For brilliant minds, we offer brilliant career progression in information security. If you want to do exciting and innovative stuff in information security world, come and join us.
For the below opportunities at Codec Networks, you can send in your resume with complete details to careers@codecnetworks.com
Location : At our client side in New Delhi / Pune / Mumbai / Bangalore.
Qualification:
Industrial Experience : Experience of 8-15 yrs
We are looking for a Sales driven, highly energetic Regional Sales Manager with good relationship building skills and communication to join our Sales team in specific locations mentioned above.
We are a passionate team with diverse backgrounds and experiences all driven to solve complex business problems with simple, intuitive solutions. We appreciate people who are fuelled by Passion, curiosity, hunger to learn & grow.
This position is for individuals with exp in information security industry, great relationship building skills, sales abilities and who can help in decision making while working in a super-agile environment.
Operational Roles and Responsibilities :
Industry Exposure Required :
Job Location : New Delhi.
Location : At our client side in Delhi, NCR.
Graduation: : BA/BTECH/BCA/BBA/B.COM/BSC
Post Graduation: MBA (IN ANY) Mandatory
Experience : Experience of 3-4 years
Operational Roles and Responsibilities :
Industry Exposure Required :
Industry relevant experience required in various industry verticals in Banking, Infrastructure, IT, ITES and Telecom. Healthcare, Textiles, Engineering, Automotive, Fertilizers, Power, Steel, Paper, Plastics, Hospitality, FMCG, Media
Other Working Skills :
Location : At our client side in New Delhi / Pune / Mumbai / Bangalore.
Qualifications:
We are looking for an ambitious & ready to leverage the learning environment in a fast-growing global leader in information and cyber security. The candidate should have an understanding of key technologies/solutions in software development and an awareness of top Security applications. The ideal candidate would have good learning agility and would keep themselves informed of the latest in technology.
OKey Responsibilities:
Location : At our client side in Delhi, NCR.
Graduation: : BA/BTECH/BCA/BBA/B.COM/BSC
Experience : Experience of 1-2 years
Operational Roles and Responsibilities :
Industry Exposure Required :
Industry relevant experience required in various industry verticals in Banking, Infrastructure, IT, ITES and Telecom. Healthcare, Textiles, Engineering, Automotive, Fertilizers, Power, Steel, Paper, Plastics, Hospitality, FMCG, Media
Other Working Skills :
Codec Networks Pvt. Ltd. is an established Cyber Security, Information Security Audit, Governance, Risk, Compliance and Managed Security Services organization. Codec Networks is also a CERT-In-empanelled Information Security Auditing Organization.
As part of the expansion of our cybersecurity services business, regulated-industry customer base, strategic alliances and global delivery programs, we are inviting suitable professionals for the following positions:
Location : New Delhi and Gurugram
Areas of Responsibility
Depending upon the position level and specialization, the role may cover:
The selected candidate may be responsible for positioning and supporting the sale of Codec Networks’ cybersecurity services, including:
These services are offered to customers across sectors such as:
Responsibilities will vary according to the applicable level. They may range from prospect research, lead generation, CRM updates, campaign support and proposal coordination at L1 to qualified pipeline development, customer meetings and proposal ownership at L2.
Compensation : Salary, designation and position level will be determined based on the candidate’s:
Compensation will be aligned with applicable industry practices and will remain negotiable for suitable candidates.
The assessment will be proportionate to the level for which your candidature is being considered.
Kindly share the requested information at the earliest so that the Codec Networks Placement Unit can coordinate the interview schedule.
You may also send you a WhatsApp message for your immediate attention and interview coordination. You may contact us at +91 9971676124, +91 8800788220 or +91 8586009171.
We look forward to interacting with you and exploring the possibility of your joining the growing Sales, Marketing and Strategic Business Development team at Codec Networks.
Best regards,
Codec Networks Placement Unit
Codec Networks Pvt. Ltd.
507, 5th Floor, New Delhi House, Barakhamba Road, New Delhi – 110001
707, 7th Floor, Silverton Towers, Nirvana Country, Sector 50, Gurugram – 122018
Email: careers@codecnetworks.com
Contact: +91 9971676124, +91 8800788220, +91 8586009171
Website: www.codecnetworks.com
Codec Networks Pvt. Ltd. is an established Cyber Security, Information Security Audit, Governance, Risk, Compliance and Managed Security Services organization. Codec Networks is also a CERT-In-empanelled Information Security Auditing Organization.
As part of the expansion of our cybersecurity services business, regulated-industry customer base, strategic alliances and global delivery programs, we are inviting suitable professionals for the following positions:
Location : New Delhi and Gurugram
Areas of Responsibility
Depending upon the position level and specialization, the role may cover:
The selected candidate may be responsible for positioning and supporting the sale of Codec Networks’ cybersecurity services, including:
These services are offered to customers across sectors such as:
Responsibilities will vary according to the applicable level. They may range from prospect research, lead generation, CRM updates, campaign support and proposal coordination at L1 to qualified pipeline development, customer meetings and proposal ownership at L2.
