ISO 27001 Compliance & Program Management
- Implement and maintain ISO 27001-compliant information security policies, procedures, and controls
- Conduct regular internal audits to ensure compliance with information security requirements
Risk Assessment & Management
- Perform security risk assessments, identify vulnerabilities, and develop mitigation strategies
- Maintain a risk register and support the implementation of risk treatment plans
- Regularly update risk assessments in response to changes in technology, personnel, or regulatory requirements
Security Incident Management
- Monitor, investigate, and respond to security incidents, ensuring minimal impact to the business
- Develop and document incident response plans and coordinate incident response activities
- Perform root cause analysis of incidents and make recommendations for improvements
Security Awareness & Training
- Develop and deliver security awareness training for employees to promote a culture of security
- Conduct regular phishing simulations and report on the effectiveness of training initiatives
Documentation & Reporting
- Maintain documentation for policies, procedures, and controls related to information security
- Prepare and present security metrics and reports for management and other stakeholders
- Support external audits, certification processes, and compliance assessments