Skip to main content
Posted 19 July, 2026

GRC - Security Audit

ClifyX
India Full Time
Reference: 365_594563_25-06019

ECMS Requirement Format

Number of Openings

2

ECMS ID in sourcing stage

539204

Assignment Duration

12 months

Total Yrs. of Experience

More than 3 years of experiences of cybersecurity domain, including but not limited to risk assessment, security operation, penetration test, network deployment, data privacy, etc.

Familiar with auditing methodology and providing solution to risk findings

Obtained related certifications, e.g.: CISSP, CISA, ISO27001LA, CEH, OSCP, CCSP, etc.

Relevant Yrs. of experience

Minimum 5 years relevant experience in cybersecurity with a focus on governance, risk and compliance.

Detailed JD (Roles and Responsibilities)

The Security Auditing SME is responsible for executing security assessments across infrastructure, applications, and data environments. This role ensures robust protection against threats by applying deep expertise in audits, network and firewall security, and secure application design.

Key Responsibilities :

Perform onsite audits for security compliance review at client locations as well as client vendor offices.

Conduct comprehensive security audits across systems, applications, and networks.

Review vulnerability assessment and penetration testing reports for web, mobile, and cloud-based applications.

Evaluate network security controls, including segmentation, IDS/IPS, and firewall configurations.

Validate data security by reviewing encryption standards, access control policy& process, and secure storage practices.

Review and validate firewall rules, policies, and change management processes.

Document findings, provide remediation guidance, and support compliance with standards like ISO 27001, NIST

Service #1: Onsite & Remote CM audit :

Objective: Provide resources to assist Apple's new product security team in performing Security Assessments of CM sites under Apple's supervision. Sample activities include:

Arrange resources with the required skillset and experience as described by Apple to execute CM Electronic Security Assessments

Participate in training and workshops organized by Apple's security team to understand the CM Electronic Security Assessment requirements

Conduct Electronic Security Assessments as planned and document results for Apple's security team

Track CM's discrepancy items against Apple security standard (SRAS) and assist with follow-ups on the remediation on a weekly basis

Consultant will use Apple's methodologies and reporting templates throughout the course of this engagement.

DELIVERABLES:

Service #1: Onsite & Remote CM audit

Consultant to perform spell check and review for consistency in CM naming convention prior to delivery of draft reports to Apple

Consultant must deliver each CM ESA finding report and CM site reporting master data based on testing performed to date

Sample activities include :

Collect security control logs of CM-related threat scenarios

Develop and design the key threat scenarios use case and monitoring metrics

Develop multiple Security applications, factory security control systems and other tools to enhance the security monitoring and operation capabilities. Through the develop support to help Apple construct the end-to-end security monitoring system.

Integrate relevant monitoring metrics, analysis processes and corresponding measures into platform-based tools or products

Related tools or products hosting, maintenance and upgradation

Continuous log monitoring, Security Operation and incident response support in accordance with agreed service processes and SLAs.

Mandatory skills

1. Resources who have worked on remediating audit findings

2. Resource should have working knowledge on CCM

3. Resource should have excellent oral and written skills (as they will have to communicate with Supplier leadership)

Desired/ Secondary skills

Have knowledge on multiple security domains.

Domain

GRC – Security Audit

Max Vendor Rate in Per Day (Currency in relevance to work location)

11500 INR / Day

Work Location given in ECMS ID

Bangalore, Chennai only

WFO/WFH/Hybrid WFO

Hybrid WFO

BG Check (Before OR After onboarding)

After

Is there any working in shifts from standard Daylight (to avoid confusions post onboarding) YES/ NO

YES

Sign up for Job Alerts