Information Security Associate

Sorry, this job was removed at 02:46 p.m. (UTC) on Tuesday, Oct 06, 2026
Be an Early Applicant
Kathmandu, Bagmati, NPL
In-Office
Entry level
Artificial Intelligence • Information Technology • Consulting • Cybersecurity
The Role
Owns day-to-day ISO 27001 ISMS governance, risk assessments, audit coordination, policy documentation, incident and vulnerability management, security awareness programs, reporting, and continuous improvement. The role monitors Wazuh alerts, coordinates remediation and audits, supports vendor risk reviews and onboarding/offboarding, and collaborates with IT, Engineering, HR, and other departments on security and compliance initiatives.
Summary Generated by Built In
JOB SUMMARY
The Information Security Associate will take ownership of day-to-day operation, maintenance, and continual improvement of the organization's Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2022. Building on hands-on experience gained during the ISO 27001 certification/renewal cycle, this role independently drives governance, risk management, and compliance (GRC) activities, coordinates internal and external audits, manages vulnerability and incident processes, and leads security awareness initiatives, while acting as a key point of contact for cross-functional security and compliance matters.

KEY RESPONSIBILITIES
ISMS Governance & Compliance
  • Own the day-to-day operation, documentation, and continual improvement of the ISMS in line with ISO/IEC 27001:2022.
  • Assist the maintenance and periodic review of the Statement of Applicability (SoA), risk register, asset inventory, and related ISMS records.
  • Independently conduct information security risk assessments and drive risk treatment planning through to closure.
  • Serve as a primary coordinator for surveillance audits, recertification audits, and internal audits, including audit planning, evidence collection, and liaison with auditors.
  • Track non-conformities and corrective actions to resolution, and report compliance status to the Information Security Officer.
Policy & Documentation
  • Own the drafting, review, and version control of information security policies, procedures, standards, and guidelines.
  • Ensure documentation stays aligned with ISO/IEC 27001:2022, applicable regulatory requirements, and industry best practices.
  • Support policy rollout and acknowledgement tracking across departments.
Incident & Vulnerability Management
  • Manage the security incident register end-to-end: logging, triage, investigation support, and closure documentation.
  • Assist vulnerability management activities, including scan coordination, tracking, prioritization, and follow-up with system/application owners through remediation.
  • Monitor Wazuh security alerts and endpoint events, and escalate relevant findings to the Information Security Officer and IT/Infrastructure team for investigation and remediation.
  • Contribute to Vulnerability Assessment and Penetration Testing (VAPT) planning, scoping, and remediation verification.
  • Escalate high-risk findings and incidents to the Information Security Officer in a timely manner.
Security Awareness & Training
  • Plan and run information security awareness programs, training sessions, and phishing simulation campaigns.
  • Analyze awareness and phishing simulation results and recommend targeted improvements.
Reporting & Continuous Improvement
  • Prepare and present security metrics, compliance dashboards, and management reports to leadership.
  • Prepare weekly/monthly departmental information security reports covering security alerts, incidents, vulnerabilities, compliance activities, and security awareness metrics.
  • Research emerging cybersecurity threats, regulatory changes, and security frameworks, and recommend improvements to the ISMS.
  • Identify opportunities to streamline GRC processes and documentation workflows.
Cross-Functional Collaboration
  • Act as a key liaison with IT, Engineering, HR, and other departments on security and compliance initiatives.
  • Support onboarding/offboarding, vendor risk reviews, and third-party due diligence from a security perspective.
  • Mentor and guide future information security interns.
  • Perform other information security-related tasks as assigned by the Information Security Officer.
QUALIFICATIONS AND SKILLS
Preferred Qualifications
  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field.
  • Demonstrated hands-on experience supporting an ISO/IEC 27001:2022 ISMS (e.g., through an internship, certification cycle, or equivalent project experience).
  • Solid understanding of information security principles, cybersecurity concepts, and risk management methodologies.
  • Working knowledge of ISO/IEC 27001, NIST Cybersecurity Framework, CIS Controls, or similar standards.
  • A relevant certification (e.g., ISO 27001 Internal Auditor/Lead Implementer, Security+, or similar) is an advantage.
Key Skills
  • Strong written and verbal communication, documentation, organizational, and audit-coordination skills.
  • Strong analytical thinking, problem-solving, and risk-assessment abilities with high attention to detail.
  • Proficiency in Microsoft Office, Jira/Confluence, and familiarity with GRC platforms or SIEM tools (such as Wazuh).
  • Ability to work independently, take ownership of deliverables, and collaborate across teams.

Skills Required

  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field
  • Hands-on experience supporting an ISO/IEC 27001:2022 ISMS through an internship, certification cycle, or equivalent project experience
  • Understanding of information security principles, cybersecurity concepts, and risk management methodologies
  • Working knowledge of ISO/IEC 27001, NIST Cybersecurity Framework, CIS Controls, or similar standards
  • Relevant certification such as ISO 27001 Internal Auditor, ISO 27001 Lead Implementer, Security+, or similar
  • Strong written and verbal communication, documentation, organizational, and audit-coordination skills
  • Analytical thinking, problem-solving, and risk-assessment abilities with high attention to detail
  • Proficiency in Microsoft Office, Jira, and Confluence
  • Familiarity with GRC platforms or SIEM tools such as Wazuh
  • Ability to work independently, take ownership of deliverables, and collaborate across teams

Similar Jobs

Techkraft Inc Pvt Ltd Logo Techkraft Inc Pvt Ltd

Senior Front-end Engineer

Artificial Intelligence • Information Technology • Consulting • Cybersecurity
In-Office
Kathmandu, Bagmati, NPL
85 Employees
In-Office
Kathmandu, Bagmati, NPL
61500 Employees

SAGEA Logo SAGEA

Quality Assurance Engineer

Artificial Intelligence • Software
In-Office or Remote
2 Locations
9 Employees

SAGEA Logo SAGEA

Scientist

Artificial Intelligence • Software
In-Office or Remote
3 Locations
9 Employees
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Lalitpur
85 Employees
Year Founded: 2020

What We Do

TechKraft Inc. is a global IT engineering services and consulting company that helps organizations turn data, security, and artificial intelligence into production-ready business capabilities. Its offerings include AI and machine-learning solutions, data engineering, technology operations, quality assurance, business analysis, cybersecurity, cloud infrastructure, product engineering, staff augmentation, and managed delivery. The company operates an offshore development center in Nepal and serves clients internationally.

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account