- Implementation, operation and maintenance of the Information Security Management System ISO 27001
- Performs information security risk assessments and assess the control environment of the business processes and applications under review,
- Assist in both internal and external audits relating to information security as well as performing independent audits to validate completeness and accuracy of the compliance program and other client audits.
- Recommend/ develop remediation and corrective action plans with related governance and operational functions (such as Physical Security/Facilities, Risk Management, IT, HR, Finance, Operations and Compliance)
- Author and revise policies, standards, procedures and guidelines, in conjunction with the Information Security Forum and with inputs from various stake holders.
- Development and operation of related compliance monitoring and improvement activities to ensure compliance both with internal security policies and applicable laws and regulations.
- Develop supporting information security awareness, training and Educational material for 27001.
- Hardening review of network and server devices.
- Follow up with respective stakeholder to close NCs
- Ability to coordinate with outside teams regarding policies, procedures or standards, and controls.