Identify Security · 1 day ago
GRC Infosec Senior Analyst (ISO 27001)
Identify Security is a highly respected, client-facing professional services organization expanding its Governance, Risk & Compliance function. They are hiring a hands-on senior analyst to help run and mature an ISO-anchored security program, supporting client assurance, audits/certifications, and internal governance.
Cloud SecurityConsultingCyber SecurityNetwork Security
Responsibilities
Operate and improve the ISO 27001 ISMS (internal audits, management reviews, risk assessments, SOA updates; evidence readiness)
Lead client-requested security assessments and contract-driven security reviews (questionnaires, RFP/security responses, third-party assurance)
Support audit & recertification cycles (planning, scoping, evidence collection, control narratives, remediation tracking)
Run ongoing IAM authorization compliance oversight (RBAC/PIM, privileged/service/user accounts, recurring access certifications; restricted-access reviews as assigned)
Support post-implementation DLP compliance oversight and continuous improvement
Help define and maintain the annual security awareness/training program
Maintain clear, defensible documentation aligned to internal standards, client obligations, and applicable regulations
Qualification
Required
5–10 years in GRC / information security / audit / risk
Hands-on experience operating an ISMS aligned to ISO 27001 (2013 and/or 2022) (SOC 2 / NIST / GDPR helpful)
Real ownership of client questionnaires, vendor/service security reviews, and audit evidence packs
Comfortable in Windows + Microsoft 365/Azure + SaaS control environments
Strong written communication — crisp, defensible answers
Preferred
Experience in high-confidentiality, contract-driven environments
ISO 27001:2022 transition experience
Security metrics/dashboards for governance reporting