02 Sep
|
TAC Security
|
Delhi
02 Sep
TAC Security
Delhi
. Management System & ISO Expertise
Strong working knowledge and hands-on implementation experience with:
- ISO/IEC 27001:2022 – Information Security Management System (ISMS)
- ISO 9001:2015 – Quality Management System (QMS)
- ISO/IEC 17025:2017 – Testing & Calibration Laboratory Competence
- ISO 27701 – Privacy Information Management System
- ISO 22301 – Business Continuity Management System
- ISO 31000 – Risk Management
- Other relevant ISO standards and industry-specific compliance frameworks.
Must be able to understand the relationship and common requirements across multiple management systems and identify opportunities for an integrated management system.
- Lead Implementer Capability
- Should have hands-on experience leading ISO implementation projects, preferably as a Lead Implementer.
- Perform initial gap assessments against applicable standards.
- Develop implementation roadmaps and compliance plans.
- Establish and maintain management system processes.
- Define policies, procedures, SOPs, work instructions and control requirements.
- Define roles, responsibilities and accountability.
- Maintain required records and documented information.
- Coordinate implementation activities across different departments.
- Track implementation milestones and closure of gaps.
3. Internal Audit Candidate should be capable of independently planning and conducting internal audits.
Responsibilities include
- Develop annual/monthly internal audit plans.
- Prepare audit checklists and audit criteria.
- Conduct process and control-based audits.
- Interview process owners and assess implementation/effectiveness.
- Collect and evaluate objective evidence.
- Identify:
- Non-conformities
- Observations
- Opportunities for improvement
- Risks
- Prepare formal internal audit reports.
- Track corrective actions to closure.
- Verify effectiveness of corrective actions.
- Maintain complete audit records.
4. External Audit Management Should be comfortable managing certification/accreditation and surveillance audits.
- Coordinate with external auditors and certification/accreditation bodies.
- Prepare the organization for Stage 1, Stage 2, surveillance and reassessment audits.
- Develop audit schedules and coordinate auditor requirements.
- Manage evidence/document requests.
- Coordinate responses to auditor queries.
- Support process owners during audits.
- Manage NCs and observations raised during external audits.
- Prepare corrective action plans and supporting evidence.
- Coordinate NC closure with auditors/assessors.
- Maintain audit history and lessons learned.
For ISO/IEC 17025, experience coordinating with accreditation bodies such as A2LA, NABL, UKAS, etc. would be a solid advantage.
- Compliance & Governance
Strong understanding of Governance, Risk & Compliance (GRC) principles.
Experience with
- Compliance frameworks
- Regulatory requirements
- Corporate governance
- Internal controls
- Risk management
- Control ownership
- Compliance monitoring
- Exception management
- Risk acceptance
- Corrective/preventive actions
- Management reporting
- Compliance calendars
- Governance committees
- Management reviews
The candidate should be able to establish a structured compliance governance program, rather than simply maintaining documentation.
- Risk Management
- Conduct organizational and information security risk assessments.
- Maintain enterprise/process-level risk registers.
- Identify and evaluate risks.
- Define risk treatment plans.
- Track mitigation activities.
- Evaluate residual risk.
- Coordinate risk acceptance with management.
- Periodically review and update risks.
- Integrate risk management into ISO 27001, ISO 9001 and other management systems.
7. Documentation & Management System Strong documentation skills with the ability to develop and maintain:
- Policies
- Procedures
- SOPs
- Work instructions
- Control matrices
- Risk registers
- Risk treatment plans
- Statements of Applicability
- Quality manuals
- Process documents
- Internal audit programs
- Management review records
- Corrective action records
- Compliance registers
- Training/competency records
- Master document lists
- Records retention requirements
8. Corrective Action & Continual Improvement
- Manage Non-Conformity (NC) lifecycle.
- Perform root cause analysis.
- Develop corrective action plans.
- Identify immediate correction vs. corrective action.
- Track implementation.
- Validate objective evidence.
- Perform effectiveness checks.
- Identify systemic issues.
- Drive continual improvement across management systems.
9. ISO 17025-Specific Knowledge For your requirement,
I would make this a key differentiator.
Candidate should understand
- Impartiality
- Confidentiality
- Structural requirements
- Resource requirements
- Personnel competence
- Equipment management
- Metrological traceability
- Externally provided products/services
- Review of requests, tenders and contracts
- Method selection, verification and validation
- Sampling
- Handling of test/calibration items
- Technical records
- Reporting
- Complaints
- Nonconforming work
- Data and information management
- Management system requirements
- Internal audits
- Management reviews
- Corrective actions
10. ISO 9001 / Quality Management
Experience with
- Quality objectives and KPIs
- Process mapping
- Quality risks
- Customer requirements
- Document control
- Change management
- Supplier evaluation
- Non-conforming outputs
- CAPA
- Customer complaints
- Internal audits
- Management reviews
- Continual improvement
11. ISO 27001 / Information Security Governance
Candidate should understand
- ISMS governance
- Information security risk assessment
- Risk treatment
- Statement of Applicability
- Annex A controls
- Asset management
- Access control
- Incident management
- Business continuity
- Supplier security
- Security awareness
- Vulnerability management
- Secure development
- Change management
- Logging and monitoring
- Internal audits
- Management reviews
12. Stakeholder Management
- Work with CTO, CISO, Quality, HR, Legal, Finance, Engineering, Operations and other process owners.
- Drive compliance ownership across departments.
- Conduct compliance awareness/training sessions.
- Present compliance status and risks to senior management.
- Challenge process owners where controls are not adequately implemented.
- Coordinate cross-functional corrective actions.
13. Compliance Reporting & Governance Metrics Should be able to develop management dashboards covering:
- Compliance status
- Open/closed NCs
- Audit findings
- Corrective action status
- Risk status
- Policy review status
- Training compliance
- Internal audit completion
- External audit readiness
- Control effectiveness
- Upcoming certification/accreditation activities
14. Preferred Certifications
Strongly preferred:
- ISO 27001 Lead Implementer
- ISO 27001 Lead Auditor
- ISO 9001 Lead Auditor/Lead Implementer
- ISO/IEC 17025 Internal Auditor / Lead Auditor
- CISA
- CISM
- CISSP
- CRISC
Additional advantage:
- ISO 27701
- ISO 22301
- ISO 31000
- PCI DSS
- SOC 2
- GDPR
- NIST
📌 Internal Compliance Specialist (Delhi)
🏢 TAC Security
📍 Delhi