- Hands-on experience in SOC 2 Type I and Type II implementation/readiness and delivery.
- Strong understanding of AICPA Trust Services Criteria (TSC).
- Experience with control mapping, gap assessments, evidence collection and validation.
- Understanding of Type II observation periods, control operating effectiveness and exceptions.
- Experience coordinating with external auditors/CPA firms.
- Ability to manage SOC 2 engagements from kickoff through audit closure.
2. ISO 27001 Expertise
- Strong understanding of ISO/IEC 27001:2022 requirements.
- Experience implementing and maintaining an Information Security Management System (ISMS).
- Conducting ISO 27001 gap assessments and readiness assessments.
- Understanding of Annex A controls and applicability assessment.
- Experience with:
- Risk assessment and risk treatment
- Statement of Applicability (SoA)
- Information security policies and procedures
- Internal audits
- Management reviews
- Corrective actions / NC management
- Continual improvement
- ISMS metrics and monitoring
- Experience supporting organizations through ISO 27001 certification audits.
- Understanding of Stage 1 and Stage 2 audit processes.
3. Governance, Risk & Compliance (GRC)
- Strong understanding of GRC frameworks and principles.
- Ability to establish and maintain governance processes.
- Experience with:
- Risk management
- Control frameworks
- Compliance assessments
- Regulatory requirements
- Policy governance
- Exception management
- Risk acceptance
- Corrective and preventive actions
- Compliance monitoring
- Ability to map controls across multiple frameworks such as SOC 2, ISO 27001, PCI DSS, GDPR, HIPAA, etc.
4. Compliance & Audit Management
- Manage internal and external compliance assessments.
- Prepare organizations for certification and attestation audits.
- Develop audit plans, evidence trackers and compliance calendars.
- Review audit evidence for completeness and adequacy.
- Manage audit observations, non-conformities and corrective actions.
- Coordinate with auditors and stakeholders to resolve audit queries.
- Maintain appropriate audit trails and compliance documentation.
5. Risk Management
- Conduct information security risk assessments.
- Identify, assess and prioritize organizational risks.
- Develop Risk Treatment Plans (RTPs).
- Maintain risk registers.
- Evaluate residual risk and risk acceptance.
- Support business owners in implementing appropriate risk mitigation measures.
6. Policies & Documentation Candidate should be comfortable creating/reviewing:
- Information Security Policy
- ISMS documentation
- Risk Management Policy
- Access Control Policy
- Incident Management Policy
- Business Continuity/DR policies
- Vendor Risk Management Policy
- Change Management Policy
- Secure SDLC policies
- Data Protection/Privacy policies
- Business Continuity documentation
- Control procedures and work instructions
7.
Client & Stakeholder Management
- Conduct client discovery and kickoff meetings.
- Understand business processes, technology environments and compliance requirements.
- Act as the primary delivery contact for clients.
- Conduct regular status meetings.
- Track milestones, dependencies, risks and deliverables.
- Communicate compliance requirements clearly to technical and non-technical stakeholders.
- Manage escalations and ensure timely closure of deliverables.
8. Technical Security Understanding Candidate should have a good working understanding of:
- AWS / Azure / GCP
- IAM, SSO and MFA
- Vulnerability management
- Secure SDLC
- Change management
- Incident response
- Logging and monitoring
- Encryption
- Backup and DR
- Endpoint security
- Network security
- Asset management
- Vendor/third-party security
- Data protection
They don't need to be a penetration tester or security engineer, but should be able to understand technical controls and assess their compliance implications.
Key Skills
Must Have:
- SOC 2 Type I/II
- ISO 27001:2022
- ISMS implementation
- GRC
- Risk assessment & treatment
- Control assessment
- Audit management
- Evidence review
- Compliance management
- Policy/procedure development
- Client management
- Robust documentation and communication skills
Good to Have:
- CISA / CISSP / CRISC
- ISO 27001 Lead Auditor / Lead Implementer
- ISO 27701
- PCI DSS
- HIPAA
- GDPR
- NIST CSF / NIST 800-53
- CSA CCM
- Experience with GRC platforms such as Vanta, Drata, Secureframe, OneTrust, etc.