We are seeking a motivated IT professional to support the implementation of information security and privacy controls as part of the organization’s ISO/IEC 27001:2022 and ISO/IEC 27701:2025 certification initiative.
The role will work closely with the IT Infrastructure team and implementation consultants to execute technical and operational activities required for audit readiness. This is a hands-on implementation role and does not involve conducting audits or leading the overall ISMS/PIMS program.
Key Responsibilities
- Support implementation of technical and operational controls aligned with ISO/IEC 27001:2022 and ISO/IEC 27701:2025 requirements.
- Coordinate with the IT Infrastructure team to implement security controls across servers, endpoints, network devices, and enterprise applications.
- Assist in asset identification, inventory validation, asset labelling, ownership assignment, and classification.
- Support implementation of endpoint security controls including antivirus, endpoint protection, device encryption, screen lock policies, USB/media control, and secure configurations.
- Assist in implementation and verification of user access management controls, including user provisioning, privilege reviews, and account de-provisioning.
- Support vulnerability assessment and remediation activities by coordinating closure of identified gaps.
- Coordinate implementation of backup, restoration testing, and monitoring controls.
- Support vulnerability assessment and remediation activities by coordinating closure of identified observations.
- Assist in implementation of secure configuration baselines and hardening activities for systems and network devices.
- Support implementation of physical security requirements such as asset tagging, server room controls, visitor access controls, and media handling practices.
- Prepare and maintain implementation evidence required during ISO certification audits.
- Update asset registers, implementation trackers, configuration records, and supporting documentation.
- Coordinate with internal stakeholders for timely closure of implementation activities.
- Participate in internal readiness reviews and support closure of audit observations.
Required Skills
- Good understanding of IT Infrastructure including Windows/Linux systems, networking fundamentals, Active Directory, endpoint management, and IT asset management.
- Basic understanding of Information Security principles and cybersecurity best practices.
- Familiarity with ISO/IEC 27001:2022 controls are preferred.
- Exposure to implementation of security controls in enterprise IT environments.
- Ability to prepare implementation evidence and maintain documentation.
- Good coordination and communication skills.
- Ability to work independently while coordinating across multiple teams.
Preferred Qualifications
- Bachelor's degree in Computer Science, Information Technology, or related discipline.
- Exposure to ISO/IEC 27001 implementation projects.
- Knowledge of ISO/IEC 27701 privacy controls will be an added advantage.
- Relevant certifications such as ISO 27001 Foundation, CompTIA Security+, or equivalent are desirable but not mandatory.
Desired Candidate Profile
- Hands-on implementation mindset rather than audit or consulting experience.
- Detail-oriented with strong documentation capabilities.
- Ability to coordinate effectively with IT Infrastructure and business teams.
- Willingness to learn and execute implementation activities across information security and privacy domains.
- Self-driven with the ability to manage assigned implementation tasks within project timelines.