14 Aug
|
Nexinfo
|
Chennai
About Nexinfo:
NexInfo is a premier consulting firm founded in 1999. We have been in business for 26 years and work with clients of all sizes to achieve ‘Operational Excellence’ using a blend of knowledge in both Business Processes and Software Consulting.
We offer implementation and managed services for businesses across many industries including Manufacturing, Pharmaceuticals, Biotech, Medical Devices, Industrial Automation, Automobile Industry, and many more. We have a global footprint across North America, Europe, and Asia with most clients distributed across North America with a team size of 300 employees and our headquarters in California, USA.
About the Role
We are looking for a detail-oriented QA & Compliance skilled to own and drive our ISO 9001 (Quality Management System) and ISO 27001 (Information Security Management System) frameworks, while also functioning as the organization's Internal Auditor. This role is critical to ensuring our ERP implementation and consulting practices meet international quality and information security standards, and that internal controls are consistently followed across projects and departments.
Key Responsibilities
ISO 9001 – Quality Management
- Maintain, review, and continuously improve the QMS documentation (policies, procedures, work instructions, forms).
- Ensure ERP implementation and consulting processes are aligned with ISO 9001 requirements.
- Monitor quality objectives, KPIs, and process performance across departments/projects.
- Drive root cause analysis and Corrective & Preventive Action (CAPA) processes for non-conformities.
- Coordinate management review meetings and prepare quality reports for leadership.
ISO 27001 – Information Security Management
- Maintain and update the ISMS documentation, risk register, and Statement of Applicability (SoA).
- Conduct periodic information security risk assessments across IT, HR, and project delivery functions.
- Monitor compliance with access control, data protection, and incident management procedures.
- Coordinate with IT/Infra teams on security controls, vulnerability management, and incident response.
- Track and close security-related non-conformities and audit findings.
Internal Audit
- Plan and execute the annual internal audit calendar covering all departments and processes.
- Conduct internal audits against ISO 9001 and ISO 27001 clauses; prepare audit reports with objective evidence.
- Track audit findings, non-conformities, and observations through to closure (CAPA follow-up).
- Liaise with external certification bodies for surveillance and recertification audits.
- Ensure audit trails,
evidence, and documentation are maintained per compliance requirements.
Client Delivery Governance & Controls Audit
- Audit ERP implementation and consulting engagements end-to-end for adherence to defined delivery methodology (e.g., ASAP, Activate, Agile/Waterfall hybrid) and internal governance framework.
- Review project governance structures — steering committee cadence, status reporting, escalation matrix, RAID (Risks, Assumptions, Issues, Dependencies) logs — for completeness and timely updates.
- Verify that project deliverables (BBP/Business Blueprint, FSD/TSD, configuration documents, test scripts, training material, go-live checklists, etc.) are prepared, reviewed, and stored as per the defined document control process.
- Audit client sign-off records at each project stage/milestone (requirement sign-off, UAT sign-off, go-live sign-off, closure sign-off) to confirm proper authorization, version control, and traceability.
- Verify the Requirements Traceability Matrix (RTM) is maintained and updated — ensuring every business requirement is mapped to design, configuration/development, test case, and UAT result, with no orphan or unmapped requirements.
- Validate that critical project milestones (kick-off, blueprint sign-off, realization/build completion, UAT completion, go-live, hypercare closure) are recorded with supporting evidence — minutes of meetings, attendance, approvals, and timelines.
- Check adherence to change management/change control procedures for scope changes, CRs (Change Requests), and their impact assessment, approval, and documentation trail.
- Review project documentation repository (SharePoint/PM tool/DMS) for structure, access control, version history, and retention as per organizational policy.
- Conduct periodic project health/governance audits and publish findings/dashboards to leadership highlighting gaps in documentation, sign-offs, or governance adherence.
- Track closure of governance-related audit observations with project/delivery teams and ensure lessons learned are incorporated into future engagements.
- Support development and continuous improvement of standard templates/checklists for governance, RTM, milestone tracking,
and sign-off documentation across projects.
General QA & Compliance
- Act as a bridge between project delivery teams and the quality/compliance function.
- Conduct employee awareness training on ISO processes, information security practices, and quality standards.
- Support client audits/due diligence questionnaires related to quality and security certifications.
- Keep the QMS/ISMS documentation aligned with any changes in ISO standards or regulatory requirements.
Required Qualifications & Experience
- Bachelor’s degree in engineering, IT, Business Administration, or related field (MBA preferred but not mandatory).
- 6 years of experience in Quality Assurance / Compliance / Internal Audit roles, preferably in IT, ERP, or consulting environments.
- Hands-on experience implementing or maintaining ISO 9001 and ISO 27001 systems.
- Certification as Internal Auditor for ISO 9001 and ISO 27001 (Lead Auditor certification is a strong plus).
- Working knowledge of ERP implementation lifecycles and consulting delivery processes is highly desirable.
- Prior experience auditing client delivery governance — project documentation, RTM, milestone sign-offs, and deliverable quality — in an ERP/IT consulting environment is highly preferred.
- Familiarity with other frameworks (ISO 20000, SOC 2, GDPR, or CMMI) is an added advantage.
Key Skills
- Strong understanding of QMS and ISMS documentation and audit methodology.
- Analytical mindset with ability to identify process gaps and drive corrective actions.
- Excellent communication skills to work across cross-functional teams and leadership.
- Proficiency in MS Office/Excel; exposure to GRC or audit-management tools is a plus.
- Familiarity with RTM preparation/review, project governance frameworks, and deliverable sign-off/documentation control practices.
- High attention to detail, integrity, and objectivity (essential for the auditor function).
- Ability to manage multiple audits/projects and meet deadlines independently.
Preferred Certifications
- ISO 9001:2015 Lead Auditor / Internal Auditor
- ISO 27001:2022 Lead Auditor / Internal Auditor
- Certified Information Security Auditor (CISA) – optional/added advantage
What We Offer
- Opportunity to build and own the compliance function in a growing ERP & business consulting organization.
- Exposure to enterprise clients and multi-industry ERP implementation projects.
- Competitive compensation aligned with experience and certifications.
Job Location: Chennai
Seniority Level: Intermediate
Work Mode: Fulltime
Shift Timing: EUR (2:30 PM to 12:00AM IST)
📌 IND-QA Executive (Chennai)
🏢 Nexinfo
📍 Chennai