Compensation : Salary, designation and position level will be determined based on the candidate’s:
Compensation will be aligned with applicable industry practices and will remain negotiable for suitable candidates.
The assessment will be proportionate to the level for which your candidature is being considered.
Kindly share the requested information at the earliest so that the Codec Networks Placement Unit can coordinate the interview schedule.
You may also send you a WhatsApp message for your immediate attention and interview coordination. You may contact us at +91 9971676124, +91 8800788220 or +91 8586009171.
We look forward to interacting with you and exploring the possibility of your joining the growing Sales, Marketing and Strategic Business Development team at Codec Networks.
Best regards,
Codec Networks Placement Unit
Codec Networks Pvt. Ltd.
507, 5th Floor, New Delhi House, Barakhamba Road, New Delhi – 110001
707, 7th Floor, Silverton Towers, Nirvana Country, Sector 50, Gurugram – 122018
Email: careers@codecnetworks.com
Contact: +91 9971676124, +91 8800788220, +91 8586009171
Website: www.codecnetworks.com
Codec Networks Pvt. Ltd. is an established Cyber Security, Information Security Audit, Governance, Risk, Compliance and Managed Security Services organization. Codec Networks is also a CERT-In-empanelled Information Security Auditing Organization.
As part of the expansion of our cybersecurity services business, regulated-industry customer base, strategic alliances and global delivery programs, we are inviting suitable professionals for the following positions:
Location : New Delhi and Gurugram
Areas of Responsibility
Depending upon the position level and specialization, the role may cover:
The selected candidate may be responsible for positioning and supporting the sale of Codec Networks’ cybersecurity services, including:
These services are offered to customers across sectors such as:
L3 professionals may be responsible for strategic accounts, revenue pipelines, vertical campaigns, large proposals, customer renewals and team coordination.
Compensation : Salary, designation and position level will be determined based on the candidate’s:
Compensation will be aligned with applicable industry practices and will remain negotiable for suitable candidates.
The assessment will be proportionate to the level for which your candidature is being considered.
Kindly share the requested information at the earliest so that the Codec Networks Placement Unit can coordinate the interview schedule.
You may also send you a WhatsApp message for your immediate attention and interview coordination. You may contact us at +91 9971676124, +91 8800788220 or +91 8586009171.
We look forward to interacting with you and exploring the possibility of your joining the growing Sales, Marketing and Strategic Business Development team at Codec Networks.
Best regards,
Codec Networks Placement Unit
Codec Networks Pvt. Ltd.
507, 5th Floor, New Delhi House, Barakhamba Road, New Delhi – 110001
707, 7th Floor, Silverton Towers, Nirvana Country, Sector 50, Gurugram – 122018
Email: careers@codecnetworks.com
Contact: +91 9971676124, +91 8800788220, +91 8586009171
Website: www.codecnetworks.com
Location : Delhi, NCR.
Role And Responsibilities :
Required :
Technical and Professional Expertise
Preferred Technical And Professional Expertise :
Location : At our client side in New Delhi / Pune / Mumbai / Bangalore.
Qualification and Experience needed : 10+ Years of experience in Security OEM / Service Provider Environment in managing Sales function
We are a passionate team with diverse backgrounds and experiences all driven to solve complex business problems with simple, intuitive solutions. We appreciate people who are fuelled by Passion, curiosity, hunger to learn & grow.
This position is for individuals with exp in information security industry, great relationship building skills, sales abilities and who can help in decision making while working in a super-agile environment
Job Description :
Whom You’ll Work With :
Location : At our client side in Delhi, NCR.
Graduation: : BA/BTECH/BCA/BBA/B.COM/BSC
Job Description :
We has an opportunity available for a CCIE Security certified - CCIE Security Presales Consultant to support our growing India Sales and Engineering team located in New Delhi, Pune or Mumbai locations. This Technical Pre-Sales Engineer will support enterprise clients across the India and Asia Pacific region.
Active CCIE certification in Security, and other industry credentials – CISSP, CEH, CISA, CISM, CCSP, etc.
Key Responsibilities :
Industry Exposure Required :
Industry relevant experience required in various industry verticals in Banking, Infrastructure, IT, ITES and Telecom. Healthcare, Textiles, Engineering, Automotive, Fertilizers, Power, Steel, Paper, Plastics, Hospitality, FMCG, Media
Other Working Skills :
We are looking for an outstanding Web Developer to be responsible for the coding, innovative design and layout of our website. Web developer responsibilities include building our website from concept all the way to completion from the bottom up, fashioning everything from the home page to site layout and function.
