Sr. Consultant - Compliance

TAC Security

New Delhi

On-site

INR 1,800,000 - 2,800,000

Full time

13 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

TAC Security in India is seeking a seasoned GRC professional to drive SOC 2, ISO 27001, and ISMS initiatives across client engagements. You will lead control mappings, audits, and certification readiness, coordinating with auditors and business stakeholders.

The role emphasizes risk management, policy development, and governance across multiple frameworks, with focus on evidence, SoA, and continual improvement to ensure compliance maturity.

Qualifications

  • Experience leading SOC 2 engagements from kickoff to audit closure.
  • Proficient in mapping controls and gathering audit evidence.
  • Strong knowledge of ISO 27001:2022 and ISMS requirements.
  • Ability to coordinate with auditors and stakeholders.

Responsibilities

  • Lead SOC 2 engagements end-to-end with clients.
  • Conduct ISO 27001 gap and readiness assessments.
  • Map controls, evidence, and SoA updates.
  • Coordinate with auditors to address audit queries.
  • Develop and review ISMS documentation and policies.
  • Manage risk assessments and treatment plans.
  • Maintain audit trails and corrective actions.
  • Ensure regulatory compliance across frameworks (SOC 2, ISO 27001, PCI DSS, GDPR, HIPAA).

Skills

SOC 2 Type I/II
ISO 27001:2022
ISMS implementation
GRC
Risk assessment
Control assessment
Audit management
Evidence review
Policy development
Client management
Documentation skills

Tools

Vanta
Drata
Secureframe
OneTrust

Job description

Job Description:
  • Hands-on experience in SOC 2 Type I and Type II implementation/readiness and delivery.
  • Strong understanding of AICPA Trust Services Criteria (TSC).
  • Experience with control mapping, gap assessments, evidence collection and validation.
  • Understanding of Type II observation periods, control operating effectiveness and exceptions.
  • Experience coordinating with external auditors/CPA firms.
  • Ability to manage SOC 2 engagements from kickoff through audit closure.
2. ISO 27001 Expertise
  • Strong understanding of ISO/IEC 27001:2022 requirements.
  • Experience implementing and maintaining an Information Security Management System (ISMS).
  • Conducting ISO 27001 gap assessments and readiness assessments.
  • Understanding of Annex A controls and applicability assessment.
  • Experience with:
  • Risk assessment and risk treatment
  • Statement of Applicability (SoA)
  • Information security policies and procedures
  • Internal audits
  • Management reviews
  • Corrective actions / NC management
  • Continual improvement
  • ISMS metrics and monitoring
  • Experience supporting organizations through ISO 27001 certification audits.
  • Understanding of Stage 1 and Stage 2 audit processes.
3. Governance, Risk & Compliance (GRC)
  • Strong understanding of GRC frameworks and principles.
  • Ability to establish and maintain governance processes.
  • Experience with:
  • Risk management
  • Control frameworks
  • Compliance assessments
  • Regulatory requirements
  • Policy governance
  • Exception management
  • Risk acceptance
  • Corrective and preventive actions
  • Compliance monitoring
  • Ability to map controls across multiple frameworks such as SOC 2, ISO 27001, PCI DSS, GDPR, HIPAA, etc.
4. Compliance & Audit Management
  • Manage internal and external compliance assessments.
  • Prepare organizations for certification and attestation audits.
  • Develop audit plans, evidence trackers and compliance calendars.
  • Review audit evidence for completeness and adequacy.
  • Manage audit observations, non-conformities and corrective actions.
  • Coordinate with auditors and stakeholders to resolve audit queries.
  • Maintain appropriate audit trails and compliance documentation.
5. Risk Management
  • Conduct information security risk assessments.
  • Identify, assess and prioritize organizational risks.
  • Develop Risk Treatment Plans (RTPs).
  • Maintain risk registers.
  • Evaluate residual risk and risk acceptance.
  • Support business owners in implementing appropriate risk mitigation measures.
6. Policies & Documentation

Candidate should be comfortable creating/reviewing:

  • Information Security Policy
  • ISMS documentation
  • Risk Management Policy
  • Access Control Policy
  • Incident Management Policy
  • Business Continuity/DR policies
  • Vendor Risk Management Policy
  • Change Management Policy
  • Secure SDLC policies
  • Data Protection/Privacy policies
  • Business Continuity documentation
  • Control procedures and work instructions
7. Client & Stakeholder Management
  • Conduct client discovery and kickoff meetings.
  • Understand business processes, technology environments and compliance requirements.
  • Act as the primary delivery contact for clients.
  • Conduct regular status meetings.
  • Track milestones, dependencies, risks and deliverables.
  • Communicate compliance requirements clearly to technical and non-technical stakeholders.
  • Manage escalations and ensure timely closure of deliverables.
8. Technical Security Understanding

Candidate should have a good working understanding of:

  • AWS / Azure / GCP
  • IAM, SSO and MFA
  • Vulnerability management
  • Secure SDLC
  • Change management
  • Incident response
  • Logging and monitoring
  • Encryption
  • Backup and DR
  • Endpoint security
  • Network security
  • Asset management
  • Vendor/third-party security
  • Data protection

They don't need to be a penetration tester or security engineer, but should be able to understand technical controls and assess their compliance implications.

Key Skills
Must Have:
  • SOC 2 Type I/II
  • ISO 27001:2022
  • ISMS implementation
  • GRC
  • Risk assessment & treatment
  • Control assessment
  • Audit management
  • Evidence review
  • Compliance management
  • Policy/procedure development
  • Client management
  • Strong documentation and communication skills
Good to Have:
  • CISA / CISSP / CRISC
  • ISO 27001 Lead Auditor / Lead Implementer
  • ISO 27701
  • PCI DSS
  • HIPAA
  • GDPR
  • NIST CSF / NIST 800-53
  • CSA CCM
  • Experience with GRC platforms such as Vanta, Drata, Secureframe, OneTrust, etc.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Consultant - Compliance
Sr. Consultant - Compliance

TAC Security • Delhi

On-site
INR 1,800,000 - 3,000,000
Manager For SOC 2 Type 2 Consultant
Manager For SOC 2 Type 2 Consultant

RAM Kala Verma • Dadri, Delhi

On-site
INR 1,200,000 - 1,800,000
Lead Compliance Specialist
Lead Compliance Specialist

TAC Security • Chandigarh

On-site
INR 2,600,000 - 3,200,000
Staff Risk and Compliance Analyst
Staff Risk and Compliance Analyst

Jobtailor • Bengaluru

On-site
INR 700,000 - 1,300,000
ISMS-IT Audit Director
ISMS-IT Audit Director

EY • India

On-site
INR 3,500,000 - 6,500,000
Security & Compliance Engineer
Security & Compliance Engineer

Kognitive Networks Inc. • Chennai District

Hybrid
INR 1,200,000 - 1,600,000
Group health insurance
Flexible working hours
Hybrid work model
Compliance Analyst (SOC -2 Type -2)
Compliance Analyst (SOC -2 Type -2)

Sita • New Delhi

On-site
INR 1,400,000 - 2,100,000
Compliance Coordinator
Compliance Coordinator

Trackwizz • Mumbai

On-site
INR 650,000 - 1,000,000
Senior Security GRC & ISO 27001 Specialist
Senior Security GRC & ISO 27001 Specialist

UST • Ernakulam

On-site
INR 2,800,000 - 4,200,000
Compliance Executive
Compliance Executive

Plutos One • Dadri

On-site
INR 1,200,000 - 1,800,000