Company: INTERCERT
Position: Information Security & Compliance Auditor
Experience: 3–4 Years
Location: Noida / Bengaluru
Employment Type: Full-Time
About the Role
INTERCERT is looking for an experienced Information Security & Compliance Auditor with 3–4 years of experience in GRC, Information Security Audits and Compliance Assessments. The primary focus of this role will be HITRUST CSF, along with ISO 27001 and Indian regulatory cybersecurity requirements.
The candidate will be responsible for conducting/supporting audits, assessing controls, reviewing evidence, identifying gaps, preparing audit reports, and interacting with clients.
Key Responsibilities
- Conduct and support HITRUST CSF assessments and readiness assessments.
- Perform ISO/IEC 27001:2022 audits and compliance assessments.
- Review policies, procedures, risk assessments, technical and operational controls, and audit evidence.
- Conduct control testing, stakeholder interviews and evidence validation.
- Identify gaps, non-conformities and areas for improvement.
- Prepare audit working papers, compliance matrices and detailed audit reports.
- Support remediation activities and closure of audit findings.
- Conduct cybersecurity and regulatory compliance assessments based on applicable requirements.
- Interact with clients, IT teams, cybersecurity teams and management.
- Manage multiple audit assignments and ensure timely delivery.
Regulatory & Compliance Exposure The candidate should have knowledge or exposure to audits/assessments based on:
- RBI – Cybersecurity,
IT Governance & IT Audits
- NPCI – Payment Security & Compliance
- IRDAI – Insurance Cybersecurity & IT Compliance
- SEBI – Cybersecurity & Cyber Resilience
- CERT-In – Cybersecurity requirements and compliance
- DLSAR / Digital Lending requirements
- CICRA / Critical Information Infrastructure requirements
Additional exposure to SOC 2, HIPAA, PCI DSS, ISO 27701, NIST, CIS Controls, GDPR and DPDP will be an advantage.
Required Skills
- Strong understanding of HITRUST CSF – Primary Requirement
- Good knowledge of ISO/IEC 27001:2022
- Information Security & GRC Auditing
- Risk & Control Assessment
- Evidence Review and Control Testing
- Audit Report Preparation
- Regulatory Compliance
- Strong documentation and analytical skills
- Valuable client communication and presentation skills
Qualifications & Certifications
- Bachelor's degree in IT, Computer Science, Cybersecurity, Information Security or related field.
- 3–4 years of relevant experience in Information Security, GRC, IT Audit or Cybersecurity Compliance.
- HITRUST-related certification or practical HITRUST assessment experience is highly preferred.
- Certifications such as HITRUST CCSFP, ISO 27001 Lead Auditor/Implementer, CISA or equivalent will be an advantage.
Interested Candidates share the CV's on
[email protected] #HITRUST #HITRUSTCSF #HITRUSTAssessment #HITRUSTCertified #ISO27001 #ISO27001Auditor #ISO27001LeadAuditor #ISO27701 #SOC2 #SOC2Compliance #PCI DSS #NIST #CISControls
📌 Information Security Compliance Consultant (Noida)
🏢 INTERCERT
📍 Noida