Essential Skills
Roles and Responsibilities :
Experience and Qualifications:
Educational Background :
Location: In Delhi, NCR.
We are looking for an all-around digital marketing team player who has a wide range of experience across the digital marketing landscape. The Digital Marketing Associate will be responsible for producing, executing, and analyzing digital engagement strategies. We're looking for someone who understands extensively how to use various tools and channels such as web analytics, search engine optimization, email marketing, and social media to contribute to our overall marketing goals: increased brand awareness, brand trust, and sales leads from digital sources.
Roles and Responsibilities:
Experience and Qualifications:
Educational Background :
Location: In Delhi, NCR.
Looking for young and talented Content Writers with excellent English language skills who can create and write articles, blogs, descriptions, and web articles related to IT Services / Cyber security / Networking Security etc and thus helps in expanding its digital footprint to drive more values through online content. The candidate must have good command over written English and possess excellent research skills.
Essential Skills
Roles and Responsibilities :
Educational Background :
Location: In Delhi, NCR.
Roles and Responsibilities :
Experience and Qualifications:
Educational Background :
Location: In Delhi, NCR.
Location : Delhi, NCR.
Experience :
1 to 2 years developing and implementing data analytics methodologies with good interpersonal with excellent communication skills
Technical Skills Required :
Hands on Knowledge on Tools :
Location : At our client side in Delhi, NCR.
Educational Background : Graduate (B.E, B.Sc)
Certifications : CEH Certification, OSCP, SANS GWAPT, SANS GPEN
Experience : Experience of 1-2 years
Operational Roles and Responsibilities :
Technical Skills Required :
Other Working Skills :
Location : Delhi, NCR
Educational Background : Graduate or Postgraduate (B.E, B. Tech, ME M.Tech) in Information Security
Experience : 2-5 years or more
Operational Roles and Responsibilities :
Other Working Skills :
Location : Delhi, NCR
Educational Background: B.E, B. Tech, B.SC in Information Security, CSC, ECE, IT
Certifications :
Experience : 2 year or more
Operational Roles and Responsibilities :
The individual as a part of Information Security operaton team shall be responsible to provide critical management and reporting services on a variety of Information Security platforms. This includes: configuration, tool creation (scripts, procedures, and templates), defining reports, and recommending best practices and procedures.
Hands on knowledge on Tools: Nmap, Kali Linux, Metasploit, Armitage , Maltego, Burp, Paros Proxy Nessus, nexpose, wireshark, sqlmap etc
Location : Delhi, NCR
Educational Background: B.E, B. Tech, B.SC in Information Security, CSC, ECE, IT
Experience: 2 year or more
Operational Roles and Responsibilities :
Performing Network Security Assessment, Network Security Architecture Review (NSAR), Network Device Configuration Audit, Security Policy drafting and review, Network Vulnerability Assessment / Penetration Testing and System Hardening.
Web application security analysis, Vulnerability assessment and penetration testing
Technical Skills Required :
Location : Delhi, NCR
Educational Background: MCA, BCA , B.Tech ( CSC or ECE)
Certifications : CEH/CSSLP/CISSP
Experience : 3-6 years
Operational Roles and Responsibilities :
Sound Knowledge in conducting Network/ Infrastructure Vulnerability Assessment and Penetration Testing, Application security testing, Wireless security testing, Code review with at least 2 year experience in information security.
Technical Skills Required :
Location : at Codec Networks Client side at New Delhi.
Educational Background : raduate (B.E, B. Tech, MSc, B.Sc) in CSC, ECE, IT
Certifications :
Experience : Experience 2 years or more
Operational Roles and Responsibilities :
Technical Skills Required :
Hands on knowledge on Tools : Nmap, Kali Linux, Metasploit, Armitage , Maltego, Burp, Paros Proxy Nessus, nexpose, wireshark, sqlmap etc.
Location : Delhi, NCR.
Educational Background : MCA, BCA , B.Tech ( CSC or ECE)
Certifications :
Experience : Experience of 2-3 years
Operational Roles and Responsibilities :
Other Working Skills :
Analytical skills, ability to work with minimal supervision, good speaking and writing skills, excellent working knowledge of word, excel and powerpoint
Location : New Delhi
Certifications :
Experience : 3-8 years
Operational Roles and Responsibilities :
Other Working Skills :
Location : Delhi, NCR.
Educational Background: MCA, BCA , B.Tech ( CSC or ECE)
Certifications : Industry recognized Application Security Certifications, such as CISSP, CISA, CEH ISO 27001 are a plus.
Experience :1-3 Years of experience in web application /Mobile Application Development.
Technical Skills Required :
Location :Delhi, NCR.
