Jobs › ISO/IEC 27001
ISO/IEC 27001 (Information Security) Jobs
ISO/IEC 27001 is the international standard for an information security management system, the global benchmark for infosec certification.
ISO/IEC 27001 is the world's most widely recognized standard for an Information Security Management System (ISMS). Most recently revised in 2022, it specifies how an organization establishes, operates, and continually improves a risk-based system of security controls, and it is certifiable, so companies use it to prove their security posture to customers and regulators across borders. Where SOC 2 is the dominant attestation in North America, ISO 27001 is the certification most often required internationally.
It is also the template for the newer management-system standards: ISO/IEC 42001 for AI was deliberately built to align with it, so an ISO 27001 program is frequently the foundation a company extends into AI and privacy governance. Roles that require it want people who can build and run an ISMS, manage the control set, and carry an organization through certification and surveillance audits.
ISO/IEC 27001: Frequently Asked Questions
What is ISO/IEC 27001?
It is the international standard for an Information Security Management System (ISMS), specifying a risk-based set of requirements that an organization can be independently certified against.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is a certifiable international standard for a security management system. SOC 2 is an AICPA attestation report common in North America. Many companies pursue both for different markets.
Is ISO 27001 certification required?
It is voluntary, but it is frequently required by international customers and partners and is often the practical baseline for doing business in many markets.
Open ISO/IEC 27001 GRC jobs (52)
Lead, Security Controls Assurance - SOX
Security Risk Management Specialist II
Enterprise Risk Manager / Hibrido - Barueri SP
Deputy Chief Information Security Officer
Governance, Risk, and Compliance Manager - FedRAMP
Governance, Risk, and Compliance Manager - Privacy
Information Security Controls Manager - Cloud & AI Governance
Security Compliance, GRC Engineer
Product GRC Subject Matter Expert, (V4G)
Subject Matter Expert, GTM GRC - V4G
Security & AI Governance Lead
Senior Third-Party Risk Specialist
Director, Cyber GRC
Security Compliance Specialist
GRC Pre-Sales Consultant / Solutions Engineer – EMEA
ICT GRC – Risk & Compliance Manager
Director of Cybersecurity Governance, Risk and Compliance
Compliance Analyst - AI Governance
Risk Services - Cyber Security Audit, Experienced/Senior Associate
Operational Resilience Manager
IT Risk & Compliance Manager
GRC Principal
Cybersecurity & AI Engineer Automation
Global Risk and Compliance Manager
Internal Audit Manager
ICT Risk Oversight Lead
Senior Manager, Information Compliance, AI Governance & Privacy
Staff Program Manager, Compliance
Field CISO
Senior IT Internal Auditor
GRC Engineer
Governance, Risk & Compliance Analyst
Virtual CISO & Cybersecurity Practice Lead
Director of Governance, Risk & Compliance (GRC)
Governance, Risk & Compliance (GRC) Analyst
GRC Lead, Governance, Risk & Compliance (Cybersecurity)
Sr Manager, Governance, Risk, Compliance & Privacy
GRC Program Manager
Program Manager, Security GRC
Security Assurance Lead
Security Engineer, GRC
Software Engineer, Risk Management
Senior Internal Auditor, Technology
Security Compliance Analyst, Privacy
IT Enterprise Risk Analyst
Chief Information Security Officer
GRC Pre-Sales Consultant / Solutions Engineer – DACH market, EMEA
EMEA Assurance Lead
Senior Software Engineer, Trust and Third Party Risk Management
Security Controls Assurance Lead
Tech Governance - Security Compliance & Governance Engineer
Senior GRC Program Manager
ISO/IEC 27001 jobs: what the market looks like right now
A snapshot built from the 52 ISO/IEC 27001 roles currently on this page.
What these roles pay
Of the 52 open ISO/IEC 27001 roles on this page, 14 publish a salary range. Across those:
- Median advertised midpoint: $183k
- Middle half of the market: $125k to $250k
- Full advertised range: $62k to $410k
Computed from the live postings on this page, not from survey data, and recalculated every time the board refreshes. Roles without a published range are excluded.
Where the work is
- Work mode: 11 remote, 2 hybrid, 39 on-site or unstated.
- Seniority mix: senior (28), mid (17), executive (4), director (3)
- Employers hiring more than one: Vanta (5), Mistral AI (3), Anthropic (2), Decagon (2), N26 (2), Scale AI (2)
Skills these postings ask for
- board and committee reporting
- policy lifecycle ownership
- risk appetite and tolerance setting
- three-lines-of-defence operating models
- ISO/IEC 42001 and NIST AI RMF fluency
How to get a governance job — the full career guide for this field: entry routes, transferable backgrounds, certifications and salary by level.
Certifications that come up most
None of these are universally required, but they appear often enough in ISO/IEC 27001 postings to be worth knowing: CGEIT, CRISC, AIGP, CISA. The certification academy covers what each one actually tests and who it is for.
Hiring for ISO/IEC 27001?
We have 52 open ISO/IEC 27001 roles on the board right now. Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
All GRC jobs · Job alerts