14 Aug
|
Allied Boston Consultants India
|
Bengaluru
14 Aug
Allied Boston Consultants India
Bengaluru
Key Responsibilities:
1. Evaluate the information security governance, risk, and compliance posture of client organizations against leading frameworks and standards, including ISO/IEC 27001:2022, ISO/IEC 27701:2019, ISO/IEC 22301:2019, ISO 31000:2018, NIST Cybersecurity Framework 2.0, NIST SP 800-53 / 800-171, COBIT 2019, PCI DSS v4.0.1, CIS Controls v8, & CSA CCM.
2. Assess client compliance with applicable Indian regulatory guidelines and frameworks, including:
- RBI master directions for banks & payment aggregators
- SEBI - Cybersecurity and Cyber Resilience Framework (CSCRF) for Regulated Entities.
- IRDAI - Information & Cyber Security Guidelines for the Insurance sector.
- UIDAI - AUA/KUA, Sub-AUA, and ASA requirements, and Information Security policies.
- CERT-In - Cyber Security Directions dated 28 April 2022 and CERT-In empanelment audit guidelines.
- NCIIPC - guidelines for the protection of Critical Information Infrastructure (CII).
- MeitY, DOT, CEA, NPCI, NSE/BSE, and other sectoral regulator guidelines, as applicable.
1. Conduct risk assessments and control testing across people, process, and technology domains; identify gaps; assess inherent vs. residual risks; and recommend risk treatment plans.
2. Review application security, IT infrastructure security, cloud security, and network security architectures as part of GRC assessments.
3. Perform third-party / vendor risk assessments and supply-chain security reviews.
4. Plan and execute compliance activities, including drafting and reviewing information security policies, procedures, standards, and process documents.
5. Support clients during regulatory inspections and external audits by responding to queries, providing evidence, and coordinating with auditors and regulators.
8.Stay current with evolving cybersecurity regulations, advisories, and threat landscape; track changes from CERT-In, RBI, SEBI, IRDAI, MeitY, NCIIPC, and other regulators, and adapt audit/compliance approaches accordingly.
1. Prepare clear, structured, and audit-ready deliverables observation sheets, risk registers, gap assessment reports, management presentations, and remediation roadmaps using MS Word, MS Excel, and MS PowerPoint.
Level-wise Scope
- Entry (02 yrs): Support audits, evidence collection, documentation, and report drafting under senior guidance.
- Mid (36 yrs): Independently lead audits and assessments, mentor juniors, present findings to client management.
- Senior (7+ yrs): Own end-to-end engagements as SME/Engagement Lead, manage teams, engage with CISOs and senior leadership, and support business development.
Key Performance Indicators (KPIs)
- Quality and timeliness of audit deliverables — reports, working papers, and evidence.
- Adherence to engagement timelines, scope, and budget.
- Number of audits/engagements successfully closed.
- Accuracy of regulatory interpretation and audit observations (minimal disputes from clients or regulators).
- Client satisfaction (CSAT / NPS) and repeat business/references.
- Contribution to methodology, knowledge base, and capability development.
- For Senior level — revenue contribution, team utilization,
mentoring outcomes, and business development support.
Qualifications & Experience:
- Graduate or above (B.E./B.Tech / B.Sc. / BCA in IT, CS, or related disciplines preferred)
- ISO/IEC 27001:2022 Lead Auditor (mandatory for Mid & Senior levels; preferred for Entry-Level).
- Additional certifications such as CISA, CISM, CRISC, CEH, CIPP/E, PCI-QSA, ISO 27701 LA, ISO 22301 LA, are an added advantage.
Experience required:
- Entry-Level (0 – 2 years)
- Mid-Level (3 – 6 years)
- Senior-Level (7+ years)
Skills & Competencies
Technical Skills
- Strong understanding of information security, cyber security, risk management, and audit methodology.
- Working knowledge of ISO/IEC 27001:2022, ISO/IEC 27002:2022, NIST CSF 2.0, COBIT 2019, ISO 31000:2018, PCI DSS v4.0.1, and ISO 22301:2019.
- Familiarity with Indian regulatory frameworks (RBI, SEBI CSCRF, IRDAI, UIDAI, NCIIPC, CERT-In Directions 2022, MeitY).
- Understanding of data protection laws — Digital Personal Data Protection Act 2023, GDPR, ISO 27701:2019.
- Hands-on proficiency in MS Word (reports & policies), MS Excel (risk registers, trackers, control matrices, pivot tables), and MS PowerPoint (management presentations).
Behavioural Skills
- Detail-oriented with solid analytical, structured-thinking, and problem-solving abilities.
- Excellent written and verbal communication skills in English; ability to articulate complex security and compliance concepts to both technical and business audiences.
- Strong client-handling, stakeholder management, and presentation skills (especially for Mid & Senior levels).
- Ability to manage multiple engagements/priorities and deliver under tight timelines
📌 Sr. Security Auditor (Bengaluru)
🏢 Allied Boston Consultants India
📍 Bengaluru