About this role
•As a GRC Analyst supporting the ISO 27001 program, you will help maintain and enhance the organization's Information Security Management System (ISMS).
•Responsibilities include performing control assessments and testing, supporting ISO 27001 audits and certification activities, monitoring compliance with ISO 27001 requirements, managing audit findings and remediation actions, maintaining ISMS documentation, and tracking program readiness to strengthen the organization's security and compliance posture.
•Support the implementation, maintenance, and continual improvement of the ISO 27001 Information Security Management System (ISMS).
•Conduct risk assessments for systems, applications, and third-party vendors in alignment with ISO 27001 and NIST CSF.
•Perform control assessments and testing to evaluate the effectiveness of security controls and recommend remediation actions.
•Conduct gap assessments and compliance reviews against ISO 27001 requirements and related security frameworks.
•Support ISO 27001 certification, surveillance audits, and audit readiness activities.
•Coordinate internal and external audits, including evidence collection and tracking of corrective actions.
•Maintain risk registers, policies, procedures, and other ISMS documentation.
•Monitor and track audit findings, risks, issues, and remediation plans through closure.
•Collaborate with business, IT, security, and compliance teams to ensure adherence to ISO 27001 requirements.
•Facilitate management reviews, governance meetings, and compliance reporting.
•Utilize IRM modules, including Risk, Policy & Compliance, Audit, and Issue Management, to support program operations.
•Added advantage: Experience working with ServiceNow IRM modulesble.
Work experience
•Good years of experience in Governance, Risk & Compliance (GRC), Information Security.
•Relevant years of experience managing ISO certification programs.
•Strong understanding of ISO 27001 standard.
•Experience with risk assessments, control frameworks, and audit management.
•Excellent stakeholder management, communication, and project management skills.
Responsibilities
- Strong client interaction skills, both written and verbal
- Highly Fluent in English – verbal and written
- Critical thinking, including questioning, digestion, thought process, and documentation of same.
- Acute attention to detail.
- Exceptional time management, including speed and ownership to drive closure and seek solutions.
- Ability to effectively manage competing priorities.
Qualifications
Additional Qualification:
- •Prior consulting experience with big 4 or large clientele is preferable.
- •ISO27001-LA/LI, CISA, CRISC or CISSP is preferrable
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?