Job DescriptionJob Overview:
nThe Information Security Consultant will be responsible for the implementation, assessment, and management of ISO 27001:2022, ISO 27002, and SOC 2 standards for clients. This role involves working independently or alongside senior consultants to help clients achieve and maintain information security compliance and other best practices. The consultant will focus on assessing and ensuring compliance with key security frameworks and will provide vCISO support to various clients.
nKey Responsibilities:
nISO 27001/27002 Compliance:
n
- n
- Assist clients in achieving ISO 27001 certification by identifying and implementing the appropriate controls within the audit scope.n
- Verify compliance with ISO 27001/27002 controls and provide recommendations for improvement.n
nSOC 2 Compliance:
n
- n
- Assist clients in achieving SOC 2 compliance by identifying and implementing the appropriate Trust Service Criteria (TSCs).n
- Conduct SOC 2 compliance assessments and ensure the proper implementation of required controls.n
nRisk Assessment and Mitigation:
n
- n
- Conduct risk assessments of business activities, collaborating with stakeholders to manage risks until closure or acceptance.n
- Provide actionable recommendations to mitigate identified risks.n
nPolicy and Procedure Development:
n
- n
- Define, develop, and review information security policies, procedures, guidelines, forms, and templates in line with best practices.n
- Ensure documentation is up-to-date and aligned with industry standards.n
nBaseline Standards Review:
n
- n
- Create and review baseline standards for operating systems, databases, web servers, and applications.n
- Recommend improvements based on security assessments.n
nPost-Implementation Audits:
n
- n
- Support post-implementation audits for ISO 27001:2022 to ensure ongoing compliance.n
- Monitor and assess adherence to established information security standards.n