Posted 19 August, 2026
Sr. Consultant - Compliance
TAC Security
Delhi, DL, IN
Full Time
Reference: c462c186bd03dd29
Job Description
Job Description:
\n- \n
- Hands-on experience in SOC 2 Type I and Type II implementation/readiness and delivery. \n
- Strong understanding of AICPA Trust Services Criteria (TSC). \n
- Experience with control mapping, gap assessments, evidence collection and validation. \n
- Understanding of Type II observation periods, control operating effectiveness and exceptions. \n
- Experience coordinating with external auditors/CPA firms. \n
- Ability to manage SOC 2 engagements from kickoff through audit closure. \n
2. ISO 27001 Expertise
\n- \n
- Strong understanding of ISO/IEC 27001:2022 requirements. \n
- Experience implementing and maintaining an Information Security Management System (ISMS). \n
- Conducting ISO 27001 gap assessments and readiness assessments. \n
- Understanding of Annex A controls and applicability assessment. \n
- Experience with: \n
- Risk assessment and risk treatment \n
- Statement of Applicability (SoA) \n
- Information security policies and procedures \n
- Internal audits \n
- Management reviews \n
- Corrective actions / NC management \n
- Continual improvement \n
- ISMS metrics and monitoring \n
- Experience supporting organizations through ISO 27001 certification audits. \n
- Understanding of Stage 1 and Stage 2 audit processes. \n
3. Governance, Risk & Compliance (GRC)
\n- \n
- Strong understanding of GRC frameworks and principles. \n
- Ability to establish and maintain governance processes. \n
- Experience with: \n
- Risk management \n
- Control frameworks \n
- Compliance assessments \n
- Regulatory requirements \n
- Policy governance \n
- Exception management \n
- Risk acceptance \n
- Corrective and preventive actions \n
- Compliance monitoring \n
- Ability to map controls across multiple frameworks such as SOC 2, ISO 27001, PCI DSS, GDPR, HIPAA, etc. \n
4. Compliance & Audit Management
\n- \n
- Manage internal and external compliance assessments. \n
- Prepare organizations for certification and attestation audits. \n
- Develop audit plans, evidence trackers and compliance calendars. \n
- Review audit evidence for completeness and adequacy. \n
- Manage audit observations, non-conformities and corrective actions. \n
- Coordinate with auditors and stakeholders to resolve audit queries. \n
- Maintain appropriate audit trails and compliance documentation. \n
5. Risk Management
\n- \n
- Conduct information security risk assessments. \n
- Identify, assess and prioritize organizational risks. \n
- Develop Risk Treatment Plans (RTPs). \n
- Maintain risk registers. \n
- Evaluate residual risk and risk acceptance. \n
- Support business owners in implementing appropriate risk mitigation measures. \n
6. Policies & Documentation
\nCandidate should be comfortable creating/reviewing:
\n- \n
- Information Security Policy \n
- ISMS documentation \n
- Risk Management Policy \n
- Access Control Policy \n
- Incident Management Policy \n
- Business Continuity/DR policies \n
- Vendor Risk Management Policy \n
- Change Management Policy \n
- Secure SDLC policies \n
- Data Protection/Privacy policies \n
- Business Continuity documentation \n
- Control procedures and work instructions \n
7. Client & Stakeholder Management
\n- \n
- Conduct client discovery and kickoff meetings. \n
- Understand business processes, technology environments and compliance requirements. \n
- Act as the primary delivery contact for clients. \n
- Conduct regular status meetings. \n
- Track milestones, dependencies, risks and deliverables. \n
- Communicate compliance requirements clearly to technical and non-technical stakeholders. \n
- Manage escalations and ensure timely closure of deliverables. \n
8. Technical Security Understanding
\nCandidate should have a good working understanding of:
\n- \n
- AWS / Azure / GCP \n
- IAM, SSO and MFA \n
- Vulnerability management \n
- Secure SDLC \n
- Change management \n
- Incident response \n
- Logging and monitoring \n
- Encryption \n
- Backup and DR \n
- Endpoint security \n
- Network security \n
- Asset management \n
- Vendor/third-party security \n
- Data protection \n
They don't need to be a penetration tester or security engineer, but should be able to understand technical controls and assess their compliance implications.
\nKey Skills
\nMust Have:
\n- \n
- SOC 2 Type I/II \n
- ISO 27001:2022 \n
- ISMS implementation \n
- GRC \n
- Risk assessment & treatment \n
- Control assessment \n
- Audit management \n
- Evidence review \n
- Compliance management \n
- Policy/procedure development \n
- Client management \n
- Strong documentation and communication skills \n
Good to Have:
\n- \n
- CISA / CISSP / CRISC \n
- ISO 27001 Lead Auditor / Lead Implementer \n
- ISO 27701 \n
- PCI DSS \n
- HIPAA \n
- GDPR \n
- NIST CSF / NIST 800-53 \n
- CSA CCM \n
- Experience with GRC platforms such as Vanta, Drata, Secureframe, OneTrust, etc. \n