ISO 27001 Auditior
TAC Security · Delhi, India
قدّم وتابع مع أبلاي إيدجRole OverviewTAC Security is looking for an experienced ISO/IEC 27001 Specialist to manage, implement, maintain, and continuously improve the organization’s Information Security Management System (ISMS) in alignment with ISO/IEC 27001:2022.The candidate will be responsible for information security governance, risk management, control implementation, internal audits, certification readiness, evidence management, compliance monitoring, and coordination with external auditors.The role will work closely with Information Security, IT, HR, Legal, Finance, Engineering, Operations, and senior leadership teams to ensure effective implementation and continuous improvement of information security controls across TAC Security's global operations.Key Responsibilities1. ISO/IEC 27001 & ISMS ManagementImplement, maintain, and continuously improve the organization's ISMS in accordance with ISO/IEC 27001:2022.Maintain the ISMS scope, policies, procedures, standards, guidelines, and supporting documentation.Ensure alignment of security practices with ISO/IEC 27001 requirements and applicable ISO/IEC 27002 controls.Conduct regular ISMS reviews and identify opportunities for improvement.2. Risk ManagementConduct information security risk assessments and maintain the organizational risk register.Identify, assess, prioritize, and monitor information security risks.Develop and track risk treatment plans and corrective actions.Support business teams in identifying security risks associated with new projects, technologies, vendors, and processes.3. Statement of Applicability & ControlsMaintain and periodically review the Statement of Applicability (SoA).Map business and technical controls against ISO/IEC 27001 requirements.Validate control implementation and operating effectiveness.Coordinate with control owners for timely remediation of gaps and exceptions.4. Internal & External AuditsPlan and conduct ISO/IEC 27001 internal audits.Coordinate certification, surveillance, and recertification audits with external certification bodies.Prepare audit plans, evidence repositories, audit schedules, and management responses.Track audit observations, non-conformities, corrective actions, and closure.Ensure audit evidence is complete, accurate, and available within defined timelines.5. Security Policies & DocumentationDevelop, review, and maintain information security policies, procedures, standards, and guidelines.Ensure policies are communicated to relevant stakeholders and reviewed periodically.Maintain proper documentation and version control for ISMS records.6. Compliance & Evidence ManagementEstablish an effective compliance evidence collection and monitoring process.Coordinate with different departments to collect evidence for ISO controls.Maintain audit-ready documentation and compliance dashboards.Monitor compliance against internal policies, contractual requirements, and applicable regulatory obligations.7. Security Awareness & TrainingCoordinate ISO 27001 and information security awareness programs.Develop training and awareness material for employees.Support periodic security awareness campaigns, phishing simulations, and policy acknowledgements.8. Third-Party & Vendor RiskSupport information security assessments of vendors, suppliers, and third parties.Review vendor security questionnaires, contracts, and security commitments.Monitor third-party compliance with applicable security requirements.Maintain vendor risk assessment records.9. Incident, Business Continuity & Security GovernanceCoordinate with relevant teams to ensure security incidents are appropriately documented and reviewed from an ISMS perspective.Support Business Continuity and Disaster Recovery governance.Ensure lessons learned from incidents and exercises are incorporated into the ISMS.Participate in management reviews and security governance meetings.10. Global Compliance SupportSupport ISO 27001 compliance across TAC Security's global operations.Coordinate with international teams and stakeholders across different geographies.Ensure consistent implementation of information security policies and controls across locations.Support customer security assessments, due-diligence questionnaires, and compliance requests.Required Skills & Experience4–8 years of experience in ISO 27001, or Cybersecurity Compliance.Strong hands-on experience with ISO/IEC 27001:2022.Practical experience in ISO 27001 implementation, maintenance, and certification audits.Strong knowledge of information security risk management.Experience in developing and maintaining Statement of Applicability (SoA) and risk registers.Experience conducting internal audits and managing external audits.Strong understanding of information security controls and control effectiveness.Experience with compliance evidence collection and audit management.Good understanding of cybersecurity concepts, including VAPT, IAM, endpoint security, network security, cloud security, vulnerability management, and data protection.Strong documentation, analytical, communication, and stakeholder-management skills.Preferred CertificationsISO/IEC 27001 Lead Auditor