Manager, Security, Risk & Compliance
Manager, Security, Risk & Compliance
International SosEarly Applicant
- Posted 17 hours ago
- Be among the first 10 applicants
Job Description
Description
Essential Job Duties and Responsibilities:
Footer
Location- Candor Techspace sector 48, Gurgaon.
Hybrid working arrangement.
Notice period- Need early joiners.
Essential Job Duties and Responsibilities:
Footer
Location- Candor Techspace sector 48, Gurgaon.
Hybrid working arrangement.
Notice period- Need early joiners.
- Overall Purpose of the Job (Brief description of the primary purpose of this position)
- Key Responsibilities (Critical responsibilities and skills of this position, listed in order of importance)
- Respond to Security Questionnaires & Assessments:
- Review, analyze, and complete customer/vendor information security questionnaires (e.g., SIG, CAIQ, custom formats).
- Ensure responses are accurate, consistent, and aligned with internal policies and external compliance requirements.
- Coordinate Cross-Functional Responses:
- Liaise with internal stakeholders (IT, Legal, Operations, etc.) to gather required information and documentation.
- Maintain a knowledge base of frequently asked questions and supporting documentation for efficient responses.
- Maintain Evidence and Documentation:
- Organize and update artifacts such as security policies, procedures, audit reports, penetration test results, certifications (ISO 27001, SOC 2, PCI DSS), and risk assessments.
- Support annual review and refresh of response libraries and evidence packages.
- Support Audits and Assessments:
- Assist with client audits, security due diligence, and compliance assessments.
- Coordinates, tracks, and reports on all remediation efforts when non-compliant issues arise.
- Facilitate meetings and walkthroughs with external parties as needed.
- Monitor Contract Compliance:
- Document information security, data compliance, and in scope laws and regulations
- Perform periodic assessment to ensure contractual obligations on information security are met
- Process Management and Improvement:
- Contribute to continuous improvement of the security questionnaire response process.
- Provide management reporting with statistics as well as insights into trends
- Identify common themes, suggest improvements in control documentation, and streamline recurring assessments.
- Job Profile
- Bachelor's Degree in Information Security, Computer Science, or a related field.
- 2–5 years of experience in information security, GRC (Governance, Risk & Compliance), or third-party risk management.
- Strong understanding of security frameworks and standards (e.g., ISO 27001, NIST, SOC 2, PCI DSS, CIS Controls).
- Experience completing detailed security questionnaires and assessments.
- Excellent written communication skills and attention to detail.
- Ability to handle multiple requests and prioritize effectively.
- Industry certifications such as CISA, CISSP, CRISC, ISO 27001 Lead Implementer, or similar.
- Experience working in or with regulated financial institutions.
- Strong organizational and time management skills.
- Ability to communicate technical content to both technical and non-technical audiences.
- Proactive problem-solver with a customer-service mindset.
- Collaborative team player who thrives in a cross-functional environment.
- English
- 15% Schedule may vary according to business needs
More Info
Key Skills
Security questionnaires
CIS Controls
SOC 2
Third-party risk management
Penetration test results




