Support the implementation, maintenance, and continuous improvement of information security compliance programs, specifically focusing on ISO 27001, SOC 1 and SOC 2.
Develop, review, and update security policies, procedures, and guidelines to align with relevant compliance frameworks and regulatory requirements.
Conduct risk assessments and gap analyses against ISO 27001 and NIST CSF controls to identify areas for improvement and ensure audit readiness.
Prepare and compile documentation, evidence, and responses for customer RFIs and audit requests efficiently and accurately.
Contribute in identification, assessment, and mitigation of information security risks in accordance with established risk management frameworks.
Maintain comprehensive documentation of security controls, compliance activities, and remediation plans.
Prepare regular reports on compliance status, key metrics, and areas of concern for management and stakeholders.
Perform comprehensive third-party risk assessments to evaluate vendor compliance with information security policies.
Ensure effective communication and documentation of third-party risk assessments.
Frequently Asked Questions
How to apply for Security Consultant - GRC at NopalCyber?
Click the "Apply on Company Website" button on this page to submit your application directly on the employer's official portal.
What is the salary for this role?
Salary details will be discussed during the interview.
What experience is required?
This position is open to freshers and experienced candidates.