An ISMS - ISO Auditor is responsible for evaluating and ensuring that an organisation's Information Security Management System (ISMS) complies with the standards set by the International Organization for Standardization (ISO), particularly ISO/IEC 27001:2022. The auditor plays a critical role in identifying vulnerabilities, ensuring compliance, and recommending improvements to safeguard information assets. As a Sancert ISMS - ISO Auditor you will be responsible for carrying out accredited certification audits on clients at their sites as well as remotely from our Sancert offices.
Responsibilities
Audit Planning
- Develop comprehensive audit plans and schedules based on the client’s information security policies and ISO standards.
- Conduct pre-audit meetings to discuss and finalise the audit scope, objectives, and duration with relevant stakeholders.
Conducting Audits
- Perform thorough and objective audits of the clients ISMS to ensure compliance with ISO/IEC 27001:2022 and other related ISO standards such as ISO 27017 and ISO 27018, POPI and GDPR standards and guides.
- Review and evaluate the effectiveness of the ISMS policies, procedures, and practices.
- Identify and document gaps in compliance, vulnerabilities, and risks associated with information security.
- Assess the effectiveness of controls, including physical, technical, and administrative safeguards.
- Review and evaluate clients’ IT systems, including hardware, software, networks, and infrastructure.
- Analyse the security of IT systems, verifying that they align with cybersecurity best practices and security standards.
- Assess VPN systems, configurations, and controls, ensuring secure remote access to client systems and data.
- Identify vulnerabilities in client systems and security processes, providing actionable recommendations for improvement.
- Evaluate and review clients' incident management and troubleshooting processes to ensure efficient handling of security incidents and technical issues.
- Ensure compliance with cybersecurity controls for organisational, physical, and technological safeguards.
- Review clients’ IT operations and data protection policies, ensuring that security measures are effective and aligned with industry standards.
Reporting and Documentation
- Prepare detailed audit reports that clearly outline findings, observations, and recommended corrective actions.
- Present audit findings to senior management and relevant stakeholders, ensuring they understand the implications and necessary actions.
- Maintain thorough and accurate documentation of all audit activities and findings.
Follow-up and Continuous Improvement
- Monitor the implementation of clients’ corrective actions and improvements identified during the audit.
- Conduct follow-up audits to ensure that corrective actions have been effectively implemented and maintained.
- Collaborate with Sancert information security team to continuously improve the Sancert ISMS and address emerging threats and vulnerabilities.
Compliance and Training
- Stay current with updates to ISO standards, regulatory requirements, and industry best practices related to information security.
- Partake in training and guidance on ISO/IEC 27001 standards and information security practices so that you are always fully up to date with latest trends and risks.
- Assist in the development and implementation of ISMS policies and procedures for Sancert’s internal system.
Qualifications
Education and Certifications
- Bachelor’s degree in Information Security, Computer Science, or a related diploma or in the same field.
- Certified ISO/IEC 27001 Lead Auditor or similar certification is preferred but not necessary.
Experience
- At least four years’ experience in some of the above areas that you will be assessing, including IT support or a similar role, with a focus on cybersecurity and security controls.
Skills
- Knowledge of ISO/IEC 27001 standards and information security principles.
- Strong analytical and problem-solving skills.
- Attention to detail and the ability to work independently and as part of a team.
- Proficiency in using audit and information security management software and tools.
- Good communication skills and ability to explain and discuss complex IT concepts
- Adequate report writing skills in English.
- Own transport is needed due to the need of auditing from the office, as well as visiting clients occasionally for onsite auditing.
Personal Attributes
- Integrity and professionalism in handling sensitive information.
- Adaptability to evolving technological and regulatory environments.
- Strong organisational and time-management skills.
- Commitment to continuous learning and professional development.
Work Environment
The ISMS - ISO Auditor typically works in an office setting but may also need to travel to various sites to conduct audits. The role requires a high level of concentration and the ability to handle multiple tasks and deadlines.
Office location is in Somerset West, Cape Town.
This is a full-time position.
To apply, please email us at [email protected] with your CV, a brief cover letter, and the subject line: ISMS Auditor Application – [Your Name]
Pay: R30 000,00 - R50 000,00 per month
Experience:
- Lead Auditing: 2 years (Preferred)
License/Certification:
- Drivers License (Required)
Work Location: Hybrid remote in Somerset West, Western Cape 7130