Job Description
This is a remote position.
The ISO 27001 Internal Auditor is responsible for planning, conducting, and reporting on internal audits of an organization’s Information Security Management System (ISMS) to ensure compliance with the ISO 27001 standard. This role is crucial for identifying vulnerabilities, recommending improvements, and supporting the continuous enhancement of information security practices within the organization
Requirements
Key Responsibilities
- Conduct Internal Audits : Plan and execute audits of the ISMS, including reviewing documentation, interviewing staff, and observing processes to assess compliance with ISO 27001 requirements.
- Identify Security Risks and Gaps : Detect vulnerabilities, non-conformities, and areas where improvements are needed in the organization’s information security practices.
- Prepare Audit Reports : Document findings, including identified risks, weaknesses, and recommendations for corrective actions.
- Recommend Corrective Actions : Provide actionable recommendations to address deficiencies and enhance the effectiveness of the ISMS.
- Monitor Progress : Track the implementation of corrective actions and conduct follow-up audits to verify their effectiveness.
- Ensure Continuous Improvement : Support ongoing improvements to information security controls and processes.
- Communicate Findings : Clearly communicate audit results and recommendations to management and relevant stakeholders.
Skills and Competencies
Knowledge of ISO 27001 : Deep understanding of the standard and its requirements.Risk Assessment Expertise : Ability to identify and assess risks in information security management systems.Attention to Detail : Meticulous in identifying vulnerabilities and gaps.Strong Communication : Capable of documenting and presenting audit findings effectively.Problem-Solving : Able to recommend practical solutions to security weaknesses.Interpersonal Skills : Ability to work collaboratively with various teams and management.Qualifications
ISO 27001 Internal Auditor certification (preferred or required).Experience in information security, risk management, or auditing.Familiarity with ISMS processes and controls.Requirements
Candidate will be accountable for : Set up IT infrastructure foundation from scratch Managing and maintenance of Servers, virtual machines on both on premises and cloud (AWS and Azure) Security, performance and Networks Implementation of regulatory frameworks