Senior Security & Compliance Consultant

5 years

0 Lacs

Posted:1 week ago| Platform: Linkedin logo

Apply

Work Mode

Remote

Job Type

Contractual

Job Description

Job Title:

Company:

Location:

Compensation:


The Senior Security & Compliance Consultant will oversee the full lifecycle of Company's information security operations, including SOC 2 (BDO) and ISO 27001 audits, penetration and vulnerability testing, RFP security responses, and policy management. This role requires hands-on experience with security frameworks, vendor risk management, and compliance documentation.

You’ll work closely with Company's Legal, IT, and Engineering teams to maintain a secure and audit-ready environment aligned with industry standards.


Key Responsibilities


Audit, Certification & Governance

  • Serve as internal lead for SOC 2, ISO AI, and ISO 27001 readiness, evidence collection, and auditor coordination.
  • Maintain and update Company's Statement of Applicability (SOA) and control library.
  • Manage security responses for client RFPs and due diligence questionnaires.


Security Operations

  • Oversee penetration testing and vulnerability testing (Tenable.io) cycles; track and validate remediation.
  • Maintain and enforce security-related policies, including access control, incident response, and DPA compliance.
  • Conduct monthly IT security plan reviews and update internal reports.
  • Manage change control, vendor security protocols, and breach notification procedures.


Risk & Asset Management

  • Conduct and document monthly risk assessments, including:
  • Review of Advanced Networks reports
  • Permission changes and audit logs
  • Data asset inventory
  • Hardware asset management and secure disposal tracking
  • Support vendor due diligence, reviewing risk scores, contracts, and compliance posture.


Documentation & Continuous Improvement

  • Maintain a comprehensive repository of policies, risk assessments, and testing results.
  • Recommend process or control improvements based on audit findings and security trends.
  • Support Legal with client and regulator data protection obligations (GDPR, CCPA, etc.).


Qualifications

  • 5+ years in information security, risk, or compliance (ideally within SaaS or regulated industries).
  • Direct experience with SOC 2, ISO 27001, or similar control frameworks.
  • Working knowledge of Tenable.io, or equivalent vendor risk platforms.
  • Strong understanding of data protection, access control, and change management.
  • Excellent writing and analytical skills; able to draft RFP responses and security documentation clearly.
  • Certifications (preferred): CISA, CISSP, CRISC, or ISO 27001 Lead Implementer.

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
Confidential logo
Confidential

Technology

Silicon Valley

RecommendedJobs for You