JOB PURPOSES:
Ensure the organization’s compliance with ISO 27001, SOC 2 readiness, and data protection regulations.
Support IT risk assessment, audit coordination, and security governance activities.
PRINCIPAL ACCOUNTABILITIES:
1. Governance & Compliance
2. Risk Management
Conduct regular IT systems and process risk assessments using established frameworks.
Collaborate with stakeholders to develop risk treatment plans and track remediation progress
3. Security Assessment & Client Support
Coordinate responses to security questionnaires and customer/vendor assessments.
Act as a liaison between auditors and technical teams to review and validate evidence.
4. Incident, Continuity & Audit Support
5. Security Awareness
Deploy and manage security awareness training programs for employees.
Minimum 3 years of experience working in IT GRC, Information Security, IT Audit or related fields.
ISO 27001 Internal Auditor or similar. Experience participating in ISO 27001 audits or implementation projects. (nice to have)
Growth Mindset & One-Team Mindset