Job Role : Security Consultant/Penetration Tester required with expert skills in Web Application and Mobile Application security assessments
Full Job Description :
Senior Penetration Tester/Ethical Hacker to work as a Web Application/Mobile Application Security Consultant in a challenging environment.
Experiance : 2-3 years experience in web application and mobile security
Operational Roles and Responsibilities :
Technical Skills Required :
Other Working Skills :
Location :Delhi, NCR.
Educational Background: MCA, BCA , B.Tech ( CSC or ECE)
Certifications : CEH/CSSLP/CISSP
Experience : 3-6 Years
Operational Roles and Responsibilities :
Technical Skills Required :
Location : Delhi, NCR
Educational Background : B.E, B. Tech, B.SC in Information Security, CSC, ECE, IT
Experience : 2 years or more
Operational Roles and Responsibilities :
The individual as a part of Information Security operaton team shall be responsible to provide critical management and reporting services on a variety of Information Security platforms. This includes: configuration, tool creation (scripts, procedures, and templates), defining reports, and recommending best practices and procedures.
Technical Skills Required :
A technically savvy individual who can work independently in shifts (24*5) operations and in a small team environment.
Passionate about IT systems and information security
A strong knowledge and background in
Intrusion detection systems, Security incident / event management systems, Firewall rule base management tools, Firewall rule base audit tools, Anti-virus or anti - malware technologies, Log analysis software, Internet proxy servers, Compliance archival solutions, Various operating systems (e.g. Windows and Linux), Basic scripting capabilities are an advantage, Possess a high level overview of risk-intelligence and security awareness, End point security, Encryption technology, Database Security.
Other Working Skills :
Location : Delhi, NCR.
Educational Background :
Bachelor's degree (or equivalent) preferred in Computer Science, Information Systems or related fields
Certifications :
Possession of industry certifications highly preferred including, but not limited to, Certified Information Systems Security Professional (CISSP) and SANS GIAC.
Experience :
5 years' experience working in IT/InfoSec engineering and operations
Technical Skills Required :
Soft Skills Expertise :
Role purpose: To support GRC engagements through structured evidence collection, control checklist preparation, documentation, audit working papers, data inventory support and first-level control testing under supervision.
| Parameter | Recommended Definition |
|---|---|
| Recommended designation | GRC Analyst, Associate Consultant - Regulatory Audit, ISO/SOC 2 and Privacy Support |
| Indicative experience | 1-3 years in IT audit, information security, compliance, privacy support, ISO implementation support, evidence collection or cybersecurity documentation. |
| Reports to | L2 Senior GRC Consultant / L3 GRC Lead / Project Manager depending on engagement size. |
| Primary service coverage | Regulatory audit support, ISO/NIST/SOC 2 evidence support, DPDPA/GDPR data inventory support, ITGC testing support and documentation. |
| Typical customer interaction | Limited but active evidence follow-up with customer control owners under senior supervision. |
| Revenue / proposal role | Supports proposal annexures, compliance matrices, credential packs, document request lists and reusable templates. |
1. Detailed Job Description
2. Technical Skill Sets Required
| Skill Area | Required Skill Set |
|---|---|
| Framework basics | Basic understanding of ISO 27001, NIST CSF, SOC 2, ISO 27701, ISO 22301, PCI DSS, ITGC, DPDPA, GDPR and sectoral cybersecurity requirements. |
| Evidence management | Ability to request, classify, index, validate basic completeness and organize audit evidence. |
| Audit documentation | Working paper preparation, gap tracker updates, MOM drafting and management action plan tracking. |
| IT control basics | Access control, backup, change management, incident management, asset management, patch management, logging, vendor management and business continuity basics. |
| Privacy support | Basic data inventory, personal data classification, privacy notice checklist, consent process review and breach checklist support. |
| Tools | MS Excel, Word, PowerPoint, SharePoint/Drive, ticketing tools, GRC portals, basic dashboarding and evidence repositories. |
| Communication | Professional evidence follow-up, meeting notes, concise writing and escalation of pending items. |
3. Supporting Certifications
| Certification Category | Recommended Certifications |
|---|---|
| Minimum preferred | ISO 27001 Foundation/Internal Auditor, cybersecurity fundamentals, privacy foundation or equivalent training. |
| Recommended within 12 months | ISO 27001 Lead Auditor/Implementer foundation pathway, ITIL foundation, DPDPA/privacy foundation, SOC 2 awareness, NIST CSF awareness. |
| Good to have | Security+, Microsoft security fundamentals, cloud security fundamentals, basic data protection/privacy training. |
