Developing, maintaining, enforcing Information security standards and procedures in line with ISO 27001 standards, COBIT, ITIL, PCI-DSS, and other similar standards.
Conduct operational and process reviews in compliance with ISO 27001 standards or others such as COBIT, NIST, ISO 20000, ISO 22301.
Develop Information security policies and procedures.
Help clients in achieving ISO 27001, ISO 22301, ISO 20000 certifications.
Experience in managing audit & compliance projects with security standards implementation such as ISO 27001/ISO 20000/ISO 22301, internal and external audit finding remediation.
Evaluating, reviewing, recommending, and setting baselines within the assigned area of focus.
Assist in maintaining frameworks for security risk management and business continuity.
Good experience in writing non-compliance reports, documentation skills, and presentation skills.
Providing expert security involvement in the lifecycle of business and infrastructure projects including architecture reviews, application design, disaster recovery, and vulnerability scanning.
Act as a subject matter expert in security policies and procedures, network assessments, security health checks, incident response, application security, security compliance assessments, and business partner assessments and management strategies.
Work closely with Senior Information Security Professionals, clients, and offer management oversight for other consultants.
Manage all aspects of an engagement lifecycle, including requirements definition, data collection, report writing, client status reporting, and final presentation of engagement deliverables.
Requirements
A bachelor's degree or a PG in Information Systems/Computer Science or relevant field.
Previous experience as an Information Security Specialist, Information Security Consultant, or ISO Security standards implementation specialist.
Proven track record of providing security consulting services such as vulnerability assessments, risk assessments, information systems security audits, and ISO 27001/20000/22301 consultancy.
Familiarity with various operating systems, databases, and applications.
Good knowledge of PCI-DSS, ISO 27001/20000/22301 standards, and Information Security Framework.
Information Security/Assurance certification such as CISSP/CISA/CISM/GIAC/CRISC/CBCP are a definite advantage.
Excellent oral and written communication skills with the ability to interact with all levels in the organization.
At least 3 to 5 years of relevant experience in consultancy.
Good experience in report writing and documentation skills.
Ability to multitask many issues at once and ensure that projects are completed on time and with the agreed quality.
Strong client relationship building/interpersonal skills and communication skills.