Risk & Compliance Analyst
Job Summary
Codilar is hiring a Compliance & ISO Officer who will report directly to management and act on their behalf to ensure that organizational processes, SOPs, and information security requirements are consistently followed. This role owns the creation, maintenance, and monitoring of Standard Operating Procedures (SOPs) across departments, and independently drives the organization's ISO 27001:2022-aligned Information Security Management System (ISMS). The ideal candidate is smart, highly organized, an excellent communicator, and comfortable working with a high degree of independence and ownership while representing management's expectations to other teams.
This is a standalone compliance charter (distinct from the Operations Associate role) for someone who will be the organization's go-to person for process discipline, SOP governance, and information security compliance.
Key Responsibilities
A. SOP & Process Governance
Own the creation, documentation, and periodic review of Standard Operating Procedures (SOPs) across departments.
Monitor adherence to SOPs and organizational processes on behalf of management, flagging deviations and driving corrective action.
Conduct periodic internal process/compliance checks across teams and report findings directly to management.
Partner with department heads to standardize and continuously improve processes and documentation.
Maintain a central repository of SOPs, policies, and process documentation, ensuring version control and easy accessibility.
B. Information Security / ISO 27001 (ISMS) Ownership
Own day-to-day administration of Codilar's Information Security Policy and drive compliance with the ISO 27001:2022-aligned ISMS.
Coordinate and track completion of mandatory annual information security awareness training for all employees.
Maintain ISMS documentation and audit evidence, including access reviews, incident logs, risk registers, and the vendor/third-party security register.
Lead preparation for internal and external ISO 27001 audits, and track corrective and preventive actions (CAPA) to closure.
Ensure vendor and third-party NDAs/security agreements are in place, reviewed periodically, and access is revoked when no longer required.
Log and follow up on reported security incidents, coordinating with the IT/Security team and relevant stakeholders.
Periodically review the Information Security Policy and related SOPs, and communicate updates to employees.
Act as the liaison between IT/Security, HR, and department heads to ensure ISMS and SOP requirements are implemented consistently across the business.
C. Reporting to Management
Report directly to management with periodic compliance status updates, audit findings, and process-adherence dashboards.
Independently represent management's expectations on process and compliance matters when engaging with other teams.
Escalate significant compliance risks, SOP violations, or security incidents to management promptly.
Qualifications & Skills
- Bachelor's degree is required.
- Minimum 1 year of experience in compliance, quality/process (SOP) management, audit, or information security, preferably in a software/IT company.
- Working knowledge of, or strong willingness to learn, ISO 27001 and ISMS practices (training and mentorship will be provided).
- Smart, proactive, and highly organized, with strong attention to detail and process orientation.
- Excellent verbal and written communication skills, with the confidence to engage directly with management and cross-functional teams.
- High level of integrity and discretion in handling confidential and sensitive information.
- Ability to work independently, take ownership, and drive follow-through with minimal supervision.
Other Details
- Location: Bangalore (Onsite)
- Experience: Minimum 1 year