HamburgerMenu
hirist

Information Security Officer - IT Compliance

Posted on: 15/07/2025

Job Description

Job Summary :

We are seeking an experienced Information Security Officer to lead the implementation, management, and continuous improvement of our ISO 27001-based Information Security Management System (ISMS). The ideal candidate will be responsible for ensuring compliance with ISO 27001, managing cybersecurity risks, and safeguarding our organization's digital infrastructure against threats and vulnerabilities.


Key Responsibilities:


- Lead the implementation and sustenance of the ISO 27001-based ISMS across the organization.

- Conduct risk assessments and gap analyses to identify security threats and ensure compliance with ISO 27001.

- Develop and implement a comprehensive set of information security policies, standards, and procedures.

- Audit internal processes to validate the effectiveness of current cybersecurity strategies.

- Plan and implement cybersecurity controls to mitigate risks from cyberattacks, unauthorized access, and data breaches.

- Monitor, assess, and continuously improve security posture based on threat intelligence and best practices.

- Participate in incident response activities including investigation, containment, recovery, and root cause analysis.

- Oversee the deployment, configuration, and maintenance of security tools and technologies (e.g., firewalls, antivirus, DLP, SIEM).

- Provide guidance and support for Business Continuity Planning (BCP) and IT Disaster Recovery Planning (DRP) initiatives.

- Conduct internal security awareness trainings and promote a culture of security across the organization.

- Collaborate with IT, audit, compliance, and business teams to ensure seamless integration of security requirements.


Required Skills & Qualifications:


- Bachelor's degree in Information Technology, Computer Science, or a related field.

- ISO 27001 Lead Implementer / Lead Auditor certification preferred.

- Proven experience in implementing and maintaining ISO 27001 ISMS.

- Strong knowledge of network and system security principles, technologies, and practices.

- Solid understanding of cybersecurity risk assessment frameworks and security auditing.

- Experience with incident detection and response, and security operations.

- Familiarity with BCP/DRP planning and execution.

- Excellent analytical, communication, and documentation skills.


info-icon

Did you find something suspicious?