All Jobs Vacancy

ISO 27001 Internal Auditor

Posted 2 days ago by Alexander Mann Solutions

Purpose of the role:

The role plans and delivers risk-based internal audits against ISO/IEC 27001 requirements, internal information security policies, client commitments, legal and regulatory obligations, and good-practice security controls. The postholder works collaboratively with stakeholders across Digital Services, business leadership, project teams, People, Legal, Procurement, Risk and Compliance to support continual improvement and strengthen security culture across Arup's global offices.

What you'll do:

  • Develop and maintain a risk-based ISO 27001 internal audit programme covering global offices, regional operations, shared services and project delivery environments.
  • Plan, scope and conduct internal audits of the ISMS, security governance processes, risk management activities and control operation.
  • Assess conformance with ISO/IEC 27001, internal policies, procedures, standards, contractual obligations and applicable regulatory expectations.
  • Perform audits remotely and where appropriate, onsite across multiple geographies, time zones and operating contexts.
  • Evaluate the effectiveness of controls relating to access management, asset management, supplier security, incident management.

The skills you'll need:

  • Practical experience planning and conducting ISO 27001 internal audits in a complex organisation.
  • Strong understanding of ISMS principles, security governance, control testing and risk management.
  • Ability to review evidence, analyse root causes and communicate findings in business-focused language.
  • Excellent report writing, interviewing, stakeholder management and facilitation skills.
  • Experience in professional services, engineering, consultancy or project-based environments.

About the client

Arup is an equal opportunity employer that actively promotes and nurtures a diverse and inclusive workforce. Guided by its values and alignment with the UN Sustainable Development Goals, Arup creates and contributes to equitable spaces and systems, while cultivating a sense of belonging for all. Arup's internal employee networks support their inclusive culture: from race, ethnicity and cross-cultural working to gender equity and LGBTQ+ and disability inclusion - creating a space for everyone to express themselves and make a positive difference.

Rate:
Not specified
Location:
London
IR35 Status:
Not specified
Remote Status:
Hybrid
Industry:
Cybersecurity
Seniority Level:
Not Specified

Take-Home Pay

Not Available

Visit calculators for additional details

Create a free account to view the take-home pay for this contract

Share job