Information Security Engineer

Summary

Information Security Engineer maintaining and improving an ISO/IEC 27001 ISMS—managing security policies, documentation workflows, risk assessments, vulnerability tracking, incident response, and security technology administration using tools like SharePoint, Confluence, and Jira.

You will maintain and continually improve the ISO/IEC 27001 ISMS. You will manage security policies, documentation repositories, registers, workflows, asset governance, data classification, and audit evidence. You will support risk assessments, corrective actions, metrics, dashboards, and security projects. You will also help administer security technologies, assess suppliers, track vulnerabilities, coordinate incident response, and support security awareness initiatives.

Responsibilities

  • Maintain and improve the ISO/IEC 27001 ISMS
  • Manage security policies standards procedures and guidelines
  • Administer SharePoint Confluence and Jira documentation workflows
  • Maintain asset risk exception and action registers
  • Support information asset management and data classification
  • Govern data loss prevention and sensitivity labelling technologies
  • Prepare audits collect evidence and track corrective actions
  • Support information security risk assessments and treatment plans
  • Prepare security metrics dashboards KPIs and management reports
  • Coordinate security projects and track deliverables
  • Support security technology implementation configuration and administration
  • Support third party security assessments and supplier assurance
  • Track vulnerability remediation and escalate overdue items
  • Support security incident response and post incident improvements
  • Support security awareness communication and reporting activities

Requirements

  • Bachelor’s degree in information security Cyber Security Computer Science or a related discipline
  • 5–7 years of experience in Information Security GRC or Security Operations
  • Understanding of ISMS and security governance frameworks such as ISO/IEC 27001
  • Experience with risk management methodologies and information security risk assessments
  • Familiarity with NIS2 SOC 2 CIS Controls GDPR and other security compliance frameworks
  • Experience managing documentation registers and workflows across SharePoint Confluence or Jira
  • Experience with Data Loss Prevention information protection and data classification solutions
  • Experience with data analysis reporting dashboard development and KPI measurement
  • Experience working cross functionally with Infrastructure IT Platform Engineering Compliance and Legal teams
  • Familiarity with vulnerability management processes and assessment tools
  • Familiarity with security testing methodologies and tools
  • Familiarity with security monitoring SIEM platforms and incident detection
  • Familiarity with Endpoint Detection and Response and endpoint security technologies
  • Basic understanding of Identity and Access Management authentication and privileged access management
  • Basic understanding of networking TCP/IP DNS routing switching and network security
  • Basic understanding of web technologies and web application security
  • Basic understanding of cloud security and shared responsibility models
  • PowerShell or Python scripting and automation fundamentals are advantageous

Benefits

  • Flexible work from home
  • Hardware provided according to work needs
  • Regular wellbeing initiatives
  • Diversity and inclusion initiatives

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available