About the Role
Responsible for conducting an external, independent, and objective assessment of LOGAN Valuation’s Information Security Management System (ISMS), using the requirements of ISO/IEC 27001:2022 as a reference. The purpose of the position is to identify the level of conformity and maturity of the ISMS, assess the effectiveness of implemented controls, and identify gaps or risks requiring attention. The work will contribute to strengthening information security management, protecting the organization’s assets, and continuously improving the system at a regional level.
Key Responsibilities
- Independently assess the ISMS against the applicable requirements of ISO/IEC 27001:2022.
- Review the documentation, policies, procedures, records, and evidence supporting the ISMS.
- Conduct interviews with process owners and validate the implementation and effectiveness of controls.
- Assess aspects related to governance, risk management, access controls, Microsoft 365 and SharePoint security, backups, and remote work.
- Identify nonconformities, gaps, risks, and opportunities for improvement.
- Document the assessment results and provide objective evidence supporting the findings.
- Issue an independent final report with conclusions and remediation recommendations