| Internal Codec requirement | Codec GRC evidence handling training, audit working paper training, confidentiality/data protection training and report-writing basics. |
4. Technical Experience Required, Including Practical Industrial Project
| Experience Area | Practical Project Exposure Expected |
|---|---|
| ISO/GRC projects | Participation in at least 2-4 ISO 27001/GRC/control review projects as evidence coordinator or junior auditor. |
| Regulatory audit support | Exposure to document collection and checklist preparation for BFSI, insurance, fintech, healthcare, government or IT/ITES audits. |
| Privacy support | Experience supporting data inventory, consent tracker, privacy notice review or personal data processing register preparation. |
| ITGC support | Basic testing support for user access review, backup evidence, change logs, incident tickets, patch records and asset inventory. |
| Documentation | Practical experience in preparing evidence index, DLR, MOM, issue tracker, gap tracker and audit working papers. |
5. Target Deliverables at This Position
| Deliverable | Ownership Level / Quality Expectation |
|---|---|
| Document request list support | Prepare and update DLR under L2/L3 supervision. |
| Evidence index | Maintain control-wise evidence index with document names, owners, dates and review status. |
| Working papers | Prepare first draft audit working papers with evidence references. |
| Gap tracker support | Update observations and pending items as directed by senior consultant. |
| Meeting notes | Prepare accurate MOMs and pending action trackers. |
| Privacy data inventory support | Collect process-level data inventory details and classify data fields under supervision. |
| Compliance matrix support | Populate basic checklist status and cross-reference evidence. |
6. Personality and Leadership Attributes Required
| Attribute | Expected Behaviour |
|---|---|
| Accuracy | Maintains evidence and working papers carefully without careless errors. |
| Discipline | Follows checklists, naming conventions, confidentiality rules and timelines. |
| Learning mindset | Actively learns frameworks, regulations, audit methodology and customer processes. |
| Professional communication | Communicates politely with customer control owners and escalates delays early. |
| Confidentiality | Treats customer documents, personal data and audit evidence with strict sensitivity. |
| Ownership | Takes ownership of assigned trackers and daily updates. |
7. KPIs and Performance Indicators
| KPI | Expected Target / Measurement |
|---|---|
| Evidence tracker accuracy | 95%+ accuracy in evidence status, ownership and file references. |
| Timely follow-up | All pending evidence follow-ups updated within agreed timeline. |
| Working paper quality | Minimal rework after L2 review. |
| Training completion | 100% completion of assigned Codec GRC and privacy training. |
| Confidentiality compliance | Zero data handling or unauthorized sharing incident. |
| Documentation timeliness | MOMs and trackers submitted within 24 hours of meetings. |
8. Interview / Evaluation Indicators
| Evaluation Area | Assessment Method |
|---|---|
| Framework awareness | Ask candidate to explain basic ISO 27001 control areas and evidence examples. |
| Evidence judgement | Give sample evidence and ask whether it supports a control. |
| Excel/document skills | Test ability to build evidence tracker and gap tracker. |
| Privacy basics | Ask candidate to identify personal data and consent evidence in a sample process. |
| Communication | Role-play evidence follow-up with a customer control owner. |
Role purpose: To independently execute GRC, regulatory, ISO/SOC 2 and privacy assessment tasks, evaluate evidence, identify gaps, draft observations, prepare risk-rated reports and coordinate customer remediation planning.
| Parameter | Recommended Definition |
|---|---|
| Recommended designation | Senior Consultant - GRC, Regulatory Cybersecurity Audit, ISO/SOC 2 and Privacy Compliance |
| Indicative experience | 3-6 years in IT audit, cyber GRC, ISO implementation/audit, SOC 2 readiness, regulatory audit, privacy assessment, ITGC or risk management. |
| Reports to | L3 GRC Lead / L4 Principal GRC Architect / Practice Head. |
| Primary service coverage | Independent control testing, gap assessment, risk register drafting, policy review, privacy/DPIA support, regulatory mapping and management action plans. |
| Typical customer interaction | Direct interaction with IT, security, compliance, HR, legal, procurement, business and privacy control owners. |
| Revenue / proposal role | Supports pre-sales scoping, effort estimation, technical solution notes, proposal sections and compliance responses. |
1. Detailed Job Description
2. Technical Skill Sets Required
| Skill Area | Required Skill Set |
|---|---|
| Multi-framework control mapping | Ability to map ISO 27001, NIST CSF, SOC 2, ISO 27701, DPDPA/GDPR, PCI DSS and sectoral regulatory requirements into a unified control checklist. |
| Audit execution | Planning evidence requests, testing controls, conducting interviews, documenting results and preparing working papers. |
