Azure Data Security & Compliance Audit - Need to obtain DPDP and SOC2 certificate
Budget / Salary₹12,500–37,500
TypeFreelance project
LocationRemote
Posted1 hour ago
I need an experienced security professional to examine our current environment and bring it in line with GDPR, SOC and India’s upcoming DPDP requirements and get our products certified on DPDP SOC2, relevant ISO etc. We already have a security program in place, but many of the controls no longer meet best-practice standards, so the primary objective is a full-scale assessment that shows the exact gaps and then guides us through remediation. Our products are hosted on Azure servers.
Where we feel weakest is encryption of data at rest and in transit, granular role-based access management, real-time monitoring, incident response playbooks and a stronger defence against external intrusion attempts. I expect a thorough review of policies, configurations and toolsets (think SIEM, IDS/IPS, DLP, MFA, privileged-access management) followed by a clear, actionable roadmap.
Deliverables
• Gap-analysis report mapped to GDPR, SOC and DPDP clauses
• Risk-ranked remediation plan with timelines and ownership suggestions
• Updated policy documents and control matrices ready for audit
• Proof-of-concept configurations or scripts for critical fixes (e.g., encryption, log forwarding, alerting)
• Final compliance readiness scorecard and executive summary
- Help obtaining DPDP certificate, SOC2, GDPR, ISO etc.
Acceptance criteria
All findings must reference the exact regulatory articles or controls, and recommended actions should be technically feasible within our existing cloud/on-prem hybrid stack. Documentation must be audit-ready, written in plain English, and validated in a review walkthrough with our internal team.
Obtain DPDP certificate, SOC2, GDPR, ISO etc.
Where we feel weakest is encryption of data at rest and in transit, granular role-based access management, real-time monitoring, incident response playbooks and a stronger defence against external intrusion attempts. I expect a thorough review of policies, configurations and toolsets (think SIEM, IDS/IPS, DLP, MFA, privileged-access management) followed by a clear, actionable roadmap.
Deliverables
• Gap-analysis report mapped to GDPR, SOC and DPDP clauses
• Risk-ranked remediation plan with timelines and ownership suggestions
• Updated policy documents and control matrices ready for audit
• Proof-of-concept configurations or scripts for critical fixes (e.g., encryption, log forwarding, alerting)
• Final compliance readiness scorecard and executive summary
- Help obtaining DPDP certificate, SOC2, GDPR, ISO etc.
Acceptance criteria
All findings must reference the exact regulatory articles or controls, and recommended actions should be technically feasible within our existing cloud/on-prem hybrid stack. Documentation must be audit-ready, written in plain English, and validated in a review walkthrough with our internal team.
Obtain DPDP certificate, SOC2, GDPR, ISO etc.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.