Consultant - ISMS/GRC

Posted 2 Days Ago
Be an Early Applicant
3 Locations
In-Office
Mid level
Information Technology • Software
The Role
The Consultant will implement ISO 27001-based ISMS and IT GRC frameworks, perform assessments, develop policies, and ensure compliance with regulations.
Summary Generated by Built In

Job Summary: 

We are seeking a Consultant with proven experience in implementing and maintaining ISO 27001-based Information Security Management Systems (ISMS) and IT Governance, Risk, and Compliance (IT GRC) frameworks. The ideal candidate will have hands-on expertise in ISO 27001 gap assessments, risk assessments, policy development, and certification audit preparation, along with working knowledge of standards such as NIST, NCA, SAMA, COBIT, and ITIL. This role involves supporting compliance programs, developing security controls, conducting awareness training, and assisting clients in aligning IT strategies with regulatory requirements including GDPR, HIPAA, and PCI-DSS. Strong documentation, auditing, and communication skills are essential.

Job Description: 

ISMS Responsibilities: 

  • Experience of implementation and maintenance of ISO 27001-based Information Security Management Systems (ISMS). 
  • Perform gap assessments to identify areas of non-compliance and assist in remediation planning against various standards & frameworks like, NIST, NCA, SAMA etc. 
  • Participate in risk assessments and help develop mitigation strategies. 
  • Developing ISMS policies, procedures, and security controls aligned with ISO 27001 standards. 
  • Prepare documentation and provide support during ISO 27001 certification audits. 
  • Conduct security awareness training and incident management processes. 

IT GRC Responsibilities: 

  • Assist in developing and implementing IT governance frameworks (COBIT, NIST, ITIL). 
  • Support IT risk assessments, compliance audits, and regulatory reporting activities. 
  • Help clients align IT strategies with their business goals while ensuring compliance with regulations like COBIT, GDPR, HIPAA, SOX, etc. 
  • Support in developing and maintaining IT compliance programs and policies. 
  • Contribute to the development and implementation of GRC tools and processes. 
  • Participate in internal audits and help clients prepare for external certification audits/compliance checks. 

Required Qualifications & Experience: 

  • Minimum Bachelor’s degree in Information Security, Computer Science, or a related field. 
  • Certifications (preferred): ISO 27001 Lead Implementer / Lead Auditor, CISM, CRISC, or COBIT Foundation. 
  • Experience: 3–4 years of experience in ISMS and IT GRC consulting, auditing, or implementation. 
  • Familiarity with ISO 27001 gap assessments, risk assessments, and audits. 
  • Basic knowledge of IT governance frameworks (COBIT, NIST, ITIL, etc.). 
  • Understanding of regulatory compliance such as GDPR, NIST, and PCI-DSS. 
  • Strong documentation, report writing, and communication skills is a must. 

Requirements
  • Master’s or Bachelor’s degree in Information Technology, Computer Science, or IT-related field.
  • ITIL Expert/Managing Professional, ISO 20000 Lead Implementer / Lead Auditor, ISO 22301 Lead Implementer / Lead Auditor, CBCP (Certified Business Continuity Professional).
  • 6-8 years of experience in ITSM and BCMS consulting or related roles.
  • In-depth knowledge of ITIL, ISO 22301, and other relevant frameworks/regulations.
  • Practical experience in ISO 22301 implementation, BIA, DR planning, and BCMS assessments.
  • Familiarity with IT compliance standards such as ISO 27001, COBIT, and NIST, NCA.
  • Excellent analytical, problem-solving, and decision-making skills.
  • Proven ability to manage multiple projects and clients simultaneously.
  • Experience in conducting internal and external audits related to ITSM and BCMS.
  • Strong stakeholder engagement, report writing, and project management skills.

Top Skills

Cobit
Gdpr
Hipaa
Iso 27001
Itil
Nist
Pci-Dss
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
839 Employees
Year Founded: 2001

What We Do

Inbox Business Technologies is the premier provider of digital services to businesses in Pakistan whose mission is “Providing Agility for the Digital Age”.

Disruptive technologies are forcing businesses to adapt or die. Business strategy has to be redesigned for this consistently uncertain digital age and business models need to be agile enough to execute the equivalent of hitting moving targets. Inbox Business Technologies gives businesses that agility with its digital services portfolio.

Visit www.inboxbiz.com to get latest thinking on how technology enables business agility in this age of disruption.

Similar Jobs

Motive Logo Motive

SQA Engineer

Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Easy Apply
In-Office
2 Locations
4000 Employees

Motive Logo Motive

Account Manager

Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Easy Apply
In-Office or Remote
2 Locations
4000 Employees

Motive Logo Motive

Account Manager

Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Easy Apply
In-Office or Remote
2 Locations
4000 Employees

Motive Logo Motive

Software Engineer

Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Easy Apply
In-Office
2 Locations
4000 Employees

Similar Companies Hiring

Standard Template Labs Thumbnail
Software • Information Technology • Artificial Intelligence
New York, NY
10 Employees
PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees
Scotch Thumbnail
Software • Retail • Payments • Fintech • eCommerce • Artificial Intelligence • Analytics
US
25 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account