Verified today
Control Advisor
About the role
The Control Advisor role supports the organization’s information security compliance program by leading audits, regulatory compliance initiatives, control assessments, risk management activities, and evidence collection. Day-to-day, the advisor plans and executes framework audits (ISO 27001, SOC 2, GDPR, DORA, FISMA), conducts risk assessments, reviews security metrics and governance reports, and partners with business and technology teams to drive remediation and process improvement. Based at The Leela Office, Airport Road, Kodihalli, Bangalore, this hybrid position follows a 1 pm to 10 pm IST schedule with office days on Tuesdays, Wednesdays, and Thursdays.
What you’ll do
- Lead and maintain information security compliance programs aligned with corporate policies and regulatory requirements
- Support and manage audits and compliance frameworks such as ISO 27001, SOC 2, GDPR, DORA, FISMA, and related standards
- Serve as a subject matter expert on security and compliance matters
- Plan and execute framework audits, collect and validate evidence, perform control testing, and assess procedural compliance
- Identify, document, and track audit findings, remediation plans, and control improvements
- Partner with business and technology teams to ensure successful audit outcomes and ongoing compliance
- Conduct risk assessments and support risk register maintenance and treatment activities
- Evaluate and score risks related to audit findings, exceptions, and attestations
What you’ll bring
- 3–4 years of experience in information security, cybersecurity compliance, GRC, IT audit, or security assurance
- Bachelor’s degree in information security, computer science, IT, risk management, or a related field
- Strong understanding of ISO 27001, SOC 2, NIST Cybersecurity Framework, GDPR, and risk management methodologies
- Working knowledge of IAM, MFA, vulnerability management, logging & monitoring, cloud security fundamentals (Azure, AWS, GCP), secure change management, and data protection & encryption
- Audit coordination and evidence management skills
- Risk assessment and control testing skills
- Policy and procedure review skills
- Compliance reporting and documentation skills
Nice to have
- ISO 27001 Internal Auditor or Lead Auditor certification
- Security+ certification
- Certified in Cybersecurity (CC) certification
- CISA certification
- Additional knowledge of DORA, CCPA, NYDFS
- Azure Defender / Security Center knowledge
- AWS Security Services knowledge
- Compliance metrics and KPI reporting experience
Skills
Education
Bachelor’s degree in information security, Computer Science, IT, Risk Management, or a related field.