Posted:1 week ago|
Platform:
On-site
Full Time
Location: Bengaluru (On-site/Hybrid based on project need)
Experience Range: 4 to 6 Years
Job Type: Full-Time
Analyze stakeholder needs and ensure compliance with ISO 27001 and internal security policies. Support business analysis tasks with a focus on information security, audit planning, and risk assessment. Act as an internal control specialist, contributing to audits, risk assessments, and business continuity plans.
Audit & Compliance
Conduct internal and vendor audits to verify compliance with ISO 27001 standards.
Collaborate with ISMS champions to enforce security policies and procedures.
Prepare for and participate in external audits for ISO certifications.
Review and maintain up-to-date documentation related to ISO 27001 and other standards.
Ensure documentation readiness for audits and compliance checks.
Risk Management
Conduct risk assessments for business processes, third-party applications, and systems.
Facilitate Business Impact Analysis (BIA) and Risk Assessments.
Support the development and execution of the Business Continuity Plan (BCP).
Identify and document security risks, controls, and mitigation plans.
Stakeholder Engagement
Interface with business stakeholders, explain technical vulnerabilities in simple terms.
Coordinate with teams across functions to enforce ISMS and compliance activities.
Document and present risk management activities to senior management.
Manage internal communications through email, reports, and presentations.
Process & Documentation
Maintain and review policies, SOPs, process flows, and compliance reports.
Develop and update presentations to report risk management activities to leadership.
Contribute to improvement of audit and compliance processes.
Ensure effective use of BA tools, templates, and communication artifacts.
Risk Management and Risk Assessment
ISO 27001 Auditing and Compliance
Internal and Vendor Audits
Business Continuity Planning (BCP)
Business Impact Analysis (BIA)
Stakeholder Management and Communication
Cybersecurity / Information Security Standards (ISO 27001, NIST CSF)
Excellent documentation, presentation, and reporting skills
Familiarity with vulnerability management and technical risk analysis.
Understanding of third-party risk and vendor assessments.
Use of tools for audit tracking and documentation (e.g., GRC tools).
Knowledge of data privacy regulations (e.g., GDPR, HIPAA).
Exposure to cloud security and application security fundamentals.
B.E. / B.Tech. / MCA / MBA with specialization in Information Security
ISO 27001 Lead Auditor Certification
You will be part of the Risk & Compliance team responsible for conducting audits, managing information security risks, and ensuring adherence to ISO 27001 standards. You will collaborate with multiple stakeholders, manage documentation, and support audit readiness throughout the year.
Strong analytical and problem-solving skills
Excellent time and task management
Ability to convey complex technical concepts to non-technical audiences
High attention to detail and proactive communication
Risk Management,Risk assesment,Compliance,Audit planning, Internal audit, Auditing
UST Global
Upload Resume
Drag or click to upload
Your data is secure with us, protected by advanced encryption.
Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.
We have sent an OTP to your contact. Please enter it below to verify.
Bengaluru, Karnataka
Salary: Not disclosed
3.4 - 8.85 Lacs P.A.
Kochi, Kerala
Salary: Not disclosed
Kochi, Kerala, India
Experience: Not specified
Salary: Not disclosed
Gurgaon, Haryana, India
Experience: Not specified
Salary: Not disclosed
Kochi, Chennai, Thiruvananthapuram
6.0 - 10.0 Lacs P.A.
Chennai, Tamil Nadu, India
Salary: Not disclosed
Hyderabad, Telangana, India
Salary: Not disclosed
Bengaluru, Karnataka
Salary: Not disclosed
3.4 - 8.85 Lacs P.A.