Risk Analyst
VicTree Solutions
Job Description
VicTree Solutions is hiring for a IT Risk & Audit Consultant for a client in Vashi, Navi Mumbai. Job Title: IT Risk & Audit Consultant Experience Required: 2-4 Years Work Mode: Onsite only Engagement Type: Full Time Location: Navi Mumbai Role: The Consultant will work closely with client organizations to design, implement, and enhance their governance, risk, and compliance programs. The role focuses on enabling clients to achieve and sustain compliance with global standards such as ISO 27001, SOC 2, regulatory requirements (RBI, SEBI etc.) and successfully navigate regulatory audits, and strengthen their overall risk posture through structured assessments and advisory.
Educational Qualifications: BE-IT / B Tech /MBA or equivalent Certifications: Bachelor’s degree in Information Security, Computer Science, or a related field Certifications such as ISO 27001 Lead Auditor/Lead Implementer, CISA, CRISC, or CISSP Experience in a consulting, advisory, or professional services environment Key Responsibilities: Lead and support clients in achieving and maintaining ISO 27001 certification, including readiness assessments, control implementation, documentation, and audit coordination. Drive end-to-end SOC 2 (Type I & Type II) engagements, including scoping, control design, evidence management, and liaison with auditors. Advise clients on regulatory compliance requirements (e.g., RBI, SEBI, data protection regulations), including control implementation, audit preparedness and response management.
Conduct gap assessments and maturity assessments against industry frameworks; develop prioritized remediation roadmaps aligned to business risk. Perform enterprise risk assessments, helping clients identify, evaluate, and mitigate cybersecurity and compliance risks. Develop and refine information security policies, standards, and governance frameworks tailored to client environments.
Act as a trusted advisor to client stakeholders, providing strategic guidance on improving security posture and compliance maturity. Support clients during external audits and certifications, including evidence preparation, walkthroughs, and audit responses. Create assessment reports, client presentations and framework documents Track and report risk, compliance status, and remediation progress to client leadership.
Stay current with evolving regulatory landscapes, threat trends, and industry best practices to provide proactive advisory. Skills Required: Strong consulting experience in ISO 27001, SOC 2, and regulatory compliance frameworks. Proven ability to lead client engagements and manage multiple projects simultaneously.
Hands-on expertise in gap assessments, risk assessments, and control implementation. Strong stakeholder management and communication skills, with the ability to engage senior leadership. Ability to translate compliance requirements into practical, business-aligned solutions.
Excellent documentation and presentation skills. Lets connect on LinkedIn - www.linkedin.com/in/aneeshkjain