Information Protection Assessments - Manager
On-sitePune, Maharashtra, India
Job Summary
Conduct senior risk-based Quality Assurance reviews of information controls audits, differentiating technical noncompliance from actual risk exposure and identifying misalignments between local interpretations and global System of Quality Management expectations. Assess independent assurance reports for ISO 27001 and SOC 2, detecting nuanced quality concerns such as unsupported assumptions and weak analytic logic while translating third-party contractual requirements into risk-based outcomes. Engage with senior stakeholders and external third parties to communicate complex risk and assurance results, operating autonomously within a global delivery model using M365 tools. This role requires a minimum of eight years in information protection and risk management, including six years in controls assessments, with a preference for prior Big 4 experience and ISO certifications.
Required Qualifications
- Minimum of 8 years of extensive experience in information protection and risk management and /or assurance
- Minimum of 6 years of experience in information protection controls assessments
- Demonstrated depth in ISO/IEC 27001 auditing and /or implementation
- Experience with complex or judgment intensive reviews based on leading industry practices for internal audits and external / supplier audits
- Advanced and well-rounded expertise in information security and privacy
- Ability to interpret requirements and risks in complex, global, and non-standard scenarios
- Proven ability to function as a senior risk-based Quality Assessment (QA) reviewer of information controls audits
- Consistently exercising professional skepticism and independent judgment beyond procedural compliance
- Ability to differentiate between technical noncompliance, actual risk exposure, significant control weaknesses, and documentation or evidentiary quality gaps
- Ability to identify and assess misalignment between local control interpretations and global SOQM expectations
- Ability to detect nuanced quality concerns such as unsupported assumptions, circular reasoning, weak analytic logic, or evidence that does not substantiate conclusions
- Strong understanding of information security and data protection contractual requirements of third party suppliers and their translation into risk‐based assessment outcomes
- Experience reviewing independent assurance reports for information security and privacy areas (e.g. ISO 27001, SOC 2), including scope considerations, exceptions and residual risks
- Experience engaging with senior stakeholders and external third parties to communicate complex risk and assurance outcomes
- Highly developed written and verbal communication skills in English
- Demonstrated strength in executive level reporting
- Excellent command of M365 tools, including Word, PowerPoint, Excel, Teams, and Copilot
- Ability to operate autonomously within a global delivery model
- Effectively collaborating with diverse teams across geographies and time zones
- Strong personal accountability
- Collaborative leadership approach
- Well-developed stakeholder management skills
- Comfort engaging at senior levels
- Highly adaptive
- Capable of quickly assimilating new subject matter
- Strong attention to detail
- Ability to maintain integrity and quality across multiple workstreams
Desired Qualifications
- Prior supplier audit and/or third-party risk assessment experience
- Professional certifications such as ISO 27001:2022 Lead Auditor and/or ISO 42001 / AI Lead Auditor
- Prior experience with KPMG or another Big 4 organization
- Strong and practical familiarity with KPMG Global Information Security and Privacy Policies and frameworks, including Global Information Security Policies (GISP), Global Acceptable Use Policies (GAUP), and their application within a global System of Quality Management (SoQM)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.