10 Aug
|
Jibe Development Services
|
Chennai
10 Aug
Jibe Development Services
Chennai
Role & responsibilities
Internal Audit & Control Testing
- Plan and execute the annual internal audit program: conduct internal audits against ISO 27001 and SOC 2 controls, document findings, and track remediation to closure.
- Perform control testing and gap assessments, collecting and organizing evidence to an external-audit standard.
External Audit & Certification Readiness
- Lead preparation and coordination for external audits (ISO 27001 certification and surveillance, SOC 2 Type II): audit scheduling, evidence collection, auditor liaison, and management of corrective actions.
- Maintain a year-round audit readiness posture and calendar, so external audits are a checkpoint rather than a scramble.
ISMS, Risk & Policy Management
- Maintain the ISMS documentation set policies, procedures, Statement of Applicability, and risk register.
- Drive periodic risk assessments and treatment plans together with control owners across the company.
Security Assessments & Incident Follow-Up
- Coordinate periodic vulnerability assessments and penetration tests with IT and external vendors; validate scope, review results, and track remediation with the relevant teams.
- Review internal security incident reports, verify root-cause analysis and corrective actions, and follow up until closure.
Vendor & Customer Assurance
- Run vendor and third-party risk assessments as part of the procurement and vendor-review process.
- Support responses to customer security questionnaires and customer audits.
Reporting
- Report compliance posture, audit results,
and open risks to management on a regular cadence.
Preferred candidate profile
- 36 years of experience in IT audit, GRC, or security compliance, preferably in a SaaS or software company.
- Hands-on experience with at least one full ISO 27001 and/or SOC 2 audit cycle — from preparation and evidence collection through the external audit itself.
- Working knowledge of risk assessment methodologies and control frameworks (ISO 27001/27002; familiarity with SOC 2 Trust Services Criteria).
- Familiarity with data protection regulations (e.g., GDPR) and their impact on a SaaS business.
- Excellent written and spoken English — the role produces audit reports, policies, and customer-facing responses.
Core Soft Skills
- Self-motivated, independent, and meticulous, with strong organizational skills and an eye for detail.
- Clear, accurate writing — audit findings and policies that people can actually act on.
- Team player with good interpersonal skills — able to work with R&D;, IT, and DevOps teams and gain cooperation without formal authority.
Nice to Have
- Experience with compliance automation platforms (e.g., Vanta, Drata, Scytale).
- Familiarity with application security concepts and vulnerability management processes.
- Experience in cloud environments (Azure / AWS) and understanding of cloud security controls.
Certifications (Preferred, Not Mandatory)
- CISA (Certified Information Systems Auditor).
- ISO 27001 Lead Auditor / Lead Implementer.
📌 Internal IT Auditor (Chennai)
🏢 Jibe Development Services
📍 Chennai