GRC Specialist (ISO27001)
On-siteSuan Luang, Bangkok, Thailand
Job Summary
Maintain and continuously improve the Information Security Management System (ISMS) documentation, including policies, procedures, Statement of Applicability, and risk treatment plans aligned to ISO 27001:2022. Conduct internal audits across IT infrastructure, HR onboarding, and vendor management to identify gaps, drive corrective actions to closure, and produce findings with specific evidence. Manage the ISO 27001 certification lifecycle by preparing for surveillance audits, coordinating with certification bodies, and tracking non-conformity report resolution. Facilitate information security risk assessments using ISO 27005 methodologies to identify threats, assess likelihood and impact, and recommend treatment options. Produce ISMS performance metrics and management review inputs while ensuring all policies are reviewed at defined intervals and communicated to stakeholders. Coordinate with other compliance frameworks like PDPA and PCI-DSS to identify synergies and reduce duplicate effort across programmes.
Required Qualifications
- 5+ years in information security with at least 3 years focused on ISO 27001 implementation and maintenance
- ISO 27001 Lead Auditor or Lead Implementer certification
- Hands-on experience conducting internal audits
- Practical experience with information security risk assessment methodologies (ISO 27005 or equivalent)
- Strong documentation and communication skills
- Fluent in Thai for internal audits and stakeholder communication
- reading/writing English for ISO standards and documentation
Desired Qualifications
- Experience with the ISO 27001:2022 transition
- Familiarity with ISO 27701 (privacy), ISO 22301 (BCM), or PCI-DSS
- Experience with GRC or ISMS management tools (e.g., OneTrust, Vanta, or similar)
- Background in IT operations or system administration before moving into GRC
- CISM, CRISC, or additional GRC-relevant certifications
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.