We are looking for a Cyber Security Specialist to own our IT and information security certification schemes end-to-end. The role holder will manage certification projects across their full lifecycle, lead audits of client organizations across a range of industries, and act as the technical authority for SIS on information security and cyber security standards. This is a hands-on role combining audit delivery, scheme ownership, and technical governance.
Preferred candidate profile
*We are seeking an experienced information security professional who understands certification from the inside someone who can both audit to a high standard and govern schemes technically. The ideal candidate combines certification-body experience with real IT/cyber security depth.*
- 4–7 years of total experience, including a minimum of 2 years within a certification body and 2–3 years in IT managing cyber/information security.
- Hands-on experience leading ISO/IEC 27001 audits as a Lead Auditor.
- Strong working knowledge of information security controls, risk assessment, and ISMS implementation.
- Familiarity with the certification lifecycle — audit stages, accreditation, surveillance, and recertification.
- Sound understanding of ISO/IEC 17021-1 and accreditation requirements (IAF).
- Excellent report-writing, communication, and stakeholder-management skills.
- High standards of audit discipline, objectivity, and attention to detail.
Preferred / Desirable
- ISO/IEC 27001 Lead Auditor certification (IRCA / Exemplar Global or equivalent).
- Qualified credentials such as CISA, CISM, or CISSP.
- Exposure to ISO/IEC 27701 (Privacy), SOC 2, or ISO/IEC 20000-1 (IT Service Management) audits.
- Awareness of allied frameworks — ISO/IEC 42001 (AI Management), DPDP Act 2023, and GDPR.