| Risk assessment | Risk identification, likelihood/impact scoring, inherent/residual risk, treatment plans and management action tracking. |
| Policy and procedure review | Ability to assess adequacy of governance documents and recommend improvements. |
| Privacy and data protection | Data inventory, data flow review, DPIA support, privacy notices, consent, breach readiness and processor/vendor privacy review. |
| ITGC and cyber controls | Access management, change management, backup, patching, logging, incident management, vulnerability management, supplier controls and BCP/DR. |
| Report writing | Ability to draft clear, risk-based, customer-ready observations and executive summaries. |
| Tools | Excel-based control matrices, GRC tools, audit management tools, evidence portals, project trackers and dashboard inputs. |
3. Supporting Certifications
| Certification Category | Recommended Certifications |
|---|---|
| Minimum preferred | ISO 27001 Lead Auditor/Lead Implementer, CISA foundation/progress, or equivalent GRC/audit certification. |
| Strongly recommended | CISA, CISM, CRISC, ISO 27701 Lead Implementer/Auditor, ISO 22301, SOC 2 practitioner/readiness training. |
| Privacy recommended | CIPM, CIPP/E, CDPSE, DPO certification or DPDPA/GDPR practitioner training. |
| Domain-specific good to have | PCI DSS awareness, HIPAA security awareness, NIST CSF training, ITIL, cloud security fundamentals. |
4. Technical Experience Required, Including Practical Industrial Project
| Experience Area | Practical Project Exposure Expected |
|---|---|
| ISO implementation/audit | Independent role in at least 3-6 ISO 27001/27701/22301 or cyber maturity projects. |
| Regulatory audit | Participation in at least 2 regulated-sector audits for BFSI, insurance, fintech, government, healthcare or telecom. |
| SOC 2/readiness | Experience preparing or reviewing trust service criteria control mapping and evidence packs. |
| Privacy projects | At least 1-3 privacy readiness, data inventory, DPIA, GDPR/DPDPA, privacy notice or vendor privacy assessment projects. |
| ITGC/control testing | Practical testing of user access, change, backup, incident, vendor, patch, asset, logging and BCP controls. |
| Policy development | Experience drafting or reviewing at least 10-15 cyber/GRC/privacy policies, SOPs or templates. |
5. Target Deliverables at This Position
| Deliverable | Ownership Level / Quality Expectation |
|---|---|
| Gap assessment report | Draft control-wise gap report with evidence references and risk rating. |
| Risk register | Prepare risk register with cause, consequence, likelihood, impact, treatment and owner. |
| Policy review notes | Prepare redline/commentary or improvement tracker for policies and SOPs. |
| Compliance matrix | Populate and validate framework-wise compliance status. |
| Management action plan | Prepare CAPA/MAP with target dates, owners and residual risk view. |
| Privacy assessment outputs | Prepare data inventory, DPIA draft, privacy notice review notes and breach readiness checklist. |
| Pre-sales inputs | Prepare scope assumptions, effort estimate inputs and deliverable matrix. |
| L1 review | Review L1 evidence indexing and working papers before L3 review. |
6. Personality and Leadership Attributes Required
| Attribute | Expected Behaviour |
|---|---|
| Analytical thinking | Connects evidence gaps to business and regulatory risk. |
| Professional challenge | Can challenge customer claims respectfully and evidence-based. |
| Detail orientation | Writes precise observations without overstatement. |
| Customer confidence | Can independently speak with control owners and explain requirements. |
| Mentoring | Guides junior analysts and improves their documentation quality. |
| Ethical judgement | Maintains independence and avoids unsupported conclusions. |
7. KPIs and Performance Indicators
| KPI | Expected Target / Measurement |
|---|---|
| Observation quality | 80-90% observations accepted by L3/QA without major rewrite. |
| Timely deliverables | Assigned deliverables submitted as per project plan. |
| Evidence review productivity | Controls/evidence reviewed per day within quality target. |
| Client feedback | Positive feedback from customer control owners and project manager. |
| L1 supervision | L1 rework and documentation errors reduced over time. |
| Pre-sales support | Accurate scope and effort assumptions with limited delivery mismatch. |
8. Interview / Evaluation Indicators
| Evaluation Area | Assessment Method |
|---|---|
| Control testing case | Provide sample access review evidence and ask candidate to identify gaps. |
| Risk writing test | Ask candidate to draft one audit observation with risk and recommendation. |
| Framework mapping | Ask candidate to map a control across ISO 27001, SOC 2 and NIST. |
| Privacy scenario | Ask candidate to identify DPIA triggers and privacy control gaps. |
| Client simulation | Role-play explaining why evidence is inadequate to a senior customer stakeholder. |
Role purpose: To lead GRC vertical engagements end-to-end, validate control conclusions, manage customer stakeholders, guide teams, own report quality and convert technical compliance observations into management-ready risk and improvement roadmaps.
