Information Security & GRC Officer
Core
Drive the Information Security Management System (ISMS), maintain ISO 27001 certification, and align security policies with hybrid cloud environments.
Role type
Mid-level Information Security & GRC Officer
Builds
Security policies, procedures, asset registers, Statement of Applicability (SoA), and risk registers
Domain
Information Security, Governance, Risk & Compliance (GRC), IT Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
ISO 27001 ISMS management, Secure SDLC governance, NIS2 compliance, hybrid infrastructure governance (Azure, VMware), risk assessment, audit management, vendor security vetting
Preferred skills
ISO 27001 Lead Implementer/Auditor certification, CompTIA Security+, CISA, CRISC
Technologies
Microsoft Azure, VMware, CI/CD pipelines
Responsibilities
Manage and improve the company's ISMS including policies and asset registers; Govern security controls throughout the software development lifecycle; Assess and align security posture to meet NIS2 directive obligations; Ensure compliance controls across Azure Cloud and On-Premises VMware private cloud; Execute risk assessments and maintain the corporate risk register; Organize internal audits and facilitate external ISO 27001 certification audits; Respond to client security questionnaires and vet third-party vendors
Seniority
Mid-level, hands-on IC