02 Oct
|
Outcome Logix ( A Tech 50 Finalist company 2025 and 2022, by Pittsburgh Technology Council )
|
India
02 Oct
Outcome Logix ( A Tech 50 Finalist company 2025 and 2022, by Pittsburgh Technology Council )
India
Validate and operationalize the existing ISO 27001 and TISAX ISMS foundation. Build on the policies, procedures, methodologies, templates, assessments, and remediation plans already prepared. Complete missing ISO 27001 deliverables, coordinate business and technology control owners, establish repeatable evidence of control operation, and prepare the organization for certification while aligning with security governance.
Scope and reporting
- Work remotely with availability overlapping the US Eastern workday through at least 12 pm Eastern.Partner with IT and business functions.
- Confirm and document the initial certification scope before a detailed partner RFP or audit commitment. Validate in-scope sites, systems,processes, data, third parties, corporateIT, critical ERP and engineering applications, plant systems, exclusions, interfaces, and dependencies. Use the existing TISAX/ISO 27001 remediation action plan, management briefing, and readiness report as the implementation baseline.
- Use established Quality and audit practices where applicable. Focus the initial assignment on ISO 27001;other certification programs will follow.
Key responsibilities
- Scope and plan. Confirm and control the scope and implementation plan, building on the existing action plan. Define workstream ownership, priorities, milestones, dependencies, acceptance criteria, evidence requirements, decision points, and reporting cadence through readiness and certification audits.
- Assessment. Validate ISO 27001 clauses and applicable Annex A controls against the existing TISAX assessment and evidence.
Maintain one prioritized gap, risk, and remediation plan with accountable owners,due dates, closurecriteria, and verification evidence.
- ISMS design. Validate and operationalize the existing risk assessment and treatment method,complete the risk register and Statement of Applicability, confirm policy and control ownership, reconcile document status, and establish a controlled evidence repository. Existing documents should be reviewed and improved rather than recreated by default.
- Control delivery. Coordinate implementation across infrastructure, cybersecurity, ERP and plant systems, identity, vendors, physical protection, mobile IT, projects,and business processeswithout displacing operational control owners. Prioritize asset and CMDB ownership, access governance, physical protection, third-party security, and repeatable evidence.
- Assurance. Prepare ISO 27001 awareness activities, internal audit, management review, corrective actions, and evidence of control operation. Integrate with existing ITGC,SOX, IATF, TISAX,penetration-test, resilience, and other applicable evidence, and verify that findings are tracked through closure and retest.
- Certification. Coordinate certification-body selection,
readiness reviews,and Stage 1 and Stage 2 audits.Maintain the assessor request log, prepare control owners for interviews, track findings, and drive corrective-action closure and verification with accountable owners and the certification body.
- Partners. Assess a focusedshortlist of specialist partners, starting with existing quality and certification relationships; use work from home where effective and site visits where necessary.
Experience and capabilities
Leadership
Has led cross-functional security or compliance programs across multiple sites, with clearownership, practical prioritization and executive reporting.
ISO 27001 practice
Experience operationalizing an existing ISO 27001 ISMS foundation through audit readiness, including gap validation, risk treatment, Statement of Applicability, control implementation, evidence repositories, internal audit, management review, corrective action, and Stage 1 and Stage 2 support.
Business partnership
Can work with manufacturing plants, Facilities, HR/Privacy, Legal, Procurement, corporate functions, IT teams, stakeholders, consultants, operational control owners, and certification bodies while preserving internal accountability.
Advantageous
Experience with manufacturing or operational technology boundaries, ERP and plant systems, ITGC, ServiceNow CMDB, identity and access governance, supplier security, physical protection, mobileIT, privacy/PII integration, and existing qualitymanagement systems.
📌 ISO 27001 Implementation Consultant - Remote - Offshore (India)
🏢 Outcome Logix ( A Tech 50 Finalist company 2025 and 2022, by Pittsburgh Technology Council )
📍 India