| Parameter | Recommended Definition |
|---|---|
| Recommended designation | Lead Consultant / Engagement Lead - Regulatory Audit, GRC, ISO/SOC 2, Cyber Maturity and Privacy |
| Indicative experience | 6-9 years in cyber GRC, information security audit, regulatory cybersecurity, ISO/SOC 2 readiness, privacy, IT risk, internal audit or consulting leadership. |
| Reports to | L4 Principal GRC Architect / Practice Head / COO depending on strategic engagement. |
| Primary service coverage | End-to-end engagement leadership, multi-framework audit design, customer workshops, report quality, L1/L2 supervision, risk validation and CXO-ready reporting. |
| Typical customer interaction | Leads customer workshops, audit interviews, steering meetings, closure meetings and management action plan discussions. |
| Revenue / proposal role | Leads solutioning for proposals, effort estimates, RFP technical responses, commercial assumptions and customer pitch support. |
1. Detailed Job Description
2. Technical Skill Sets Required
| Skill Area | Required Skill Set |
|---|---|
| Engagement leadership | Planning, staffing, kickoff, governance, delivery tracking, risk escalation and customer closure. |
| Advanced control interpretation | Ability to interpret regulatory, ISO, SOC 2, NIST and privacy requirements in different industry contexts. |
| Audit methodology | Risk-based audit design, sampling, evidence sufficiency, control effectiveness testing and audit trail defensibility. |
| Maturity assessment | Designing maturity models, scoring logic, heatmaps and multi-year remediation roadmaps. |
| Privacy leadership | DPIA review, data processing maps, DPO advisory support, breach readiness, vendor privacy and cross-border control review. |
| Board reporting | Converting control gaps into business risk, management priorities, investment roadmap and board summaries. |
| Pre-sales and pricing | Scope definition, effort estimation, proposal defence, assumptions, exclusions and delivery model design. |
| Team mentoring | Coaching L1/L2 consultants in evidence review, report writing, risk rating and customer communication. |
3. Supporting Certifications
| Certification Category | Recommended Certifications |
|---|---|
| Minimum preferred | CISA or ISO 27001 Lead Auditor/Lead Implementer plus strong regulatory/GRC project experience. |
| Strongly recommended | CISM, CRISC, CISSP, ISO 27701, ISO 22301, SOC 2 practitioner, NIST CSF, PCI DSS practitioner awareness. |
| Privacy leadership | CIPM, CIPP/E, CDPSE, DPO certification, GDPR/DPDPA practitioner certification. |
| Additional valuable | PMP/PRINCE2/Agile project management, cloud security certifications, ITIL, fraud risk/ITGC training. |
4. Technical Experience Required, Including Practical Industrial Project
| Experience Area | Practical Project Exposure Expected |
|---|---|
| Lead GRC engagements | Led at least 8-12 GRC/ISO/SOC 2/regulatory/privacy engagements across multiple industries. |
| Regulated-sector experience | Hands-on leadership in BFSI, insurance, fintech, stock broking, payment, healthcare, government or telecom audits. |
| Certification readiness | Led ISO 27001/27701/22301 or SOC 2 readiness projects with policy, risk, control and evidence deliverables. |
| Privacy programs | Led or significantly contributed to privacy readiness, DPIA, DPO support, data inventory or breach readiness programs. |
| Multi-framework mapping | Experience mapping controls across ISO/NIST/SOC 2/regulatory/privacy frameworks. |
| Executive reporting | Presented risk findings and remediation roadmaps to CISO, CIO, compliance head, risk committee or board-level stakeholders. |
| Cross-practice coordination | Coordinated with VAPT, SOC, cloud, DFIR, TPRM and application security teams for integrated assurance. |
5. Target Deliverables at This Position
| Deliverable | Ownership Level / Quality Expectation |
|---|---|
| Audit plan | Owns final audit plan, scope, sampling approach and interview schedule. |
| Final gap/audit report | Owns report structure, observation quality, risk rating and management-ready recommendations. |
| Board summary | Prepares executive summary, heatmap and strategic remediation roadmap. |
| Regulator-ready response matrix | Validates evidence and response alignment for regulated entities. |
| Certification readiness report | Assesses readiness and final closure items before external audit/certification. |
| Privacy governance outputs | Approves DPIA summary, data processing inventory, privacy gap report and breach plan. |
| Team review package | Approves L1/L2 working papers and ensures quality before QA. |
| Proposal solution note | Prepares methodology, staffing, assumptions and effort for complex opportunities. |
6. Personality and Leadership Attributes Required
| Attribute | Expected Behaviour |
|---|---|
| Leadership | Leads teams calmly under deadlines and customer pressure. |
| Executive presence | Can communicate risk to CISO, CIO, compliance head and management. |
| Balanced judgement | Avoids both under-reporting and exaggerating risks. |
| Coaching mindset | Builds capability of L1/L2 team members. |
| Commercial awareness | Understands effort, margins, scope creep and change requests. |
| Integrity | Protects independence, confidentiality and factual accuracy of audit conclusions. |
7. KPIs and Performance Indicators
| KPI | Expected Target / Measurement |
|---|---|
| On-time delivery | 95%+ milestone adherence for assigned engagements. |
| Report QA acceptance | 90%+ reports cleared with limited rework. |
| Customer satisfaction | Average customer feedback above agreed benchmark. |
| Gross margin protection | Projects delivered within approved effort and margin assumptions. |
| Team productivity | L1/L2 utilization and quality managed effectively. |
| Pre-sales accuracy | Low variance between proposed effort and actual effort. |
| Retainer conversion support | Supports conversion of project customers to ongoing compliance retainers. |
8. Interview / Evaluation Indicators
| Evaluation Area | Assessment Method |
|---|---|
| Engagement planning | Ask candidate to design an audit plan for a fintech ISO/SOC 2/DPDPA readiness project. |
| Risk validation | Give five draft findings and ask candidate to adjust risk ratings and wording. |
| Executive communication | Ask candidate to present top 5 risks to a simulated CISO/board panel. |
| Regulatory challenge | Ask how evidence sufficiency is established in a regulated audit. |
| Team leadership | Ask how candidate manages L1/L2 quality issues and customer delays. |
Location : Delhi, NCR.
