ISA is a premier technology solution provider for the Aviation industry. We are backed by Air Arabia and headquartered in Sharjah, UAE. (www.isa.ae )
ISA (Information Systems Associates) is a premier in the field of Information Technology providing best-of-breed technology solutions for the global travel and aviation industry since 2005. We offer a wide range of tailor-made aviation technology
We are hiring!
Colombo, Sri Lanka
Information Security Compliance Specialist
Job Purpose
The Information Security Compliance Specialist ensures the organization’s information security practices comply with internal policies, contractual obligations, and external regulatory requirements. This role supports audits, manages security governance documentation, responds to third-party and regulatory requests, and drives the implementation of security compliance initiatives across the business.
Key Responsibilities
- Governance & Policy Management
- Develop, review, and maintain information security policies, procedures, and standards.
- Ensure alignment of policies with international frameworks (e.g., ISO 27001, NIST, PCI DSS, GDPR, etc. as applicable).
- Monitor adherence and coordinate periodic reviews.
- Compliance & Regulatory Engagement
- Support external and internal audits, certifications, and compliance assessments.
- Act as a point of contact for regulatory bodies, customers, and partners on compliance and assurance matters.
- Ensure timely submission of compliance reports and regulatory filings.
- Risk & Assurance Activities
- Conduct compliance checks, security risk assessments, and gap analyses.
- Coordinate responses to Data Processing Agreements (DPAs), Non-Disclosure Agreements (NDAs), and vendor due diligence.
- Manage responses to security questionnaires and requests for solutions or providers assessments.
- Awareness & Continuous Improvement
- Provide guidance to teams on compliance requirements and best practices.
- Support awareness programs to embed a culture of information security compliance.
- Track changes in laws, regulations, and industry standards, advising management on their impact.
Qualifications & Experience
Bachelor’s degree in Information Security, Computer Science, IT, or related field.3–6 years of experience in information security, IT governance, or compliance.Knowledge of regulatory requirements (e.g., GDPR, local data protection laws, etc. depending on jurisdiction).Familiarity with security standards / frameworks (ISO 27001, NIST CSF, SOC 2, COBIT, etc.).Experience with audit processes and vendor security risk management.Skills & Competencies
Strong understanding of information security governance and compliance practices.Excellent analytical, problem-solving, and documentation skills.Ability to communicate effectively with technical and non-technical stakeholders.Attention to detail and ability to manage multiple compliance tasks simultaneously.Certifications preferred : CISM, CISA, ISO 27001 Lead Implementer / Auditor, or equivalent.Please send your profiles to careers@isa.ae