Manager For SOC 2 Type 2 Consultant (New Delhi)

Manager For SOC 2 Type 2 Consultant (New Delhi)

11 Sep
|
RAM Kala Verma
|
New Delhi

11 Sep

RAM Kala Verma

New Delhi

Job Role: SOC 2 Type 2 Consultant Manager

Department: Information Security / Compliance / Risk Management

Reports To: Head Information Security / Compliance Manager

Employment Type: Full-Time

Location: NSP, Pitampura or Noida

Job Purpose The SOC 2 Type II Consultant is responsible for helping organizations prepare for and maintain compliance with the AICPA Trust Services Criteria (TSC), including Security and, where applicable, Availability, Confidentiality, Processing Integrity, and Privacy.

The consultant will assess existing controls, identify gaps, support remediation, prepare policies and evidence, coordinate control testing, and assist management throughout the SOC 2 Type II audit readiness and examination period.

Important: The consultant supports SOC 2 readiness and implementation. The formal SOC 2 Type II attestation report must be issued by an eligible independent CPA firm or accounting organization.

Key Responsibilities

- Conduct SOC 2 readiness and gap assessments against applicable Trust Services Criteria.
- Understand the organization's business processes, infrastructure, applications, cloud environment, data flows and security architecture.
- Determine applicable SOC 2 Trust Services Criteria based on the organization's services and customer commitments.
- Develop and maintain the SOC 2 compliance roadmap and implementation plan.
- Design, document and improve security and operational controls.
- Prepare and review policies, procedures, standards, registers and supporting records.
- Develop the SOC 2 control matrix and map controls to applicable Trust Services Criteria.
- Assist in defining system boundaries and preparing the SOC 2 system description.
- Identify control owners and define responsibilities for implementation and evidence maintenance.
- Conduct risk assessments and maintain risk treatment/action plans.
- Review logical access controls, including:

- User access provisioning

- Access modification

- User termination

- Privileged access

- MFA

- Periodic access reviews
- Review change-management controls covering development, testing, approval and production deployment.
- Review vulnerability management, patch management, endpoint security and configuration-management controls.
- Review security incident management and incident-response records.
- Assess vendor and third-party risk-management controls.
- Review backup,



disaster recovery and business-continuity arrangements.
- Review employee onboarding, background verification, security awareness and offboarding controls.
- Assess logging, monitoring, alerting and security-event management.
- Define and track corrective actions for identified gaps.
- Conduct periodic control-effectiveness reviews throughout the Type II observation period.
- Maintain an evidence tracker and ensure evidence is complete, current and traceable.
- Review evidence before submission to the independent SOC auditor.
- Coordinate with process owners, IT teams, HR, legal, management and external auditors.
- Assist management in responding to auditor requests, observations and exceptions.
- Support remediation of control exceptions identified during the audit.
- Conduct internal readiness reviews before commencement of the formal SOC 2 Type II examination.
- Support continuous compliance after completion of the SOC 2 engagement.

Key Documents / Deliverables The consultant should be capable of preparing or reviewing:

- SOC 2 Readiness Assessment Report
- Gap Analysis Report
- SOC 2 Control Matrix
- Trust Services Criteria Mapping
- System Description
- Information Security Policy
- Access Control Policy
- Password and Authentication Policy
- Change Management Procedure
- Incident Response Plan
- Risk Assessment and Risk Register
- Vendor Risk Management Procedure
- Business Continuity Plan
- Disaster Recovery Plan
- Backup Procedure
- Vulnerability and Patch Management Procedure
- Security Awareness and Training Records
- Employee Onboarding and Offboarding Controls
- Asset Register
- Access Review Records
- Change Records
- Incident Register
- Vendor Assessment Records
- Business Continuity / DR Test Records
- Control Evidence Tracker
- Corrective Action Tracker

Educational Qualification

Required:

- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Security, Engineering, Commerce, Management or a related field.

Experience Preferred: 1-3 years of relevant experience in one or more of the following:





- SOC 2 readiness or implementation
- Information security
- IT audit
- Cybersecurity compliance
- Governance, Risk and Compliance (GRC)
- ISO/IEC 27001
- Internal controls
- Cloud security
- Third-party risk management

Hands-on experience supporting at least one SOC 2 Type I or Type II engagement is strongly preferred. Technical Knowledge The candidate should understand:

- AICPA Trust Services Criteria
- SOC 2 Type I vs. Type II
- Control design and operating effectiveness
- Risk assessment
- Information-security governance
- Identity and Access Management
- Cloud environments such as AWS, Azure or Google Cloud
- Microsoft 365 / Google Workspace
- Vulnerability and patch management
- Endpoint security
- Network security
- Logging and monitoring
- Secure SDLC
- Change management
- Incident response
- Business continuity and disaster recovery
- Vendor risk management

Working knowledge of ISO/IEC 27001, NIST CSF, CIS Controls or similar frameworks is beneficial.

Preferred Certifications

Any of the following are advantageous:

- CISA
- CISM
- CISSP
- ISO/IEC 27001 Lead Auditor
- ISO/IEC 27001 Lead Implementer
- CRISC
- CCSP
- Security+
- Relevant cloud-security certification

Key Skills

- Strong understanding of information-security controls
- Gap-analysis and risk-assessment capability
- Policy and procedure drafting
- Control-testing skills
- Audit-evidence review
- Documentation and report writing
- Project management
- Client communication
- Stakeholder coordination
- Analytical and problem-solving skills
- Ability to manage multiple control owners and deadlines
- Solid attention to evidence consistency and traceability

Key Performance Indicators Performance can be measured against:

- Completion of SOC 2 readiness assessment within agreed timeline
- Percentage of identified gaps closed before the audit period
- Percentage of controls operating effectively
- Timely collection of control evidence
- Number of audit exceptions
- Timely closure of auditor observations
- Completion of periodic control reviews
- Accuracy and completeness of SOC 2 documentation
- Successful completion of the SOC 2 Type II examination

Role Authority The SOC 2 Consultant may recommend control improvements, request evidence, perform readiness assessments and coordinate remediation activities. Call: Ms. Manshi

Share CV at: +91 97171 95141

📌 Manager For SOC 2 Type 2 Consultant (New Delhi)
🏢 RAM Kala Verma
📍 New Delhi

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: manager for soc 2 type 2 consultant (new delhi) / new delhi

Subscribe to this job alert:

Get the latest job offers by email for: manager for soc 2 type 2 consultant (new delhi) / new delhi