ISO 27001 Internal Security Auditor

Job ID: 40508574

Budget: ₹1,250 – ₹2,500 INR

I need a seasoned cybersecurity professional to carry out ISO/IEC 27001:2022-aligned internal audits for my clients. Each engagement is focused squarely on security risk assessment, so I am looking for someone who can dive deep into threats, vulnerabilities, and controls and translate their findings into clear, actionable guidance.

To be considered you must hold:
• CISSP, CISM or CRISC, and
• An IRCA, PECB, or Exemplar Global ISO/IEC 27001:2022 Lead Auditor credential.

A minimum of five years of ISMS auditing experience is essential. Prior work in Muslim-majority countries is strongly preferred, as many of my clients are based there.Travel is associated to this work.

You will work from client location for a short term coordinating with client teams via secure collaboration tools and delivering a concise, evidence-based audit report for each assignment. Your report must map findings to ISO 27001 clauses and annex controls, rate the associated risks, and recommend remediation steps that prepare the organisation for external certification. You will be also doing Threat modelling based on STRIDE and or MITRE ATT&CK framework.

Deliverables for every audit
• Audit plan defining scope, objectives, and sampling
• Completed checklist with objective evidence captured
• Comprehensive audit report ranking findings by likelihood and impact
• Executive-level summary slide deck

Acceptance criteria
• All reports must conform to ISO/IEC 27001:2022 guidance.
• Final documentation is due within five business days after fieldwork ends.

Please attach proof of certifications and a brief summary of three comparable audits you have led in the last five years, along with your typical turnaround time for the deliverables noted above. I look forward to working with the right expert.
Related categories: Compliance Risk Assessment