About this role
<div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b>Essential Job Duties and Responsibilities:</b></H2> </div><div></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b></b></H2> </div><div></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b>Description:</b></H2> </div><div></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b>Footer</b></H2> </div><div></div></div></div><p><strong><span style="font-size:10.0pt;line-height:103%;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">J</span><span style="font-size:12.0pt">ob Title- Assistant Manager, Internal Audit and Compliance </span><br><span style="font-size:12.0pt">Work location- Candor Tech Space- sector 48, Tikri, Sohna Road, Gurgaon</span><br><span style="font-size:12.0pt">Work Arrangement - Hybrid.</span></span></strong></p> <p><span style="background-color:olivedrab">Kindly note- </span><span style="background-color:gold"><strong><span style="color:black">We are looking for someone who has skills and experience end to end in implementation, managing internal compliance, and conducting internal audit focusing on ISO 27001. Preferable we are looking for someone who actually manages the ISO 27001 framework as an internal staff within an organisation and not as a consultant (external party) where the role is focus on providing consultation services for their customers and not doing the actual groundwork.</span></strong></span></p> <p> </p> <p style="margin:0.0cm 6.0pt 6.85pt 0.0px;text-align:left;line-height:104%;background-color:#eeece1;font-size:10.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt"><strong>A: Overall Purpose of the Job </strong><em>(Brief description of the primary purpose of this position)</em><strong> </strong></span></p> <p style="margin:0.0cm 60.85pt 2.6pt 0.5pt;text-align:justify;text-indent:-0.5pt;line-height:103%;font-size:10.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Executes internal compliance program as per the overall strategic information security plan of Aspire Lifestyles in accordance with customer requirements, certifications requirements, and cyber security requirements. A key element of this role is to work with internal stakeholders in business lines and support function. </span><br><br></p> <p style="margin:0.0cm 6.0pt 10.0pt 0.0px;text-align:left;line-height:104%;background-color:#eeece1;font-size:10.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt"><strong>B: Key Responsibilities </strong><em>(Critical responsibilities and skills of this position, listed in order of importance)</em><strong> </strong></span></p> <ul> <li style="list-style-type:none;font-size:12.0pt"> <ul style="margin-top:0.0cm;margin-bottom:5.55pt"> <li style="margin:0.0cm 60.85pt 5.55pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt"><img alt="Unsupported image type." width="1" height="15" align="left">Serve as 2nd line of defense (2LOD), performing continuous assessment of IT security practices and policies to improve the security posture of the company </span></li> <li style="margin:0.0cm 60.85pt 5.55pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Conduct regular risk assessments to identify potential vulnerabilities in systems and processes and develop/implement strategies to mitigate identified risks. </span></li> <li style="margin:0.0cm 60.85pt 5.55pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Produce regular reporting on compliance evidence status. </span></li> <li style="margin:0.0cm 60.85pt 5.55pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Identify compliance gaps and plan the implementation of remediation actions and controls </span></li> <li style="margin:0.0cm 60.85pt 5.55pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Verifying all compliance gaps and implementation of remediation actions/controls are effective.</span></li> <li style="margin:0.0cm 60.85pt 5.55pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Work closely with application and infrastructure architects and ensure the applications and infrastructure <s><span style="color:#5c2e91">is</span></s><u><span style="color:#5c2e91">are</span></u> designed and transitioned to operations based on various business and technology needs. </span></li> <li style="margin:0.0cm 60.85pt 5.55pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Work closely with information technology team to ensure that infrastructure is designed and built with required security controls. Advise on infrastructure security best practices such as server hardening, patch management, secure operating environment. </span></li> <li style="margin:0.0cm 60.85pt 5.55pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Educate employees by planning periodic webinars, emailers and group talk on audits and certifications to promote the culture of information security and compliance. </span></li> <li style="margin:0.0cm 60.85pt 5.55pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Plan, present and follow-up on compliance programs in all security forums such as security steering committee, data protection committee, information security management committee.</span></li> <li style="margin:0.0cm 60.85pt 5.55pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Collect and maintain applicable IT Security Regulations for all relevant geographies.</span></li> <li style="margin:0.0cm 60.85pt 5.55pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Provide expert opinions on information security policies to ensure that these are updated based upon the new security trends, customer needs, incident trend and legal or regulatory requirements. </span></li> <li style="margin:0.0cm 60.85pt 5.55pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Demonstrate expertise in managing third party security assessments across the organization.</span></li> <li style="margin:0.0cm 60.85pt 17.95pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Support the Manager of Audits, Certifications and Attestations in executing internal compliance program. </span><br><br><br> <p style="margin:0.0cm 44.9pt 5.5pt 13.4pt;text-align:left;text-indent:-14.15pt;line-height:104%;font-size:10.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt"><strong>C: Required Competencies & Work Experience </strong><em>(Critical behaviors necessary to successfully perform the job)</em><strong> </strong></span></p> <ul style="margin-top:0.0cm;margin-bottom:0.4pt"> <li style="list-style:none;margin:0.0cm 60.85pt 0.4pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"> <ul style="margin-top:0.0cm;margin-bottom:0.4pt"> <li style="margin:0.0cm 60.85pt 0.4pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Degree in business administration or a technology-related field required. </span></li> <li style="margin:0.0cm 60.85pt 0.4pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Professional security certifications such as CISA, CISSP, ISO/IEC 27001 Lead Auditor. </span></li> <li style="margin:0.0cm 60.85pt 0.4pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt"><strong>Experience with either PCI DSS, ISO 27001 or SOC2 certification required.- Mandatory. </strong></span></li> <li style="margin:0.0cm 60.85pt 1.15pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Minimum of 3 to 7 years of experience in a combination of information security compliance and audits.</span></li> <li style="margin:0.0cm 60.85pt 0.4pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Minimum 2 to 3 years of experience in managing end-to-end internal or external audits (e.g.</span></li> </ul> </li> </ul> <p style="margin:0.0cm 60.85pt 0.25pt 36.5pt;text-align:justify;text-indent:-0.5pt;line-height:103%;font-size:10.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">scoping, scheduling, audit preparation guidance discussions, coordination of evidence, report review, follow up actions of audit findings<u><span style="color:#498205">)</span></u></span></p> <ul style="margin-top:0.0cm;margin-bottom:1.1pt"> <li style="list-style:none;margin:0.0cm 60.85pt 1.1pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"> <ul style="margin-top:0.0cm;margin-bottom:1.1pt"> <li style="margin:0.0cm 60.85pt 1.1pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Knowledge of common information security management frameworks, such as ISO/IEC 27001, and NIST.</span></li> <li style="margin:0.0cm 60.85pt 0.85pt 0.0px;text-align:justify;line-height:103%;font-size:12.0pt;font-family:Arial, sans-serif;color:black"><span style="font-size:12.0pt">Excellent written and verbal communication skills and high level of personal integrity</span></li> </ul> </li> </ul> <p><span style="font-size:12.0pt"><strong>Required Languages </strong>(Brief description of the language skills needed to perform the job)<strong> </strong></span></p> <ul> <li style="list-style:none"> <ul> <li><span style="font-size:12.0pt">English (high proficiency in spoken & written)</span><br><br><span style="background-color:olivedrab"><strong><span style="font-size:12.0pt;background-color:olivedrab">Looking for early joiners. </span></strong></span></li> </ul> </li> </ul> </li> </ul> </li> </ul>