01 Sep
|
Airtel Digital
|
Noida
01 Sep
Airtel Digital
Noida
Job Description
Certification & Compliance Leadership
n
n
Own and lead the end-to-end strategy, implementation, certification, audit, maintenance, and continual improvement of cloud compliance and assurance programs across Airtel Cloud services, platforms, products, infrastructure, and shared services.
n
n
Lead certification and attestation activities for:
n
n
- MeitY Empanelment / Government Cloud Compliance (GI Cloud / MeghRaj)
n
- ISO/IEC 27001:2022 (ISMS)
n
- ISO/IEC 27017 & ISO/IEC 27018
n
- ISO/IEC 27701 (Privacy Information Management System)
n
- ISO 22301 (Business Continuity Management System)
n
- ISO 20000-1 (IT Service Management)
n
- ISO 9001 (Quality Management System)
n
- SOC 1 Type I & Type II
n
- SOC 2 Type I & Type II/ISAE 3402
n
- SOC 3
n
- PCI DSS
n
- Uptime Institute Tier Certification
n
- CSA STAR
n
- CMMI Level 3
n
- GCC (Government Cloud Compliances)
n
- DPDPA
n
- Any emerging regulatory, customer, industry, or telecom-specific assurance requirements.
n
n
n
Governance & Program Management
n
n
- Establish and maintain an enterprise-wide compliance and certification roadmap aligned with business objectives and regulatory requirements.
n
- Manage multiple certification, surveillance, recertification, and attestation programs concurrently.
n
- Act as the single point of accountability for external auditors, certification bodies, assessors, regulators, and customer assurance teams.
n
- Drive organization-wide compliance readiness through governance forums, compliance reviews, risk assessments, and control monitoring.
n
- Develop certification dashboards, executive reporting, and compliance status updates for senior leadership.
n
n
n
System and Organization Controls (SOC) & Assurance Program Management
n
n
- Lead SOC 1, SOC 2, ISAE 3402 and SOC 3 attestation programs from readiness assessment through final report issuance.
n
- Drive control design reviews, evidence management, auditor coordination, remediation tracking, and management responses.
n
- Lead development of system descriptions, management assertions, service commitments, control narratives, Trust Services Criteria mapping, and final assurance reports.
n
- Support customer assurance requests, due diligence activities, and third-party security assessments using approved compliance artefacts and attestation reports.
n
n
n
Regulatory & MeitY Compliance
n
n
- Lead compliance activities related to MeitY empanelment and Government Cloud Compliance requirements.
n
- Ensure adherence to data residency requirements, cloud governance mandates, and applicable Government of India guidelines.
n
- Coordinate and manage STQC assessments and audits.
n
- Maintain compliance with applicable Indian cybersecurity, privacy, telecom, and data protection regulations.
n
n
n
Policy, Standards & Control Management
n
n
- Develop, maintain, and enhance security policies, standards, procedures, and governance frameworks aligned to certification requirements.
n
- Ensure business processes are designed, operated, and evidenced in compliance with certification and regulatory obligations.
n
- Drive standardization and maturity improvement across cloud operations, engineering, service delivery, and support functions.
n
n
n
Audit & Continuous Improvement
n
n
- Lead Stage 1, Stage 2, Surveillance, Recertification, Customer, Internal, Regulatory, and Third-Party audits. Manage external certification bodies.
n
- Coordinate internal audit programs and Management Review Board activities.
n
- Track audit findings, non-conformities, observations, and corrective/preventive action plans through closure.
n
- Drive continual improvement initiatives and automation opportunities for evidence collection, monitoring, and compliance reporting.
n
- Support customer audits, third-party questionnaires and due diligence responses by leveraging SOC reports, control assertions and approved compliance artefacts.
n
- Support continuous compliance improvement by identifying repeat issues, control design gaps and automation opportunities for evidence collection and monitoring.
n
n
n
n
Control Assurance
n
Oversee assessment and effectiveness of key controls including:
n
n
- Identity & Access Management
n
- Privileged Access Management
n
- Change Management
n
- Incident Response
n
- Vulnerability Management
n
- Security Monitoring & Logging
n
- Vendor Risk Management
n
- Data Protection & Privacy Controls
n
- Backup & Recovery
n
- Business Continuity & Disaster Recovery
n
- Cloud Security Governance
n
- IT Service Management Controls
n
n
📌 GRC- Cloud security Risk & Compliance Manager(6-12 Years) (Noida)
🏢 Airtel Digital
📍 Noida