

Dedicated and results-oriented Information Security Management System (ISMS) Internal Auditor with a proven track record in enhancing ISMS awareness and fostering team motivation. Holds an MTech in Instrumentation Engineering with a commendable 78.50%, complemented by multiple certifications in Compliance and Audit Management, demonstrating a commitment to professional development and industry standards. Expertise includes driving compliance initiatives and conducting thorough audits to ensure organizational security integrity. Strong organizational skills promote a culture of continuous improvement and accountability within the workplace.
Management Systems (ISMS), ISO 27001:2022, and Privacy Information Management Systems (PIMS), ISO 27701:2019. The role involves developing policies, conducting gap analysis, delivering training, and coordinating audits, both internal and external. The individual also demonstrates skills in vendor management, compliance monitoring, and awareness program development.
The role involves managing and maintaining Information Security Management System (ISMS) and Privacy Information Management System (PIMS) in accordance with ISO/IEC 27001:2022 and ISO/IEC 27701:2019 standards
Key responsibilities include:
Audit Planning and Execution: Plan and conduct internal, surveillance, and certification audits to ensure ISMS and PIMS compliance
Basic knowledge of Regulatory Compliance: Demonstrate a solid understanding of GDPR, ISO 31000:2018 Risk Management, and ISO 27005: ISRM
Prepare and present: Audit reports to management in the context of Management Risk Management (MRM)
Audit Report Preparation: Prepare internal audit reports detailing conformities, observations, and non-conformities (OFIs and NCs) follow up with stakeholders till closure of the findings
ODC Physical Assessment: Perform Onshore Development Centre (ODC) Physical Assessments as per ISO 27001: 2022 requirement
Risk Management: Conduct risk assessments and develop treatment plans to mitigate identified risks
Stakeholder Coordination: Collaborate with all relevant parties to ensure alignment and effective communication for ISMS compliance
Documentation Management: Prepare, Maintain and update all policy and procedure documents related to ISMS and PIMS
Training: Conduct ISMS induction and Data Privacy Induction sessions