02 Sep
|
Ascendion
|
Bengaluru
02 Sep
Ascendion
Bengaluru
Security Compliance & Audit Specialist
Experience: 5+ Years
Location: Hyderabad
Work Mode: Hybrid – 2 Days Work from Office
Employment Type: Full-time
Role Overview
We are looking for a Security Compliance & Audit Specialist to join the Security team and drive security compliance, audit readiness, risk management, and governance initiatives. The role will involve working closely with Technology, Product, Cloud, Infrastructure, and Security teams to ensure alignment with security frameworks, internal policies, and regulatory requirements.
Key Responsibilities
- Lead and support internal, external, customer, and regulatory security audits.
- Drive compliance initiatives aligned with NIST CSF, NIST 800-53, SOC 2, ISO 27001, and CIS Controls.
- Conduct risk assessments, control reviews, compliance gap analysis, and remediation tracking.
- Manage audit findings, risks, exceptions, and corrective action plans through closure.
- Coordinate audit evidence collection, control testing, and auditor engagements.
- Develop and maintain security policies, standards, procedures, and compliance documentation.
- Support customer security assessments, security questionnaires, due diligence, and third-party risk evaluations.
- Prepare executive presentations, dashboards, KPIs, compliance reports, and security metrics.
- Work with Cloud and Infrastructure teams on AWS and Azure security controls and compliance.
- Leverage AI and automation tools to improve audit readiness, reporting, and compliance monitoring.
- Communicate security risks, audit outcomes, and compliance status to technical and business stakeholders.
Required Skills
- 5+ years of experience in Information Security, GRC, Security Compliance, Audit, or Risk Management.
- Strong knowledge of NIST, SOC 2, ISO 27001, and CIS Controls.
- Hands-on experience with security audits, risk assessments, control evaluations, and remediation management.
- Understanding of Access Management, Vulnerability Management, Incident Response, Security Monitoring, Data Protection, and Third-Party Risk.
- Working knowledge of AWS and Azure security controls and governance.
- Experience preparing compliance reports, dashboards, KPIs, and executive presentations.
- Robust stakeholder management, communication, and analytical skills.
Good to Have
- Experience with GRC platforms such as Archer.
- Security certifications such as CISA, CISSP, CISM, CRISC, Security+, or ISO 27001 Lead Auditor.
- Experience with customer audits and large enterprise environments.
- Experience using Microsoft Copilot, Claude, ChatGPT, Power BI, or security analytics platforms for compliance and reporting automation.
📌 Info/Security - Analyst (Bengaluru)
🏢 Ascendion
📍 Bengaluru