Responsible for the implementation, maintenance, and continuous improvement of the Information Security Management System (ISMS) in compliance with ISO/IEC 27001 standards. This role focuses on integrating security governance, risk management, and compliance (GRC) into the organization’s IT operations.
Key Responsibilities:
ISMS Management: Implement and maintain the ISMS framework and ensure alignment with ISO 27001.
Policy & Governance: Draft, implement, and enforce security policies, standards, and procedures.
Risk Management: Conduct periodic IT risk assessments, identify threats, and manage Risk Treatment Plans (RTP).
Auditing & Compliance: Perform internal audits, manage non-conformities (CAPA), and coordinate with external auditors.
Vendor Security: Conduct security assessments for third-party providers and vendors.
Awareness: Drive security awareness programs across the organization.
Required Qualifications:
Bachelor’s degree in Computer Science, IT, Cyber Security, or a related field.
Experience: at least 3 years of experience in IT Security, GRC, or ISMS implementation.
Deep understanding of ISO/IEC 27001/27002, risk assessment methodologies (e.g., ISO 27005), and security controls.
Core Skills:
Analytical: Ability to perform root-cause analysis and risk modeling.
Communication: Capable of translating technical risks into business terms for management.
Attention to Detail: Rigorous approach to auditing and documentation.