Roles & Responsibilities
Job Nature
The Information Security Auditor will be responsible for assessing, monitoring, and ensuring the organization’s compliance with international security standards (ISO 27001), cybersecurity frameworks, and data protection regulations. The role involves planning and conducting internal / external audits, identifying risks and vulnerabilities, and recommending corrective actions. The auditor will work closely with IT, compliance, and business teams to strengthen the organization’s security posture and support certification / recertification processes.
Key Responsibilities
Audit & Compliance
Plan, conduct, and report on internal information security audits aligned with ISO 27001 and other frameworks.
Support external audits and certification processes by liaising with auditors and regulatory bodies.
Ensure compliance with data protection laws (e.g., GDPR, PDPA where applicable).
Risk & Controls Assessment
Evaluate existing security controls, policies, and procedures for effectiveness.
Identify risks, vulnerabilities, and gaps in cybersecurity and data protection practices.
Recommend improvements and track corrective / preventive actions (CAPA).
Documentation & Reporting
Develop and maintain audit checklists, reports, and compliance documentation.
Provide management with clear audit findings and risk assessments.
Maintain evidence logs for ISO 27001 controls and compliance purposes.
Stakeholder Engagement
Collaborate with IT, HR, Legal, and Business units to ensure alignment with security policies.
Conduct awareness sessions to promote compliance culture.
Advise leadership on security risks, trends, and mitigation strategies.
Continuous Improvement
Monitor changes in international standards and regulatory requirements.
Drive continuous improvement of Information Security Management Systems (ISMS).
Benchmark practices against industry best standards (e.g., NIST, CIS Controls).
Qualifications & Skills
Education & Certifications
Experience
Skills
Tell employers what skills you have
Information Security
Report Writing
Security Audits
Risk Assessment
Assessing
ISO
Risk Management
Information Technology
ISO 27001
Auditor
Compliance
Audits
CISA
Information Security Management
Audit
CISSP
Information Security • D23 Hillview, Dairy Farm, Bukit Panjang, Choa Chu Kang, SG