Sr. Consultant - Compliance

TAC Security

Delhi

On-site

INR 1,500,000 - 2,100,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

TAC Security in Delhi is seeking a seasoned GRC professional to lead SOC 2, ISO 27001, and audit readiness initiatives. You will map controls, coordinate with auditors, and drive evidence collection through closure.

The role requires strong documentation, stakeholder management, and the ability to assess compliance implications of technical controls across frameworks such as SOC 2, ISO 27001, PCI DSS, GDPR, and HIPAA.

Qualifications

  • Experience with SOC 2 Type I/II engagements and certification processes.
  • Deep knowledge of ISO/IEC 27001:2022 and ISMS implementation.
  • Proven ability to map controls, perform gap assessments and collect evidence.
  • Familiarity with audit management, non-conformities and corrective actions.
  • Ability to coordinate with external auditors and stakeholders.
  • Strong documentation and communication for policy and control artifacts.

Responsibilities

  • Lead SOC 2, ISO 27001, and GRC programs from kickoff to audit closure.
  • Develop control matrices, risk assessments and SoA documentation.
  • Coordinate internal/external audits and track audit findings.
  • Prepare clients for certification/attestation audits and keep evidence trackers up to date.
  • Engage with stakeholders to ensure timely responses and remediation.
  • Review audit evidence for completeness and suitability; maintain audit trails.

Skills

SOC 2 Type I/II
ISO 27001:2022
ISMS implementation
GRC
Control assessment
Audit management
Evidence review
Compliance management
Client management
Documentation & communication

Tools

Vanta
Drata
Secureframe
OneTrust

Job description

  • Hands-on experience in SOC 2 Type I and Type II implementation/readiness and delivery.
  • Strong understanding of AICPA Trust Services Criteria (TSC).
  • Experience with control mapping, gap assessments, evidence collection and validation.
  • Understanding of Type II observation periods, control operating effectiveness and exceptions.
  • Experience coordinating with external auditors/CPA firms.
  • Ability to manage SOC 2 engagements from kickoff through audit closure.
2. ISO 27001 Expertise
  • Strong understanding of ISO/IEC 27001:2022 requirements.
  • Experience implementing and maintaining an Information Security Management System (ISMS).
  • Conducting ISO 27001 gap assessments and readiness assessments.
  • Understanding of Annex A controls and applicability assessment.
  • Experience with:
  • Risk assessment and risk treatment
  • Statement of Applicability (SoA)
  • Information security policies and procedures
  • Internal audits
  • Management reviews
  • Corrective actions / NC management
  • ISMS metrics and monitoring
  • Experience supporting organizations through ISO 27001 certification audits.
  • Understanding of Stage 1 and Stage 2 audit processes.
3. Governance, Risk & Compliance (GRC)
  • Strong understanding of GRC frameworks and principles.
  • Ability to establish and maintain governance processes.
  • Experience with:
  • Control frameworks
  • Compliance assessments
  • Regulatory requirements
  • Policy governance
  • Exception management
  • Corrective and preventive actions
  • Compliance monitoring
  • Ability to map controls across multiple frameworks such as SOC 2, ISO 27001, PCI DSS, GDPR, HIPAA, etc.
4. Compliance & Audit Management
  • Manage internal and external compliance assessments.
  • Prepare organizations for certification and attestation audits.
  • Develop audit plans, evidence trackers and compliance calendars.
  • Review audit evidence for completeness and adequacy.
  • Manage audit observations, non-conformities and corrective actions.
  • Coordinate with auditors and stakeholders to resolve audit queries.
  • Maintain appropriate audit trails and compliance documentation.
  • Conduct information security risk assessments.
  • Identify, assess and prioritize organizational risks.
  • Evaluate residual risk and risk acceptance.
  • Support business owners in implementing appropriate risk mitigation measures.

Candidate should be comfortable creating/reviewing:

  • Information Security Policy
  • ISMS documentation
  • Access Control Policy
  • Business Continuity/DR policies
  • Change Management Policy
  • Business Continuity documentation
  • Control procedures and work instructions
7. Client & Stakeholder Management
  • Conduct client discovery and kickoff meetings.
  • Understand business processes, technology environments and compliance requirements.
  • Act as the primary delivery contact for clients.
  • Track milestones, dependencies, risks and deliverables.
  • Communicate compliance requirements clearly to technical and non-technical stakeholders.
  • Manage escalations and ensure timely closure of deliverables.
8. Technical Security Understanding

Candidate should have a good working understanding of:

  • IAM, SSO and MFA
  • Vulnerability management
  • Secure SDLC
  • Change management
  • Logging and monitoring
  • Encryption
  • Backup and DR
  • Network security
  • Asset management
  • Vendor/third-party security
  • Data protection

They don't need to be a penetration tester or security engineer, but should be able to understand technical controls and assess their compliance implications.

Key Skills
Must Have:
  • SOC 2 Type I/II
  • ISO 27001:2022
  • ISMS implementation
  • GRC
  • Control assessment
  • Audit management
  • Evidence review
  • Compliance management
  • Client management
  • Strong documentation and communication skills
Good to Have:
  • CISA / CISSP / CRISC
  • ISO 27701
  • PCI DSS
  • HIPAA
  • GDPR
  • NIST CSF / NIST 800-53
  • CSA CCM
  • Experience with GRC platforms such as Vanta, Drata, Secureframe, OneTrust, etc.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Internal IT Auditor
Internal IT Auditor

Jibe Development Services • Navi Mumbai, Chennai District

On-site
INR 1,400,000 - 2,300,000
Manager- GRC
Manager- GRC

CyberCube Services • Gurugram District

On-site
INR 1,500,000 - 2,100,000
Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
Senior Security GRC & ISO 27001 Manager
Senior Security GRC & ISO 27001 Manager

UST • Thiruvananthapuram

On-site
INR 2,500,000 - 4,500,000
Security & Compliance Engineer
Security & Compliance Engineer

Kognitive Networks Inc. • Chennai District

Hybrid
INR 1,200,000 - 1,600,000
Group health insurance
Flexible working hours
Hybrid work model
Compliance Coordinator
Compliance Coordinator

Trackwizz • Mumbai

On-site
INR 650,000 - 1,000,000
Audit & Compliance Executive
Audit & Compliance Executive

Vouchagram India • New Delhi

On-site
INR 700,000 - 1,100,000
Senior Digital Risk Consultant
Senior Digital Risk Consultant

Jobtailor • Hyderabad

On-site
INR 1,200,000 - 2,400,000
Governance, Risk & Compliance (GRC) Manager
Governance, Risk & Compliance (GRC) Manager

TeamsWork.In • India

On-site
INR 1,500,000 - 2,100,000
Staff Consultant, Digital Risk – IT Controls
Staff Consultant, Digital Risk – IT Controls

Jobtailor • Bengaluru

On-site
INR 900,000 - 1,300,000