ISO/IEC 27001:2022 (ISMS) Consultant — SaaS Readiness | Remote | Milestone-based
Budget: $750 – $1,500 USD
Context
We’re a global SaaS in identity/signature/2FA. The company and product are starting from scratch, yet we already have a solid technical baseline (AWS/EKS/Terraform/GitHub) and several freelancers engaged (infra, security, compliance). We want to implement a practical, audit-ready ISMS integrated with our DevOps, with a preference for online/remote certification. Experience working with Certification Bodies (CBs) and remote audits is highly valued.
Objective
Make us ready for ISO/IEC 27001:2022 certification (Stage 1/Stage 2) with live processes and objective evidence. No infrastructure redesign: your work is to integrate controls/evidence over what’s already built. Include mappings to ISO 27017/27018 and alignment with ISO 27701 where appropriate.
Scope & milestones (with acceptance criteria)
H1) GAP, Scope, Context, RACI and ISMS Plan
– Deliverables: GAP report; ISMS scope; context/stakeholders; RACI; master ISMS plan.
– Acceptance: approved scope and plan; prioritized backlog.
H2) Risk Management + SoA (Annex A:2022, 93 controls)
– Deliverables: risk methodology and risk register; Statement of Applicability (SoA).
– Acceptance: prioritized risks with treatment plan; SoA published.
H3) Core Policies & Procedures (bundled by A.5/A.6/A.7/A.8)
– Deliverables: policies/SOPs for incident management, change management (linked to CI/CD), IAM, information classification/handling, asset management, suppliers/third parties, logging/retention (CloudTrail/GuardDuty), backup/restore, vulnerability/patching, cryptography (KMS/HSM), secure development.
– Acceptance: documents approved, coded, and in use.
H4) Runbooks and Airtable Evidence Board
– Deliverables: operational runbooks; master register in Airtable with UC-XXX → S3/Git URL + owner + date + commit SHA; auditor views.
– Acceptance: live, traceable board; evidence uploaded.
H5) Initial ISMS Operation
– Deliverables: awareness/training plan; KPIs/KRIs; first operation records (incidents, changes, access reviews, backups, etc.).
– Acceptance: KPIs tracked; regular evidence captured.
H6) Internal Audit + NC/CAPA + Management Review
– Deliverables: internal audit program and report; corrective actions plan; Management Review minutes.
– Acceptance: critical findings closed; Management Review issued.
H7) Readiness Pack & Stage 1 Support
– Deliverables: ISO 27001 ↔ UC-XXX traceability matrix; evidence list with S3/Git paths; pre-cert guidance and remote audit support.
– Acceptance: pack validated with our team.
General acceptance criteria
– Every control maps to objective evidence (UC-XXX → S3/Git URL + owner + date + commit SHA).
– Documents coded TYPE-AREA-SUBAREA-№SEC, with status and revision (REV A/B/0/1…).
– No destructive changes or infra redesign without RFC/ADR and approval.
– Weekly status (RAG), risks and dependencies tracked.
Requirements (must-have)
– ISO/IEC 27001:2022 Lead Implementer and/or Lead Auditor (verifiable).
– Proven ISMS implementations in SaaS/DevOps, integrating with CI/CD (GitHub Actions).
– Practical knowledge of AWS/EKS/Terraform, KMS/HSM, and technical evidence (logs, backups, changes).
– Experience coordinating with Certification Bodies and remote/online audits.
– Professional English (Spanish is a plus). NDA required.
Nice to have
– ISO 27701, ISO 27017/27018, SOC 2, ENS (Spain), ISO 22301, ISO 9001.
– Integrated matrices (security/privacy/quality).
– CloudHSM/FIPS 140-3 experience.
Out of scope
– Redesigning infrastructure or developing product features.
– Structural changes without PM and Security/Infra approval.
– Substantive legal advice (we have Legal/DPO).
Tools & ways of working
– Airtable (controls/evidence register), Jira/Confluence, GitHub, S3, Slack.
– Remote, milestone-based, coordination with our PM (20h/week) and other specialists.
– Weekly cadence; preferred time zone CET/CEST (Europe/Madrid).
– We aim to complete ISO 27001 certification online/remotely where feasible.
Note
We’re a new company with a significant part of the core infrastructure already built and multiple freelancers in motion. The pace is high and the environment dynamic; we need someone ready to lead from day one with maximum traceability and minimal overhead.
