Jobs › ISO/IEC 27001
ISO/IEC 27001 (Information Security) Jobs
ISO/IEC 27001 is the international standard for an information security management system, the global benchmark for infosec certification.
ISO/IEC 27001 is the world's most widely recognized standard for an Information Security Management System (ISMS). Most recently revised in 2022, it specifies how an organization establishes, operates, and continually improves a risk-based system of security controls, and it is certifiable, so companies use it to prove their security posture to customers and regulators across borders. Where SOC 2 is the dominant attestation in North America, ISO 27001 is the certification most often required internationally.
It is also the template for the newer management-system standards: ISO/IEC 42001 for AI was deliberately built to align with it, so an ISO 27001 program is frequently the foundation a company extends into AI and privacy governance. Roles that require it want people who can build and run an ISMS, manage the control set, and carry an organization through certification and surveillance audits.
ISO/IEC 27001: Frequently Asked Questions
What is ISO/IEC 27001?
It is the international standard for an Information Security Management System (ISMS), specifying a risk-based set of requirements that an organization can be independently certified against.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is a certifiable international standard for a security management system. SOC 2 is an AICPA attestation report common in North America. Many companies pursue both for different markets.
Is ISO 27001 certification required?
It is voluntary, but it is frequently required by international customers and partners and is often the practical baseline for doing business in many markets.
Open ISO/IEC 27001 GRC roles (27)
GRC and AI Governance - Senior Manager
Governance, Risk & Compliance (GRC) Manager
Manager, GRC Subject Matter Experts, Product
Senior GRC Specialist
Senior AI GRC Engineer
Senior Director, Privacy, Security & Data Compliance
Senior GRC Lead
Senior Compliance Advisor
Security GRC Manager: Customer Trust Enablement
Senior Director of Governance, Risk and Compliance
Director of Governance, Risk, and Compliance (GRC)
Senior Fullstack Engineer, Vendor Risk Management - UK
Compliance Program Assistant Manager
IT Governance, Risk & Compliance (GRC) Specialist, Luxembourg
Data Governance Technical Program Manager
Governance Risk and Compliance
Staff+ Software Engineer, GRC Platform
Senior Technology and Security Risk Manager
GRC Specialist
Senior Compliance Automation Engineer
Staff+ Security Engineer, Risk Engineering
Senior Fullstack Engineer, Vendor Risk Management
Senior Engineering Manager, Privacy & Data Security
Group Product Manager, GRC Workflows
Senior Manager, Audit Partnerships
Senior Fullstack Software Engineer, Privacy & Data Security
Director of Security, GRC
All GRC jobs · Job alerts