Karmacpa logo

Information Security & IT Governance Consultant

karmacpa

On-site
Surat, India
Part-time
Senior
8+ yrs
Salary not listedPosted 1mo ago

Real job — pulled straight from karmacpa’s careers page · Verified June 30, 2026 · No reposts.

Job description

karmacpa is hiring a Information Security & IT Governance Consultant — a part-time, based in Surat, India role. Apply directly on karmacpa's careers page below.

ISO Consultant (Part Time)

Location: Surat, India

Department: Others

Experience: 8-10 Years

1. About the Role
Karma Global Solutions (a ~150-person accounting/back-office firm serving US CPA and property-management companies) is hiring a part-time/retainer independent consultant to raise their IT and security posture to audit-grade standard, build and certify an ISMS aligned to ISO/IEC 27001:2022, and upskill in-house IT engineers for long-term sustainability. It's explicitly a build-and-transfer role — not a paperwork/template exercise.

2. Mandate / Objectives
Five core objectives:
  1. Diagnose current IT/security posture against ISO 27001:2022 (Annex A controls) and identify real gaps
  2. Build a certifiable ISMS — scope, risk assessment, Statement of Applicability, policies, and technical controls
  3. Harden actual infrastructure (identity, access, endpoints, network, remote access, logging, backup/DR)
  4. Mentor two in-house IT engineers to independently operate and maintain the ISMS
  5. Drive certification through Stage 1 and Stage 2 audits with zero major non-conformities
3. Key Responsibilities & Deliverables
Broken into four areas:
  • A. Assessment & Strategy — Gap assessment, asset inventory, risk assessment, ISMS scope, and Statement of Applicability
  • B. Implementation — Author core policies (access control, incident response, DR, vendor management, etc.) and implement technical controls (MFA, EDR, network segmentation, logging, encryption, DLP, etc.)
  • C. Governance & Audit Readiness — Internal audit programme, management reviews, vendor due diligence, certification body management
  • D. Capability Building — Hands-on IT engineer mentoring, company-wide security awareness training, and leaving behind runbooks/SOPs
4. Required Qualifications
Mandatory:
  • 8+ years in IT/information security with hands-on ISMS implementation experience
  • ISO/IEC 27001:2022 Lead Implementer and/or Lead Auditor certification
  • Personally taken at least one organisation end-to-end through ISO 27001 certification (references required)
  • Strong technical depth in IAM, endpoint/network security, logging, and backup/DR
  • BPO/KPO/ITES or financial services experience handling third-party client data
Strongly Preferred:
  • CISM / CISA / CISSP
  • SOC 2 Type II readiness experience
  • Exposure to US-client delivery environments and US data-privacy expectations
  • Familiarity with cloud and self-hosted infrastructure tooling

Get Information Security & IT Governance Consultant jobs like this

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Accenture logo

Crowdstrike Technical Consultant

London
✓ From careers page· 3h ago
Accenture logo

Technical Consulting Manager, Crowdstrike

London
✓ From careers page· 3h ago
Accenture logo

Crowdstrike Technical Consulting Manager

London
✓ From careers page· 3h ago
Accenture logo

Database Administrator

Santiago
✓ From careers page· 3h ago

Frequently asked questions

What skills are required for Information Security & IT Governance Consultant at karmacpa?

The required skills for Information Security & IT Governance Consultant at karmacpa include: ISO 27001, IAM, CISM, CISA, CISSP, SOC 2.

What is the seniority level for Information Security & IT Governance Consultant at karmacpa?

Information Security & IT Governance Consultant at karmacpa is a Senior level position.

How do I apply for Information Security & IT Governance Consultant at karmacpa?

You can view the full description and apply for Information Security & IT Governance Consultant at karmacpa on EchoJobs: https://echojobs.io/job/karmacpa-fractional-information-security-it-governance-consultant-part-time-qbh7e.