Connecting Odds
HCLTech

SME:ISO 27001:2005, ISMS

HCLTech
Banglore, Karnataka, IndiaPosted 28 days agoDiscoveredMatch locked
Full-time

Job Summary

This role provides expert oversight and management of information security management systems, ensuring compliance with ISO 27001:2005 and related frameworks. The position is pivotal in resolving escalated incidents, optimizing operational processes, and serving as a key technical liaison to business stakeholders to uphold organizational security standards and drive continuous improvement.

Key Responsibilities

Depth knowledge in doing Audit/Control Testing for SAP applications o Be part of an international IT GRC team including other control testers o Carry out tests of IT security controls against Henkel’s control framework which is closely aligned to ISO27000 o Review evidence provided via GRC tool to demonstrate control effectiveness and check for further evidence together with IT and business colleagues in documentation, applications o Support of IT and business colleagues in understanding security control objectives o Work with Henkel’s GRC Platform ServiceNow GRC/IRM

Skill Requirements

o Several years of experience in relevant positions o Seniority to come to decisions on effectiveness / ineffectiveness of IT controls independently, based on Henkel’s control framework and evidences provided as input to the control monitoring and testing. o Good background on IT Security Frameworks, esp. ISO 27000 and NIST o Good understanding of current cloud environments and its security challenges o Willingness to learn about Henkels security tool landscape and how it interacts with the applications which are tested o Strong communication skills to address both security experts and people with little to non security knowledge appropriately. o Very good English language skills, spoken and in writing o Having an IT Auditor background would help

Other Requirements

  1. ISO 27001 Lead Implementer or Lead Auditor certification (optional but highly valuable).
  1. CISSP, CISM, or CISA certifications (optional but valuable)

Not included in the source posting: about the role, benefits.

Skills

cisspsap

Who can apply

The employer didn't state any visa, work authorization, citizenship or clearance requirements in this posting. Confirm with the employer before applying.

Read automatically from the employer's posting text. Always confirm with the employer — requirements can change after a job is published.