Job Summary
The Contract Senior Associate, ISO role is a flexible, primarily remote position focused on executing hands-on information security audits, testing procedures, and client attestations within a professional services environment.
Key responsibilities include conducting detailed technical analysis, drafting project deliverables, and managing client relationships to ensure expectations are exceeded.
Candidates must possess a relevant bachelor's degree or equivalent experience, professional auditing or risk consulting experience, and an active ISO 27001:2022 Lead Auditor certification.
Additionally, candidates should hold or actively pursue industry credentials like CISA, CISSP, or CPA, alongside demonstrated experience auditing against the ISO 27001:2022 standard.
Responsibilities
- Testing and Analysis: Execute assigned testing procedures, perform detailed analysis, reach conclusions, and document results in accordance with company standards.
- Deliverables: Draft project deliverables and suggest ideas for improvements where applicable.
- Client Management: Establish high-quality relationships with client personnel, manage expectations to ensure they are exceeded, and serve as a contact for basic engagement questions.
- Communication: Use discretion and decorum in the timing, form, and content of all client communications.
- Team Collaboration: Collaborate with fellow project team members productively throughout the project life cycle.
- Project Tracking: Adhere to project schedules, keep fellow team members apprised of task progress, and escalate issues internally in a proper and timely manner.
- Meetings: Attend project kick-off and closing meetings.
- Compliance: Comply with Schellman's code of ethics, professional conduct, methodologies, policies, and procedures.
- Professional Standards: Adhere to professional and regulatory standards relevant to assigned service lines and continuously develop expert knowledge of these standards.
- Adaptability: Perform essential functions of other service delivery positions when qualified and called upon to do so.
Qualifications
Certifications & Memberships: Mandatory ISO Credential: Must maintain an active ISO lead auditor certification, with ISO 27001:2022 Lead Auditor as the minimum requirement.
Preferred ISO Certifications: Additional credentials such as ISO 42001:2023, ISO 27701:2025, or ISO 9001:2015 are preferred.
Professional Certifications: Must actively pursue or maintain at least one industry designation, such as CISA, CISSP, or CPA.
Professional Memberships: Preferred active membership in ISACA, ISC2, or AICPA.
Experience & Client-Facing Skills: Professional Services Experience: Relevant experience in information systems auditing, internal auditing, information security management, financial/operational auditing, or risk consulting.
Client Management: Strong client service orientation with a track record of building high-quality client relationships, managing client expectations, and communicating with decorum.
Standard Expertise: Practical experience auditing the specific requirements of the ISO 27001:2022 Standard.
Education & Technical Aptitude: Education: Bachelor's degree in technology, accounting, finance, business management, or a related field (or equivalent directly related experience).
Technical Knowledge: Requisite knowledge of applicable technology and security domains, along with proficiency in Microsoft Office (Word, Excel, PowerPoint) and audit applications.
Project Execution: Excellent time management skills to simultaneously manage tasks across multiple projects in a remote, collaborative team environment.
Skills
- flexible
- audit
- project execution