Educational Background :
Bachelor's degree (or equivalent) preferred in Computer Science, Information Systems or related fields
Certifications :
Possession of industry certifications highly preferred including, but not limited to, Certified Information Systems Security Professional (CISSP) and SANS GIAC.
Experience :
1 years' experience working in IT/InfoSec engineering and operations
Primary Duties: :
Excellent understanding of basic concepts such as networking, applications, and operating system functionality and be able to learn advanced concepts such as application manipulation, exploit development, and stealthy operations. Job involves reverse engineering an application and encryption method in order to gain access to sensitive data, all without being detected.
Identify and exploit misconfigurations in network infrastructure, parse various types of output data, present relevant data in a digestible manner. Expected to quickly assimilate new information of Client environments on a weekly or monthly basis on threat vectors to each environment and properly assess them.
Technical Skills Required :
Key Responsibilities :
Other Skills :
Location : Delhi, NCR.
Educational Background :
Bachelor's degree (or equivalent) preferred in Computer Science, Information Systems or related fields
Certifications :
Possession of industry certifications highly preferred including, but not limited to, Certified Information Systems Security Professional (CISSP) and SANS GIAC.
Experience :
1 years' experience working in IT/InfoSec engineering and operations
Primary Duties: :
Excellent understanding of basic concepts such as networking, applications, and operating system functionality and be able to learn advanced concepts such as application manipulation, exploit development, and stealthy operations. Job involves reverse engineering an application and encryption method in order to gain access to sensitive data, all without being detected.
Identify and exploit misconfigurations in network infrastructure, parse various types of output data, present relevant data in a digestible manner. Expected to quickly assimilate new information of Client environments on a weekly or monthly basis on threat vectors to each environment and properly assess them.
Technical Skills Required :
Key Responsibilities :
Other Skills :
Location : Noida
Experience :
1 to 2 years developing and implementing data analytics methodologies with good interpersonal with excellent communication skills
Technical Skills Required :
Key Responsibilities :
Other Skills :
Location : Delhi, NCR.
Educational Background :
Bachelor's degree (or equivalent) preferred in Computer Science, Information Systems or related fields
Certifications :
Possession of industry certifications highly preferred including, but not limited to, Certified Information Systems Security Professional (CISSP) and SANS GIAC.
Experience :
1 years' experience working in IT/InfoSec engineering and operations
Key Responsibilities :
Technical Skills Required :
Other Skills :
Location : Delhi, NCR.
Educational Background :
Bachelor's degree (or equivalent) preferred in Computer Science, Information Systems or related fields
Certifications :
Possession of industry certifications highly preferred including, but not limited to, Certified Information Systems Security Professional (CISSP) and SANS GIAC.
Experience :
1 years' experience working in IT/InfoSec engineering and operations
Primary Duties: :
First line of response for monitoring alerts and resolving incidents that are events triggered and escalate accordingly. (MONITORING).Review false positives and ensure the right alerts are being reviewed (MONITORING) Investigating and find the root cause of the these issues.
Technical Skills Required :
Key Responsibilities :
Other Skills :
Location : Delhi, NCR.
Educational Background :
Bachelor's degree (or equivalent) preferred in Computer Science, Information Systems or related fields
Certifications :
Possession of industry certifications highly preferred including, but not limited to, Certified Information Systems Security Professional (CISSP) and SANS GIAC.
Experience :
1 years' experience working in IT/InfoSec engineering and operations
Primary Duties: :
The Cybersecurity SIEM Administrator will be responsible for administering the deployed SIEM service. This role is also responsible for identifying, analyzing, developing new or tuning & Refinement of the content or use cases.
Technical Skills Required :
Key Responsibilities :
Other Skills :