Company logo hidden

ISMS & ISO 27001 Security Process Specialist

Unlock employer Abu Dhabi, United Arab Emirates Direct to Company Under an hour ago · 23 Sep 2026

Financial

  • Estimate: $60k - $120k*
  • Zero income tax location

Accessibility

  • Office Only
  • Visa Provided

Requirements

  • Experience: Senior
  • English: Professional

Position

About the Role
At the company, we are strengthening our Information Security Management System (ISMS) and advancing towards ISO/IEC 27001:2022 certification readiness. We are looking for a hands-on ISMS & Security Process Specialist who will help build, structure, document, and operationalize our security management framework across the organization. This role goes beyond compliance administration or policy maintenance; it requires transforming existing processes, controls, and ways of working into a structured, auditable, and sustainable Information Security Management System. You will work alongside the Group CISO and key stakeholders to lay the groundwork for compliance and certification readiness.

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

The Role
As an ISMS & Security Process Specialist, you will drive the company's ISO/IEC 27001:2022 implementation efforts. Key responsibilities include:

  • Identifying existing security and IT processes, documenting them, and formalizing control activities.
  • Establishing traceability between risks and controls and ensuring evidence can be consistently produced for audits and certification activities.
  • Collaborating with Process Owners, Control Owners, IT Service Owners, Quality Management teams, Security stakeholders, and various business functions.

Success in this role requires strong process documentation skills, practical ISO 27001 knowledge, attention to detail, and the ability to transform fragmented information into a structured and auditable management system.

Key Responsibilities
Build & Maintain the ISMS

  • Develop and maintain the Information Security Management System aligned with ISO/IEC 27001:2022
  • Create policies, procedures, standards, registers, and governance documentation
  • Establish traceability between risks, controls, owners, processes, and evidence
  • Support maintenance of the Information Security Risk Register and Statement of Applicability (SoA)
  • Build sustainable governance structures that support certification readiness

Document & Formalize Processes

  • Identify existing security, IT, and governance processes across the organization
  • Interview stakeholders to understand how controls operate in practice
  • Create process flows, control descriptions, workflows, and supporting documentation
  • Translate operational activities into auditable and repeatable processes
  • Identify and remediate documentation and process gaps

Support ISO/IEC 27001 Compliance

  • Map existing practices against ISO/IEC 27001:2022 clauses and Annex A controls
  • Perform compliance and gap assessments
  • Define actions required to address identified deficiencies
  • Support control owners in documenting controls and evidence requirements
  • Track remediation activities through to completion

Develop the Security Management System

  • Build and maintain security processes within the company's Mavim platform
  • Structure relationships between controls, risks, evidence, systems, and stakeholders
  • Ensure information security requirements are embedded into business processes
  • Maintain process ownership, version control, and review cycles
  • Support continuous improvement of the management system

Manage Evidence & Audit Readiness

  • Establish and maintain the ISMS evidence repository
  • Coordinate the collection and validation of audit evidence
  • Ensure evidence remains current, complete, and accessible
  • Support internal audits, certification audits, and management reviews
  • Track findings, corrective actions, and improvement initiatives

Drive Continuous Improvement

  • Promote best practices in security governance and process management
  • Support stakeholders in adopting structured and sustainable controls
  • Facilitate workshops and working sessions across the business
  • Translate ISO requirements into practical business guidance
  • Improve ISMS maturity, audit readiness, and process effectiveness

What We're Looking For
Experience

  • 4-7 years of experience in Information Security, ISMS, IT Governance, GRC, IT Service Management, Quality Management, or Process Management
  • Practical experience implementing or maintaining an ISO/IEC 27001-compliant management system
  • Experience documenting processes, controls, procedures, and governance frameworks
  • Experience supporting internal audits, certification audits, or compliance assessments
  • Experience working within complex international organizations
  • Familiarity with BPM or process management tools such as Mavim, ARIS, Signavio, Visio, or similar platforms

Technical Expertise

  • ISO/IEC 27001:2022 Framework
  • Information Security Management Systems (ISMS)
  • Risk and Control Management
  • Governance, Risk & Compliance (GRC)
  • Process Documentation and Process Modeling
  • Audit and Evidence Management
  • IT Service Management (ITIL)
  • Mavim, ARIS, Signavio, Visio, or equivalent BPM solutions
  • ServiceNow or similar governance platforms
  • Data Governance and Data Stewardship concepts

Personal Attributes

  • Structured and highly organized
  • Excellent documentation and analytical skills
  • Strong stakeholder engagement abilities
  • Detail-oriented with a focus on quality and compliance
  • Pragmatic and solution-oriented
  • Comfortable working independently and across organizational boundaries
  • Able to challenge existing practices constructively
  • Passionate about building sustainable security processes and management systems

Why Join the company?
In this role, you will directly contribute to strengthening information security across a global maritime leader. You'll work with senior security leadership and stakeholders across multiple countries and business functions, establishing the foundations required for long-term security governance and ISO/IEC 27001 certification readiness. This position provides an opportunity to create lasting organizational impact by building a structured, auditable, and scalable security management system that supports operational excellence and regulatory compliance. Join a team that values ownership, continuous improvement, collaboration, and professional growth.

Ideal Candidate Profile
The ideal candidate is currently an ISMS Specialist, Information Security Analyst, ISO 27001 Consultant, Security Governance Analyst, GRC Specialist, Security Compliance Specialist, IT Governance Consultant, or Information Security Officer, with hands-on experience in building and operationalizing security management systems. This individual understands how to convert policies, controls, and operational practices into a sustainable ISO/IEC 27001:2022-aligned management system and thrives in environments where structure, compliance, and continuous improvement are critical to success.

Apply Direct

Jobs you might like   View all jobs

About Shipbuilding Company

Company details are hidden. Subscribe to view full company profile.

Ready to apply for this role?

Apply Direct