
Data Protection Officer β ISO Lead
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United States.
β’ Take ownership of, maintain, and update ISMS documentation, which includes policies, procedures, controls, and records.
β’ Oversee the ISMS through control monitoring, risk treatment, and ongoing enhancement.
β’ Provide guidance and assistance in completing Security Assurance Questionnaires from both prospects and clients.
β’ Develop internal capabilities for managing security questionnaires.
β’ Perform cybersecurity assessments and policy evaluations, identify deficiencies, and drive necessary remediation efforts.
β’ Organize and manage both internal and external ISO audits, as well as regulatory compliance audits.
β’ Collaborate with certification bodies and prepare the organization for surveillance and recertification processes.
β’ Appoint a representative for Cognassist's InfoSec and Estate Committee and engage in committee activities.
β’ Participate in quarterly GRCA meetings with leadership.
β’ Suggest and implement improvements for InfoSec governance, risk, and compliance programs.
β’ Provide consultancy for Data Protection Officer on an as-needed basis.
β’ Adhere to industry-standard security protocols while utilizing encrypted communications and secure networks.
β’ Proven experience in offering InfoSec and audit compliance consultancy, preferably within a SaaS or technology setting.
β’ Established record of maintaining and managing an ISO ISMS through certification and audit processes.
β’ Experience in completing Security Assurance Questionnaires and addressing customer and supplier security due diligence inquiries.
β’ Familiarity with Data Protection Officer duties, UK GDPR, and the Data Protection Act 2018.
β’ Relevant qualifications such as ISO Lead Implementer or Lead Auditor.
β’ Recognized data protection certification, such as BCS/CIPP.
β’ Excellent documentation skills.
β’ Capability to work independently with minimal supervision.
β’ Proficient in handling special category or sensitive personal data with the utmost care and confidentiality.
β’ Commitment to compliance with industry-standard security protocols, encrypted communications, and secure networks.
β’ Best possible benefits.
β’ Access to the latest tools.
β’ Supportive work environments.
β’ Emphasis on an inclusive culture and investment in people.
CVS Health
FreedomCare
Northrop Grumman
Get handpicked remote jobs straight to your inbox weekly.