowledge of regulatory compliance and excellent communication skills are essential for success in this role.

Qualifications

  • 10 years of relevant experience in information systems audit/assessment and risk management.
  • Experience with ISO 27001, SSAE, PCI, ISO 27701, and risk assessment.

Responsibilities

  • Lead the internal assessment program; oversee control testing.
  • Maintain and update the enterprise risk register.
  • Design dashboards for key metrics and status reports.

Skills

Risk and compliance experience
ISO 27001 handling
Strong analytical skills
Communication skills
Project management

Education

Bachelor’s Degree in Information Technology or Computer Science

Tools

MS Office

Job description

Overview

The position is a member of Risk & Compliance within HCL Technologies. The DCO will be aligned to critical service delivery engagements and will be responsible for ensuring compliance in accordance to client, organizational & regulatory security requirements.

Key Responsibilities
  • Lead and manage the internal assessment program, ensuring effective facilitation of assessments. Oversee the program's execution and conduct control testing aligned with established frameworks and standards, including ISO 27001, ISO 22301, ISO 27701, SOC 1 & SOC 2.
  • Maintain and update the enterprise risk register, ensuring accuracy and completeness of risk data, and develop consolidated risk views for reporting and analysis.
  • Design and prepare risk dashboards to visualize key metrics and trends, and present comprehensive status reports to senior management as part of the internal risk assessment program.
  • Perform assessments of the in-scope facilities against relevant standards such as ISO 27001, ISO 22301, SOC.
  • Collaborate closely with various stakeholders to support the entire certification lifecycle.
  • Engage with relevant stakeholders to manage compliance requirements through awareness initiatives and regular interactions, ensuring users understand and comply with necessary procedures to maintain security.
  • Identify gaps and non-compliances, and work with relevant stakeholders to ensure timely resolution.
  • Promote a risk-aware culture throughout the organization.
  • Assist in scoping and develop a calendarized schedule of activities for regular monitoring.
  • Adhere to a defined escalation matrix to manage identified risks.
  • Coordinate and facilitate to third parties for external audits.
  • Stay informed about the latest information security trends and threat landscapes to take proactive measures during assessments.
  • Keep management informed of critical issues that may impact customers, suppliers, or the company.
  • Introduce efficiencies to enhance existing programs.
  • Actively participate in other projects / initiatives as required.
Mandatory knowledge or skills
  • Candidates should possess prior relevant experience in risk and compliance, along with appropriate certifications. Experience in handling ISO 27001, SSAE, and PCI requirements across various industries is preferable.
  • Additional experience with other standards and assessments such as ISO 27701, ISO 42001 and ISO 22301 is advantageous. A foundational understanding of regulatory and statutory compliance is essential.
  • Experience in managing merger and acquisition activities from an information security perspective is desirable. Candidates are expected to have 10 years of relevant experience in information systems audit/assessment and risk management (including risk assessment and remediation).
  • Sound knowledge of management reporting and dashboard creation is required.
  • Proficiency in independently handling projects with strong interpersonal and excellent communication skills is necessary. Candidates should demonstrate strong analytical, familiarity and experience with managing small to medium initiatives, including timelines, status, interdependency, and risk management, is essential.
  • The candidate should be adept at assisting with the management of stakeholder needs and expectations, providing consistent and regular communications with support from management.
  • The ability to effectively balance multiple tasks through careful prioritization and to work collaboratively with others to produce a quality work product is required.
Education Qualification

Bachelor’s Degree - BE/B Tech/B.Sc, Master degree in any domain, preferably in Information Technology or Computer Science

Certifications Preferred

Security Certifications like CISA/CRISC/ISO27001

Attributes of Ideal Candidate
  • At least 10 years’ experience, or minimum 8-10 years of experience in ISO 27001 & SSAE 18 / assessment and Risk management (risk assessment and remediation).
  • Strong analytical, problem solving, organizational, documentation; time management skills.
  • Proven ability to communicate with multiple stakeholders and manage output from multiple teams.
  • Excellent spoken and written English; good report writing and analytical skills.
  • Proficient in MS Office; good data analytics, MIS, inferences and self-scrutiny for continuous improvement.
Seniority level
  • Mid-Senior level
Employment type
  • Full-time
Job function
  • Other
Industries
  • IT Services and IT Consulting
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Manager
Manager

HCLTech • Chennai District

On-site
INR 1,800,000 - 2,800,000
Manager - Information Security
Manager - Information Security

DS Group • Dadri

On-site
INR 2,800,000 - 5,400,000
Manager Security Risk And Compliance
Manager Security Risk And Compliance

International SOS • Gurugram District

Hybrid
INR 900,000 - 1,500,000
Manager - Information Security
Manager - Information Security

Ashok Maheshwary & Associates • Gurugram District

Hybrid
INR 2,000,000 - 3,800,000
Compliance Executive
Compliance Executive

Plutos One • Dadri

On-site
INR 1,200,000 - 1,800,000
Control Advisor
Control Advisor

Equiniti • Chennai District

Hybrid
INR 1,200,000 - 1,800,000
Hybrid work model
Lead - Risk & Compliance
Lead - Risk & Compliance

ATAIN • Gurugram District

On-site
INR 1,200,000 - 2,400,000
ISMS-IT Audit Director
ISMS-IT Audit Director

EY • India

On-site
INR 3,500,000 - 6,500,000
Information Security Analyst
Information Security Analyst

ACL Digital • Chennai District, Bengaluru

On-site
INR 600,000 - 900,000
Information Security Analyst
Information Security Analyst

ASSA ABLOY Global Solutions • Chennai District

Hybrid
INR 900,000 - 1,500,000