Management Level
HBasic Function
Support the organization’s information security compliance program by leading audits, regulatory compliance initiatives, control assessments, risk management activities, and evidence collection. Act as a trusted advisor to the business, promoting risk-based decision-making, compliance awareness, control maturity, and process improvement.
Key Responsibilities
Compliance & Audit Management
- Lead and maintain information security compliance programs aligned with corporate policies and regulatory requirements.
- Support and manage audits and compliance frameworks such as ISO 27001, SOC 2, GDPR, DORA, FISMA, and related standards.
- Serve as a subject matter expert on security and compliance matters.
- Plan and execute framework audits, collect and validate evidence, perform control testing, and assess procedural compliance.
- Identify, document, and track audit findings, remediation plans, and control improvements.
- Partner with business and technology teams to ensure successful audit outcomes and ongoing compliance.
- Maintain knowledge of business systems, processes, regulations, and industry best practices.
Risk Management
- Monitor emerging security, privacy, and regulatory risks affecting the business.
- Conduct risk assessments and support risk register maintenance and treatment activities.
- Evaluate and score risks related to audit findings, exceptions, and attestations.
- Monitor, report, and escalate identified risks while driving remediation to acceptable risk levels.
- Collaborate with stakeholders to ensure risk exposure remains within approved tolerances.
Security Governance & Reporting
- Monitor compliance with security standards and controls.
- Review security metrics, compliance KPIs, and governance reports.
- Support security awareness and compliance initiatives.
- Prepare compliance and risk reports for management and key stakeholders.
Stakeholder & Customer Support
- Respond to customer security questionnaires, due diligence requests, and regulatory inquiries.
- Build strong relationships with internal and external stakeholders.
- Provide timely issue resolution, recommendations, and process improvements.
- Support projects from planning through completion, including reporting and recommendations.
Required Qualifications
Experience
- 3–4 years of experience in:
- Information Security
- Cybersecurity Compliance
- Governance, Risk & Compliance (GRC)
- IT Audit or Security Assurance
Compliance & Risk Knowledge
Strong understanding of:
- ISO 27001
- SOC 2
- NIST Cybersecurity Framework
- GDPR
- Risk Management methodologies
Technical Knowledge
Working knowledge of:
- Identity & Access Management (IAM)
- Multi-Factor Authentication (MFA)
- Vulnerability Management
- Logging & Monitoring
- Cloud Security fundamentals (Azure, AWS, GCP)
- Secure Change Management
- Data Protection & Encryption
Core Skills
- Audit coordination and evidence management
- Risk assessment and control testing
- Policy and procedure reviews
- Compliance reporting and documentation
- Stakeholder management and communication
Tools
Experience with:
- Microsoft 365
- Word and Excel (reporting and analysis)
- SharePoint / OneDrive
- GRC platforms such as Drata, Archer, LogicGate, or ServiceNow GRC
Education
Bachelor’s degree in information security, Computer Science, IT, Risk Management, or a related field.
Preferred Qualifications
Certifications
- ISO 27001 Internal Auditor or Lead Auditor
- Security+
- Certified in Cybersecurity (CC)
- CISA
Additional Knowledge
- DORA, CCPA, NYDFS
- Azure Defender / Security Center
- AWS Security Services
- Compliance metrics and KPI reporting
Soft Skills
- Executive presentations
- Project management
- Process improvement
- Training and coaching
- Cross-functional collaboration
Location: This role will be based out of The Leela Office located on the 4th Floor, Airport Road, Kodihalli, Bangalore- 560008.
Work Timing : 1 pm to 10 pm IST. Cab Pick-up and drop available.
Hybrid : Our expectation at this time, is that you would work from our office on Tuesdays, Wednesdays, Thursdays with flexibility to work from home on Mondays and Fridays.
We are committed to equality of opportunity for all staff and applications from individuals are encouraged regardless of age, disability, sex, gender reassignment, sexual orientation, pregnancy and maternity, race, religion or belief and marriage and civil partnerships. Please note any offer of employment is subject to satisfactory pre-employment screening checks.
Skills Required
- 3-4 years experience in Information Security, Cybersecurity Compliance, GRC, IT Audit or Security Assurance
- Strong understanding of ISO 27001, SOC 2, NIST Cybersecurity Framework, GDPR, and risk management methodologies
- Working knowledge of IAM, MFA, Vulnerability Management, Logging & Monitoring, Cloud Security (Azure, AWS, GCP), Secure Change Management, Data Protection and Encryption
- Experience coordinating audits, evidence management, control testing, and remediation tracking
- Policy and procedure reviews, compliance reporting, and documentation skills
- Stakeholder management and effective communication with technical and non-technical audiences
- Experience with Microsoft 365, Word, Excel, SharePoint / OneDrive
- Experience with GRC platforms such as Drata, Archer, LogicGate, or ServiceNow GRC
- Bachelor's degree in Information Security, Computer Science, IT, Risk Management, or related field
- ISO 27001 Internal Auditor or Lead Auditor certification
- Security+, Certified in Cybersecurity (CC), or CISA certification
- Knowledge of DORA, CCPA, NYDFS, Azure Defender/Security Center, AWS Security Services, and compliance KPI reporting
Equiniti Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Equiniti and has not been reviewed or approved by Equiniti.
-
Fair & Transparent Compensation — Company materials describe a formal pay framework and living‑wage commitments that provide clearer expectations on levels and ranges. Some mid‑to‑senior roles are characterized as competitively paid relative to market.
-
Retirement Support — UK roles are advertised with strong pension matching and access to a long‑term incentive plan, while U.S. roles commonly include a 401(k) and retirement planning options. These elements add meaningful long‑term value beyond base pay.
-
Leave & Time Off Breadth — UK packages promote generous annual leave alongside volunteer days, and U.S. accounts describe substantial PTO in some positions. Time‑off offerings are a recurring strength that bolsters total rewards.
Equiniti Insights
What We Do
Our people and platforms engage customers with investments, connect businesses with markets, and enable organisations to grow. Our vision is to be a leading global share registrar and transfer agent, offering complementary services in pensions and remediation, to help our customers succeed.









