Jobs › ISO/IEC 27001
ISO/IEC 27001 (Information Security) Jobs
ISO/IEC 27001 is the international standard for an information security management system, the global benchmark for infosec certification.
ISO/IEC 27001 is the world's most widely recognized standard for an Information Security Management System (ISMS). Most recently revised in 2022, it specifies how an organization establishes, operates, and continually improves a risk-based system of security controls, and it is certifiable, so companies use it to prove their security posture to customers and regulators across borders. Where SOC 2 is the dominant attestation in North America, ISO 27001 is the certification most often required internationally.
It is also the template for the newer management-system standards: ISO/IEC 42001 for AI was deliberately built to align with it, so an ISO 27001 program is frequently the foundation a company extends into AI and privacy governance. Roles that require it want people who can build and run an ISMS, manage the control set, and carry an organization through certification and surveillance audits.
ISO/IEC 27001: Frequently Asked Questions
What is ISO/IEC 27001?
It is the international standard for an Information Security Management System (ISMS), specifying a risk-based set of requirements that an organization can be independently certified against.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is a certifiable international standard for a security management system. SOC 2 is an AICPA attestation report common in North America. Many companies pursue both for different markets.
Is ISO 27001 certification required?
It is voluntary, but it is frequently required by international customers and partners and is often the practical baseline for doing business in many markets.
Open ISO/IEC 27001 GRC roles (31)
GRC and AI Governance - Senior Manager
Governance, Risk & Compliance (GRC) Manager
Manager, GRC Subject Matter Experts, Product
Senior Cybersecurity GRC Analyst
Governance, Risk & Compliance Specialist
Security Risk Analyst
RMF/GRC Program Lead
Governance, Risk & Compliance
Chief Information Security Officer
Security GRC Manager
Senior GRC Specialist
Senior AI GRC Engineer
Senior Manager, GRC Subject Matter Experts, Product
Senior GRC Lead
EMEA Assurance Lead
Security GRC Manager: Customer Trust Enablement
IT Governance, Risk & Compliance (GRC) Specialist, Luxembourg
Senior Software Engineer, Trust and Third Party Risk Management
Governance Risk and Compliance
Security Controls Assurance Lead
Senior Security Analyst, Customer Assurance
Sr. Compliance Analyst
Security Compliance Architect
Staff+ Software Engineer, GRC Platform
Senior Manager, Customer Trust & Security Governance
GRC Specialist
Staff+ Security Engineer, Risk Engineering
Senior Manager, Audit Partnerships
GRC Pre-Sales Consultant / Solutions Engineer – DACH market, EMEA
Senior GRC Program Manager
Tech Governance - Security Compliance & Governance Engineer
All GRC jobs · Job alerts