About the Role : We are seeking an experienced and detail-oriented Information Security & Compliance Specialist to join Zeapl.ai. The ideal candidate will have hands-on experience with ISO 27001 : 2013 & SOC 2 ( Service Organization Control 2 Type 2)
implementation & Maintenance, a deep understanding of IT security controls, and a proactive approach to audit management and incident response. You will be a key stakeholder in building a secure, compliant, and resilient security framework across our organization.
Key Responsibilities : Lead the Maintenance of ISO 27001 : 2013 and support the organization in achieving SOC 2 Type II ( Service Organization Control 2 Type 2)
certification. Develop, review, and maintain information security policies, procedures, and guidelines tailored to organizational needs. Own and manage internal and external audits — including coordination, evidence gathering, remediation tracking, and closure of findings. Conduct periodic internal audits and client-specific assessments, ensuring compliance with regulatory and customer requirements. Deliver security awareness training, workshops, and compliance-related sessions across teams. Create, update, and maintain clear process documentation and standard operating procedures. Collaborate with IT and engineering teams to support network design, infrastructure audits, and security hardening. Lead incident response activities including root-cause analysis, documentation, lessons learned, and implementation of corrective / preventive actions (CAPA). Manage SOC strategy, processes, alerts, case aggregation, and SLA optimization. Perform vulnerability assessments, risk analysis, and application security testing as required. Analyse and report IS events, track incidents, identify weaknesses, and ensure timely escalation and resolution. Work closely with stakeholders on custom alert integrations, tuning detection logic, and managing logs and monitoring tools. Apply knowledge of IT infrastructure, including Windows, Linux, firewalls, IDS / IPS, VPNs, proxies, and endpoint security. Ensure continuous improvements in the security posture and compliance maturity of the organization.
Information Security Specialist • India