Local Security Officer (LSO)
TMF Group Local Security Officer (LSO)
Summary
The Local Security Officer is TMF Group's on-the-ground owner of information security, business continuity, emergency response, and physical security for a local office. Day to day this means ISO 27001/ISAE 3402 compliance and audits, incident reporting, BCP and emergency drills, and overseeing access control and security vendors.
1. Information Security (ISMS)
Act as the local point of contact for all information security matters.
Ensure compliance with TMF’ s global Information Security Management Framework and underlying policies, procedures, and standards.
Ensure compliance with ISO 27001 and ISAE 3402 standards.
Support internal and external audits related to information security.
Follow up on the closure of the corrective and preventive action plan for the reported non-conformities and observations.
Report and escalate security incidents to the Global Information Security Officer (GISO).
Co-ordinating with asset and process owners for periodic review of asset list and risk assessment.
Conduct periodic security awareness training for staff.
2. Business Continuity Planning (BCP)
Maintain and update the local Business Continuity Plan.
Coordinate regular BCP testing and simulations.
Ensure critical business functions are identified and recovery strategies are in place.
Support the implementation of the Business Continuity Management System (BCMS) ISO22301
Liaise with global and regional BCP teams to align local plans with corporate standards.
3. Emergency Response Planning (ERP)
Develop and maintain emergency response procedures for the local office.
Conduct regular emergency drills (e.g., fire evacuation, lockdown).
Coordinate with building management and local authorities during emergencies.
Ensure emergency contact lists and communication protocols are up to date.
4. Physical Security
Oversee access control systems, visitor management, and office security measures.
Conduct regular security risk assessments and recommend improvements.
Manage relationships with security vendors and service providers.
5. Compliance & Reporting
Ensure compliance with local laws and regulations related to security and safety.
Prepare and submit regular reports on security incidents, audit findings, and risk assessments
Participate in regional and global security meetings and initiatives.