ISO 9001:2015 (QMS) Consultant — SaaS Readiness | Remote | Milestone-based

Job ID: 39736256

Budget: $750 – $1,500 USD

Context

We’re a new, global SaaS in identity/signature/2FA. The company and product are starting from scratch, but we already have a solid technical baseline (AWS/EKS/Terraform/GitHub) and several freelancers engaged (infra, security, compliance). We want to implement a practical ISO 9001:2015 Quality Management System (QMS) integrated with our ISMS (ISO 27001/27701) and our document coding scheme (TYPE-AREA-SUBAREA-№SEC; revisions REV A/B/0/1…).

Objective
Prepare the organization for ISO 9001:2015 certification (Stage 1/Stage 2), with real, operating processes and objective evidence—without redesigning infrastructure; the work is process/documentation integration over what’s already built.

Scope & milestones (with acceptance criteria)
1. QMS framework and Process Map
– Context, interested parties, quality policy/objectives.
– End-to-end process map (strategic/operational/support) with inputs/outputs/roles/KPIs.
– Master document index.
Acceptance: approved process map; measurable quality objectives in place.
2. Document Control and Templates
– Document control procedure (cl. 7.5) using our coding scheme and approval workflow.
– Templates for SOPs, Work Instructions, Records, Minutes, Forms.
– Implementation in Airtable (or Jira↔Airtable) + Git/S3 (versioning and traceability).
Acceptance: every document has code, status, owner, revision; approval flow working.
3. Core SaaS Operating Processes
– Design & Development (8.3) linked to CI/CD (DoR/DoD, testing, releases).
– Service Provision (8.5), Change Management (8.5.6), Supplier Management (8.4).
– Customer care/complaints (8.2.1) and Non-conformities & CAPA (10.2).
Acceptance: processes published and in use; records/evidence in S3/Git with commit SHA.
4. Competence and Training
– Procedure (7.2), competency matrix, annual plan and records.
Acceptance: live matrix; plan and training records filed.
5. Measurement, Internal Audit and Management Review
– KPIs per process (e.g., defect rate, lead time, uptime, MTTR, NPS).
– Internal audit program (9.2), checklists and report with PoA&M.
– Management Review (9.3): agenda, inputs, minutes and decisions.
Acceptance: KPIs tracked on a live board; internal audit executed; Management Review minutes issued; critical findings closed.
6. Certification Readiness Pack
– ISO 9001 ↔ UC-XXX traceability matrix (bridging QMS with ISMS/DevOps).
– Evidence list with S3/Git paths, owner, date, commit SHA.
– Pre-cert guidance and support for Stage 1.
Acceptance: complete pack validated with our team.

General acceptance criteria
– Objective, traceable evidence (UC-XXX → S3/Git URL + owner + date + commit SHA).
– Documents coded TYPE-AREA-SUBAREA-№SEC with version control.
– Live Airtable board (processes, controls, evidence, risks, decisions).

Requirements (must-have)
– Verifiable credentials as ISO 9001:2015 Lead Auditor and/or Lead Implementer.
– Demonstrated QMS implementations in SaaS/DevOps environments.
– Ability to integrate QMS with ISMS (ISO 27001/27701) and CI/CD pipelines (GitHub Actions).
– Fluency with Airtable/Jira/Confluence, Git/S3; excellent communication.
– Professional English (Spanish is a plus). NDA required.

Preferred
– Familiarity with ISO 27001/27701, SOC 2, ENS (Spain).
– BPMN process modeling.
– ISO 19011 auditing experience.
– Experience working with Certification Bodies (CBs) or accredited auditors and handling online/remote certification audits for global companies.

Out of scope
– Redesigning infrastructure or building product features.
– Structural changes without prior approval from PM and Security/Infra.
– Substantive legal advice (we have Legal/DPO).

Tools & ways of working
– Airtable (controls/evidence register), Jira/Confluence, GitHub, S3, Slack.
– Remote, milestone-based, coordination with our PM (20h/week) and other certification specialists.
– Weekly cadence; preferred time zone CET/CEST (Europe/Madrid).

Additional note
We aim to complete online/remote ISO 9001 certification where feasible. We’re a global-reach company from day one, so prior experience coordinating with Certification Bodies for remote audits is highly valued.