25 Aug
|
Notified
|
Bengaluru
25 Aug
Notified
Bengaluru
Basic Function
Support the organization’s information security compliance program by leading audits, regulatory compliance initiatives, control assessments, risk management activities, and evidence collection. Act as a trusted advisor to the business, promoting risk-based decision-making, compliance awareness, control maturity, and process improvement.
Key Responsibilities
Compliance & Audit Management
- Lead and maintain information security compliance programs aligned with corporate policies and regulatory requirements.
- Support and manage audits and compliance frameworks such as ISO 27001, SOC 2, GDPR, DORA, FISMA, and related standards.
- Serve as a subject matter expert on security and compliance matters.
- Plan and execute framework audits, collect and validate evidence, perform control testing, and assess procedural compliance.
- Identify, document, and track audit findings, remediation plans, and control improvements.
- Partner with business and technology teams to ensure successful audit outcomes and ongoing compliance.
- Maintain knowledge of business systems, processes, regulations, and industry best practices.
Risk Management
- Monitor emerging security, privacy, and regulatory risks affecting the business.
- Conduct risk assessments and support risk register maintenance and treatment activities.
- Evaluate and score risks related to audit findings, exceptions, and attestations.
- Monitor, report, and escalate identified risks while driving remediation to acceptable risk levels.
- Collaborate with stakeholders to ensure risk exposure remains within approved tolerances.
Security Governance & Reporting
- Monitor compliance with security standards and controls.
- Review security metrics, compliance KPIs, and governance reports.
- Support security awareness and compliance initiatives.
- Prepare compliance and risk reports for management and key stakeholders.
Stakeholder & Customer Support
- Respond to customer security questionnaires, due diligence requests, and regulatory inquiries.
- Build strong relationships with internal and external stakeholders.
- Provide timely issue resolution, recommendations, and process improvements.
- Support projects from planning through completion, including reporting and recommendations.
Required Qualifications
Experience
- 3–4 years of experience in:
- Information Security
- Cybersecurity Compliance
- Governance, Risk & Compliance (GRC)
- IT Audit or Security Assurance
Compliance & Risk Knowledge
Robust understanding of
- ISO 27001
- SOC 2
- NIST Cybersecurity Framework
- GDPR
- Risk Management methodologies
Technical Knowledge
Working knowledge of
- Identity & Access Management (IAM)
- Multi-Factor Authentication (MFA)
- Vulnerability Management
- Logging & Monitoring
- Cloud Security fundamentals (Azure, AWS, GCP)
- Secure Change Management
- Data Protection & Encryption
Core Skills
- Audit coordination and evidence management
- Risk assessment and control testing
- Policy and procedure reviews
- Compliance reporting and documentation
- Stakeholder management and communication
Tools
Experience with
- Microsoft 365
- Word and Excel (reporting and analysis)
- SharePoint / OneDrive
- GRC platforms such as Drata, Archer, LogicGate, or ServiceNow GRC
Education Bachelor’s degree in information security, Computer Science, IT, Risk Management, or a related field.
Preferred Qualifications
Certifications
- ISO 27001 Internal Auditor or Lead Auditor
- Security+
- Certified in Cybersecurity (CC)
- CISA
Additional Knowledge
- DORA, CCPA, NYDFS
- Azure Defender / Security Center
- AWS Security Services
- Compliance metrics and KPI reporting
Soft Skills
- Executive presentations
- Project management
- Process improvement
- Training and coaching
- Cross-functional collaboration
Location: This role will be based out of The Leela Office located on the 4th Floor, Airport Road, Kodihalli, Bangalore- 560008. Work Timing : 1 pm to 10 pm IST. Cab Pick-up and drop available.
Hybrid : Our expectation at this time, is that you would work from our office on Tuesdays, Wednesdays, Thursdays with flexibility to work from home on Mondays and Fridays.
📌 Control Advisor (Bengaluru)
🏢 Notified
📍 Bengaluru