The Role
Owns day-to-day ISO 27001 ISMS governance, risk assessments, audit coordination, policy documentation, incident and vulnerability management, security awareness programs, reporting, and continuous improvement. The role monitors Wazuh alerts, coordinates remediation and audits, supports vendor risk reviews and onboarding/offboarding, and collaborates with IT, Engineering, HR, and other departments on security and compliance initiatives.
Summary Generated by Built In
JOB SUMMARY
KEY RESPONSIBILITIES
ISMS Governance & Compliance
Preferred Qualifications
The Information Security Associate will take ownership of day-to-day operation, maintenance, and continual
improvement of the organization's Information Security Management System (ISMS) in accordance with ISO/IEC
27001:2022. Building on hands-on experience gained during the ISO 27001 certification/renewal cycle, this role
independently drives governance, risk management, and compliance (GRC) activities, coordinates internal and
external audits, manages vulnerability and incident processes, and leads security awareness initiatives, while acting
as a key point of contact for cross-functional security and compliance matters.
ISMS Governance & Compliance
- Own the day-to-day operation, documentation, and continual improvement of the ISMS in line with ISO/IEC 27001:2022.
- Assist the maintenance and periodic review of the Statement of Applicability (SoA), risk register, asset inventory, and
related ISMS records.
- Independently conduct information security risk assessments and drive risk treatment planning through to closure.
- Serve as a primary coordinator for surveillance audits, recertification audits, and internal audits, including audit planning,
evidence collection, and liaison with auditors.
- Track non-conformities and corrective actions to resolution, and report compliance status to the Information Security
Officer.
- Own the drafting, review, and version control of information security policies, procedures, standards, and guidelines.
- Ensure documentation stays aligned with ISO/IEC 27001:2022, applicable regulatory requirements, and industry best
practices.
- Support policy rollout and acknowledgement tracking across departments.
- Manage the security incident register end-to-end: logging, triage, investigation support, and closure documentation.
- Assist vulnerability management activities, including scan coordination, tracking, prioritization, and follow-up with
system/application owners through remediation.
- Monitor Wazuh security alerts and endpoint events, and escalate relevant findings to the Information Security Officer and
IT/Infrastructure team for investigation and remediation.
- Contribute to Vulnerability Assessment and Penetration Testing (VAPT) planning, scoping, and remediation verification.
- Escalate high-risk findings and incidents to the Information Security Officer in a timely manner.
- Plan and run information security awareness programs, training sessions, and phishing simulation campaigns.
- Analyze awareness and phishing simulation results and recommend targeted improvements.
- Prepare and present security metrics, compliance dashboards, and management reports to leadership.
- Prepare weekly/monthly departmental information security reports covering security alerts, incidents, vulnerabilities,
compliance activities, and security awareness metrics.
- Research emerging cybersecurity threats, regulatory changes, and security frameworks, and recommend improvements
to the ISMS.
- Identify opportunities to streamline GRC processes and documentation workflows.
- Act as a key liaison with IT, Engineering, HR, and other departments on security and compliance initiatives.
- Support onboarding/offboarding, vendor risk reviews, and third-party due diligence from a security perspective.
- Mentor and guide future information security interns.
- Perform other information security-related tasks as assigned by the Information Security Officer.
Preferred Qualifications
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field.
- Demonstrated hands-on experience supporting an ISO/IEC 27001:2022 ISMS (e.g., through an internship, certification
cycle, or equivalent project experience).
- Solid understanding of information security principles, cybersecurity concepts, and risk management methodologies.
- Working knowledge of ISO/IEC 27001, NIST Cybersecurity Framework, CIS Controls, or similar standards.
- A relevant certification (e.g., ISO 27001 Internal Auditor/Lead Implementer, Security+, or similar) is an advantage.
- Strong written and verbal communication, documentation, organizational, and audit-coordination skills.
- Strong analytical thinking, problem-solving, and risk-assessment abilities with high attention to detail.
- Proficiency in Microsoft Office, Jira/Confluence, and familiarity with GRC platforms or SIEM tools (such as Wazuh).
- Ability to work independently, take ownership of deliverables, and collaborate across teams.
Skills Required
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field
- Hands-on experience supporting an ISO/IEC 27001:2022 ISMS through an internship, certification cycle, or equivalent project experience
- Understanding of information security principles, cybersecurity concepts, and risk management methodologies
- Working knowledge of ISO/IEC 27001, NIST Cybersecurity Framework, CIS Controls, or similar standards
- Relevant certification such as ISO 27001 Internal Auditor, ISO 27001 Lead Implementer, Security+, or similar
- Strong written and verbal communication, documentation, organizational, and audit-coordination skills
- Analytical thinking, problem-solving, and risk-assessment abilities with high attention to detail
- Proficiency in Microsoft Office, Jira, and Confluence
- Familiarity with GRC platforms or SIEM tools such as Wazuh
- Ability to work independently, take ownership of deliverables, and collaborate across teams
Similar Jobs
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
TechKraft Inc. is a global IT engineering services and consulting company that helps organizations turn data, security, and artificial intelligence into production-ready business capabilities. Its offerings include AI and machine-learning solutions, data engineering, technology operations, quality assurance, business analysis, cybersecurity, cloud infrastructure, product engineering, staff augmentation, and managed delivery. The company operates an offshore development center in Nepal and serves clients internationally.







