Information Protection Assessments - Assistant Manager
On-sitePune, Maharashtra, India
Job Summary
Conduct risk-based information protection controls assessments and execute internal and third-party supplier audits. Lead Quality Assurance reviews of audit findings, applying independent judgment to evaluate control effectiveness and separate procedural issues from systemic risks. Map contractual security obligations to control testing evidence and interpret independent certification reports such as ISO 27001 and SOC 2. Deliver clear, high-quality reports and presentations to senior stakeholders using M365 tools while managing stakeholder relationships within a global, multicultural team. Requires minimum 6 years of information security experience, including 4 years in ISO 27001 auditing, with ISO 27001:2022 lead auditor certification.
Required Qualifications
- Minimum 6 years of information security and risk experience
- Minimum 4 years of experience in information protection controls assessments
- ISO 27001 information security controls auditing and/or implementing experience
- Strong information security and privacy standards knowledge
- Excellent information protection risk assessment planning, executing, managing and reporting skills for internal audits as well as third party supplier audits
- Proven ability to operate as a risk-based Quality Assessment (QA) reviewer of audits performed
- Demonstrated sound professional judgment to evaluate control effectiveness in context, separating isolated procedural issues from matters that present meaningful risk or systemic
- Ability to assess contractual security obligations and map them to control testing and evidence
- Experience reviewing and interpreting independent certification and attestation reports (e.g. ISO 27001, SOC 2)
- Understanding of risk‐based scoping approaches, including consideration of supplier risk indicators and service context
- ISO 27001:2022 lead auditor or lead implementer certification
- Excellent written and verbal communication skills in English
- Strong report writing ability
- Ability to present clearly and confidently to senior stakeholders
- Proficient in M365 tools (Word, PowerPoint, Excel, Teams, Copilot)
- Strong capability to produce clear, high‐quality reports and presentations
- Strong ability to multitask and work independently within a global team
- Proactive work style
- Ability to work with minimal supervision
- Work on continuous improvements
- Accountable approach
- Collaborative approach
- Excellent stakeholder management skills
- Adaptive mindset
- Quick learner
- Attention to detail
- Experience working in multicultural environments
- Sensitivity to different business cultures
Desired Qualifications
- ISO 42001 / AI lead auditor or lead implementer certification
- Prior supplier security assessment experience
- Prior KPMG (or Big4) work experience
- Familiarity with KPMG policies (e.g. Global InfoSec & Privacy Policies, GISP, GAUP) or governance frameworks (e.g. IFDTA)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.