Job descriptionRole Overview
The candidate is an experienced Information Security professional with a strong blend of technical security operations expertise and information security process/standards knowledge. With hands-on experience in ISO 27001 implementation, auditing, and continuous improvement, they contribute to strengthening the organization's security posture through robust policies, risk management practices, and compliance frameworks.
Key Responsibilities
Security Operations Expertise:
Apply hands-on experience in IT security domains to support threat management, incident response, vulnerability handling, and security monitoring activities.
ISMS Implementation & Management (ISO 27001)
Lead the implementation, maintenance, and continuous improvement of the Information Security Management System in alignment with ISO 27001 requirements.
Policy & Documentation Development
Draft, review, and maintain Information Security policies, standards, and technical documents by leveraging a unique combination of technical and process-oriented knowledge.
ISO 27001 Audits & Compliance
Conduct internal audits as ISO 27001 Lead Auditor, coordinate with external auditors, and drive remediation of audit findings.
Risk Management
Support and improve the IT Risk & Controls Framework by identifying risks, performing risk assessments, monitoring controls, and ensuring alignment with industry best practices.
Stakeholder Collaboration
Work with cross-functional teams—including IT, business units, and compliance—to ensure security controls are understood, implemented, and effective across the organization.
Continuous Improvement
Recommend enhancements to security processes, controls, and technologies based on evolving threats, audit insights, and operational learnings.
Skills & Qualifications
Hands-on experience in Security Operations and IT Security technologies.
Certified ISO 27001 Lead Auditor and Lead Implementer.
Strong expertise in drafting Information Security policies and frameworks.
Proven experience in implementing and managing ISMS.
Experience in IT Risk Management and Controls frameworks (preferably in global or financial organizations).
Strong analytical, communication, and documentation skills.
Skills Required
Iso 27001, Security Operations, Risk Management