FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in leading ISO 27001 certification and compliance activities, with a strong focus on risk assessment, audit readiness, and information security governance. Proficient in applying security frameworks such as SOC 2, NIST, and HIPAA to ensure effective risk management and control implementation.
Highest-signal resume keywords
ISO 27001 CertificationRisk AssessmentSOC 2 ComplianceNIST CSFInformation Security Governance
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Information Security Risk ManagementAudit ReadinessControl TestingCorrective Action PlansVulnerability ManagementSecurity Policies DevelopmentControl Design EvaluationIncident ResponsePenetration TestingTechnology Risk Evaluation
Soft Skills
Strong Communication SkillsPresentation SkillsOrganizational SkillsTime ManagementCollaboration
Tools & Technologies
ServiceNowJiraGRC ToolsIT InfrastructureTicketing Systems
Industry Keywords
ISO 27001SOC 2NIST 800-53HIPAACISCOBITITILFedRAMPCybersecurityCompliance
Tech Stack
Tools & technologiesCyber SecurityServiceNow
About the role
Key responsibilities & impact- Lead Empyrean’s ISO 27001 certification, surveillance, internal audit readiness, and ongoing ISMS compliance activities
- Coordinate ISO 27001 control testing and communications with control owners, business partners, and audit stakeholders
- Support assessments and assurance activities involving SOC 2, NIST AI RMF, NIST CSF, NIST 800-53, HIPAA, and other frameworks
- Identify, assess, document, monitor, and communicate information security risks and control gaps
- Develop, implement, track, and validate corrective action and risk-remediation plans
- Manage audit and assessment activities for information security, cybersecurity, business applications, and technology controls
- Lead or coordinate risk assessments for technology initiatives, environmental changes, third parties, emerging technologies, exceptions, and risk events
- Facilitate security risk and governance meetings, including preparation, documentation, and follow-up
- Maintain the enterprise information security risk register and related risk, issue, exception, and remediation documentation
- Provide technical expertise and apply security and compliance practices to identify control weaknesses and address policy exceptions
- Lead security and technology responses for client questionnaires, RFPs, due-diligence requests, and internal inquiries
- Evaluate enterprise cybersecurity threat and vulnerability monitoring and management effectiveness
- Develop and maintain information security policies, standards, and governance documentation
- Provide security risk and IT controls expertise on technology initiatives and evaluate control design and implementation
- Interpret audit findings, make practical recommendations, and verify remediation implementation
- Support broader information security initiatives, incidents, escalations, roadmaps, and strategic projects
Requirements
What you’ll need- Strong communication, presentation, and organization skills
- Strong time-management skills and ability to manage multiple priorities
- Ability to work effectively with varied roles and teams
- Prior security compliance, risk, or audit experience, particularly with ISO 27001
- Experience with SOC 2, HIPAA, NIST, FedRAMP, or similar frameworks is a plus
- Experience preparing work papers, audit reports, and presentations
- Working knowledge of information security, technology risk, audit, and control-assurance practices
- Strong understanding of ISO 27001, SOC 2/TSC, NIST CSF, NIST 800-53, NIST AI RMF, CIS, COBIT, and related frameworks
- Experience with enterprise workflow, ticketing, directory, IT infrastructure, GRC, and security technologies; ServiceNow and Jira beneficial
- High level of integrity and confidentiality
- 5+ years of experience in information security risk, governance, compliance, technology audit, security engineering, or related areas
- Working knowledge of IT and security best practices and frameworks including NIST CSF, SOC 2/TSC, CIS, ISO 27001/ISMS, COBIT, and ITIL
- Knowledge of technology risks and experience evaluating cybersecurity, privacy, and engineering controls
- Understanding of vulnerability management, security governance, software development, incident response, physical security, logging and monitoring, microsegmentation, SASE, zero trust, insider threat, vendor risk management, PKI, penetration testing, application controls, and segregation of duties
- Advanced understanding of internal controls and ability to evaluate control design and operating effectiveness
