We are seeking an experienced Process Analyst to manage and enhance our Information Security Management System (ISMS) and Quality Management System (QMS) in alignment with ISO 27001 and ISO 9001 standards. The ideal candidate will have a proven track record of successfully managing internal controls, leading compliance initiatives, and facing both internal and external audits with confidence.
Key Responsibilities:
SMS & QMS Management
- Maintain and continually improve the company’s ISMS and QMS frameworks as per ISO 27001 and ISO 9001 requirements.
- Define, implement, and monitor internal policies, procedures, and controls aligned with business objectives.
- Manage risk assessments, control implementation, and effectiveness reviews.
Audit & Compliance
- Conduct periodic internal ISO audits
- Prepare and coordinate external ISO audits (surveillance and recertification).
- Act as the primary point of contact for auditors and certification bodies.
- Drive corrective and preventive action plans (CAPA) based on audit findings.
- Ensure timely closure of nonconformities and documentation of evidence.
Process Management
- Analyze and optimize business processes for efficiency, compliance, and continual improvement.
- Facilitate process documentation, SOP creation, and periodic reviews.
- Ensure consistency and alignment between ISMS, QMS, and organizational processes.
Training & Awareness
- Conduct regular ISMS/QMS awareness and training programs across departments.
- Promote a culture of security, quality, and compliance throughout the organization.
Metrics & Reporting
- Monitor key performance indicators (KPIs) for ISMS and QMS effectiveness.
- Generate periodic compliance and risk reports for management review.
Qualifications & Skills:
- Bachelor’s degree in Information Technology, Computer Science, Management Systems, or related field.
- Minimum 5 years of experience managing or supporting ISO 27001 and ISO 9001 frameworks.
- Hands-on experience with internal/external audits, risk assessments, and control implementation.
- Strong understanding of information security controls, quality management principles, and process improvement.
- Excellent documentation and communication skills.
- Analytical mindset with attention to detail and ability to manage multiple stakeholders.
Certifications preferred:
- ISO 27001 Lead Implementer / Lead Auditor
- ISO 9001 Lead Auditor
- ITIL, Six Sigma, or other process improvement credentials (optional but desirable)