Job Description
We are seeking a detail-oriented and proactive Information Security Operations Specialist to support the implementation and ongoing operation of the organization’s Information Security governance, compliance, policy, and certification activities.
This is a hands-on, execution-focused role. The specialist will assist with maintaining policies and procedures, collecting and organizing compliance evidence, supporting audits and certifications, updating Information Security documentation, monitoring assigned actions, and coordinating routine communications with internal and external stakeholders.
The role does not include formal management responsibility, strategic ownership of the Information Security program, approval authority, or independent decision-making regarding risk acceptance, policy approval, or compliance exceptions.
Responsibilities
- Support the implementation and ongoing operation of Information Security governance, compliance, and ISMS activities.
- Maintain compliance documentation, control matrices, risk registers, evidence repositories, corrective-action trackers, and related records.
- Collect, review, organize, and maintain evidence for ISO/IEC 27001, PCI DSS, internal audits, external assessments, and certification activities.
- Support the preparation, review, publication, version control, and periodic update of Information Security policies, standards, procedures, and guidelines.
- Track compliance gaps, audit findings, risk-treatment actions, remediation activities, responsible owners, and completion deadlines.
- Support internal and external audits, readiness assessments, control reviews, and certification activities.
- Prepare compliance reports, audit updates, policy summaries, risk documentation, meeting materials, and management-review content.
- Assist with maintaining the Information Security risk register, control inventory, Statement of Applicability, and supporting documentation.
- Support customer security questionnaires, third-party assessments, and routine coordination with IT, Legal, Procurement, Compliance, and business teams.
- Follow up with responsible stakeholders on outstanding evidence, document reviews, corrective actions, and compliance deadlines.
Requirements
- Relevant education or professional experience in Information Security, cybersecurity, compliance, risk management, audit, policy administration, or a related field.
- Strong understanding of Information Security governance, risk, compliance, internal controls, and standards such as ISO/IEC 27001 or PCI DSS.
- Experience preparing, reviewing, updating, or maintaining policies, procedures, compliance records, or audit documentation.
- Strong documentation, business-writing, communication, organizational, and stakeholder-coordination skills.
- Ability to manage multiple deadlines, follow established procedures, work with technical and non-technical teams, and handle confidential information appropriately.