We’re a global SaaS in identity/signature/2FA. The company and product are starting from scratch, yet we already have a solid technical baseline (AWS/EKS/Terraform/GitHub) and several freelancers engaged (infra, security, compliance). We want to implement a practical, audit-ready ISMS integrated with our DevOps, with a preference for online/remote certification. Experience working with Certification Bodies (CBs) and remote audits is highly valued.
Objective
Make us ready for ISO/IEC 27001:2022 certification (Stage 1/Stage 2) with live processes and objective evidence. No infrastructure redesign: your work is to integrate controls/evidence over what’s already built. Include mappings to ISO 27017/27018 and alignment with ISO 27701 where appropriate.
Scope & milestones (with acceptance criteria)
H1) GAP, Scope, Context, RACI and ISMS Plan
– Deliverables: GAP report; ISMS scope; context/stakeholders; RACI; master ISMS plan.
– Acceptance: approved scope and plan; prioritized backlog.
H2) Risk Management + SoA (Annex A:2022, 93 controls)
– Deliverables: risk methodology and risk register; Statement of Applicability (SoA).
– Acceptance: prioritized risks with treatment plan; SoA published.
H3) Core Policies & Procedures (bundled by A.5/A.6/A.7/A.8)
– Deliverables: policies/SOPs for incident management, change management (linked to CI/CD), IAM, information classification/handling, asset management, suppliers/third parties, logging/retention (CloudTrail/GuardDuty), backup/restore, vulnerability/patching, cryptography (KMS/HSM), secure development.
– Acceptance: documents approved, coded, and in use.
H4) Runbooks and Airtable Evidence Board
– Deliverables: operational runbooks; master register in Airtable with UC-XXX → S3/Git URL + owner + date + commit SHA; auditor views.
– Acceptance: live, traceable board; evidence uploaded.
H5) Initial ISMS Operation
– Deliverables: awareness/training plan; KPIs/KRIs; first operation records (incidents, changes, access reviews, backups, etc.).
– Acceptance: KPIs tracked; regular evidence captured.
H6) Internal Audit + NC/CAPA + Management Review
– Deliverables: internal audit program and report; corrective actions plan; Management Review minutes.
– Acceptance: critical findings closed; Management Review issued.
H7) Readiness Pack & Stage 1 Support
– Deliverables: ISO 27001 ↔ UC-XXX traceability matrix; evidence list with S3/Git paths; pre-cert guidance and remote audit support.
– Acceptance: pack validated with our team.
General acceptance criteria
– Every control maps to objective evidence (UC-XXX → S3/Git URL + owner + date + commit SHA).
– Documents coded TYPE-AREA-SUBAREA-№SEC, with status and revision (REV A/B/0/1…).
– No destructive changes or infra redesign without RFC/ADR and approval.
– Weekly status (RAG), risks and dependencies tracked.
Requirements (must-have)
– ISO/IEC 27001:2022 Lead Implementer and/or Lead Auditor (verifiable).
– Proven ISMS implementations in SaaS/DevOps, integrating with CI/CD (GitHub Actions).
– Practical knowledge of AWS/EKS/Terraform, KMS/HSM, and technical evidence (logs, backups, changes).
– Experience coordinating with Certification Bodies and remote/online audits.
– Professional English (Spanish is a plus). NDA required.
Nice to have
– ISO 27701, ISO 27017/27018, SOC 2, ENS (Spain), ISO 22301, ISO 9001.
– Integrated matrices (security/privacy/quality).
– CloudHSM/FIPS 140-3 experience.
Out of scope
– Redesigning infrastructure or developing product features.
– Structural changes without PM and Security/Infra approval.
– Substantive legal advice (we have Legal/DPO).
Tools & ways of working
– Airtable (controls/evidence register), Jira/Confluence, GitHub, S3, Slack.
– Remote, milestone-based, coordination with our PM (20h/week) and other specialists.
– Weekly cadence; preferred time zone CET/CEST (Europe/Madrid).
– We aim to complete ISO 27001 certification online/remotely where feasible.
Note
We’re a new company with a significant part of the core infrastructure already built and multiple freelancers in motion. The pace is high and the environment dynamic; we need someone ready to lead from day one with maximum traceability and minimal overhead.