Support and maintain ISO 27001 certification by monitoring compliance, performing audits, and implementing necessary corrective actions.
Lead ISO 27001 gap analysis and risk assessments, and provide recommendations for continuous improvement.
Develop, review, and update ISO 27001 documentation, including policies, procedures, and control guidelines.
Business Continuity Management (BCM):
Collaborate with departments to maintain and update the Business Continuity Management System (BCMS), ensuring alignment with organizational needs.
Conduct Business Impact Analysis (BIA) to identify critical processes, assess risks, and design business continuity plans to ensure operational resilience.
Perform regular testing of BCMS protocols and lead recovery activities as needed.
Stakeholder Communication and Reporting:
Act as a liaison between the Information Security team and stakeholders, including executive management, to communicate security posture, risks, and improvement initiatives.
Draft clear, concise reports on security assessments, risk analysis, and incident management outcomes.
Present security metrics and dashboards to management, highlighting areas of risk and proposing corrective actions.
Audit and Compliance Support:
Assist in internal and external audits related to ISO 27001 and other regulatory requirements, providing relevant documentation and evidence.
Collaborate with cross-functional teams to address audit findings and ensure the closure of gaps.
Security Awareness and Training:
Support security awareness initiatives and training programs to promote a security-first culture within the organization.
Contribute to the development of educational materials that enhance understanding of security policies and incident response procedures.
Required Qualifications:
Bachelor s degree in Information Security, Computer Science, or a related field.
4-5 years of experience in Information Security, with proven experience in ISO 27001 implementation and management.
Strong understanding of BCMS principles and Business Impact Analysis.
Proficiency in report writing and the ability to clearly communicate technical details to non-technical stakeholders.
Excellent verbal and written communication skills, with a demonstrated ability to interact effectively with senior management and other key stakeholders.
Certifications such as ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, or CISA is a plus
Key Competencies:
Attention to detail and ability to handle multiple tasks with minimal supervision.
Strong analytical skills and a proactive approach to identifying security risks and proposing solutions.
Collaborative mindset, with the ability to work effectively within cross-functional teams.