Information Security Compliance Officer
Lalitpur, Nepal
TechKraft Inc.
TechKraft is a global IT services and consulting company, unlocking opportunities for clients worldwide to outsource operations in strategic regions of the world.
Techkraft Inc. Pvt. Ltd. is seeking a detail-oriented and experienced Information Security Compliance Officer (ISCO) with a strong background in compliance and risk management.The ideal candidate will have at least 3 years of hands-on experience in information security compliance, including a solid understanding of ISO 27001:2022. The role involves overseeing the organization’s ISMS, conducting risk assessments, recommending treatment plans, and collaborating across departments to ensure continued compliance and security posture improvement.
Key Responsibilities:
Key Responsibilities:
- Maintain and enhance the Information Security Management System (ISMS) in accordance with ISO 27001:2022 standards, driving continuous improvement through regular reviews and updates.
- Conduct regular risk assessments, document findings, and develop and implement risk treatment plans to mitigate identified risks.
- Lead internal ISMS audits, support external audits for certifications and client assessments, and ensure timely resolution of audit findings.
- Collaborate with department heads and senior management to ensure security controls and compliance measures are understood, implemented, and aligned with organizational objectives.
- Monitor and report on ISMS metrics and compliance status.
- Develop, update, and review information security policies, procedures, and documentation to ensure alignment with standards and regulations.
- Design and deliver comprehensive security awareness programs, including role specific training and phishing simulations, and measure their effectiveness to foster a security-aware culture.
- Oversee and coordinate responses to information security incidents, including root cause analysis, corrective actions, and compliance with regulatory and contractual reporting obligations.
- Stay informed of changes in information security and privacy regulations, standards, and emerging threats, and recommend updates to the ISMS to address them.
- Act as a point of contact for regulators, clients, and auditors regarding information security compliance, and present ISMS performance to senior management and the board.
- Bachelor's degree in information security, Computer Science, or a related field.
- Minimum 3 years of experience in information security compliance or ISMS-related roles.
- Strong understanding of ISO 27001:2022 requirements.
- ISO 27001 Lead Implementer or Lead Auditor certification is highly preferred.
- Experience in risk assessment, mitigation planning, and compliance reporting.
- Excellent communication and collaboration skills.
- Strong analytical and problem-solving abilities.
- Ability to work independently and manage multiple priorities.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
1
0
0
Category:
Compliance Jobs
Tags: Audits Compliance Computer Science ISMS ISO 27001 Privacy Risk assessment Risk management
Region:
Asia/Pacific
Country:
Nepal
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information System Security Officer jobsIT Security Analyst jobsSecurity Operations Engineer jobsSenior Cybersecurity Engineer jobsSenior Cloud Security Engineer jobsSenior Security Analyst jobsSenior Information Security Analyst jobsCyber Security Specialist jobsInformation Security Manager jobsSenior Product Security Engineer jobsSenior Network Security Engineer jobsSecurity Consultant jobsSenior Information Security Engineer jobsInformation System Security Officer (ISSO) jobsChief Information Security Officer jobsInformation Systems Security Engineer jobsSecurity Specialist jobsSenior Cyber Security Engineer jobsIT Security Engineer jobsCyber Threat Intelligence Analyst jobsSecurity Operations Analyst jobsSenior Software Engineer jobsSenior IT Auditor jobsCybersecurity Specialist jobsNetwork Engineer jobs
Bash jobsCEH jobsTS/SCI jobsEncryption jobsEDR jobsSDLC jobsSplunk jobsThreat detection jobsMalware jobsRMF jobsTerraform jobsFinance jobsIDS jobsSQL jobsTop Secret jobsCompTIA jobsForensics jobsITIL jobsIPS jobsSOC 2 jobsOWASP jobsActive Directory jobsDocker jobsClearance Required jobsGIAC jobs
CRISC jobsIntrusion detection jobsTCP/IP jobsOSCP jobsAnsible jobsHIPAA jobsVPN jobsMITRE ATT&CK jobsDoDD 8570 jobsZero Trust jobsData Analytics jobsJavaScript jobsSOAR jobsCCSP jobsSOX jobsBanking jobsIT infrastructure jobsJira jobsUNIX jobsDNS jobsIndustrial jobsNIST 800-53 jobsKPIs jobsCISO jobsMachine Learning jobs