External Information Security Auditor

Responsibilities 

About the Role
Responsible for conducting an external, independent, and objective assessment of LOGAN Valuation’s Information Security Management System (ISMS), using the requirements of ISO/IEC 27001:2022 as a reference. The purpose of the position is to identify the level of conformity and maturity of the ISMS, assess the effectiveness of implemented controls, and identify gaps or risks requiring attention. The work will contribute to strengthening information security management, protecting the organization’s assets, and continuously improving the system at a regional level. 

Key Responsibilities

  • Independently assess the ISMS against the applicable requirements of ISO/IEC 27001:2022. 
  • Review the documentation, policies, procedures, records, and evidence supporting the ISMS. 
  • Conduct interviews with process owners and validate the implementation and effectiveness of controls. 
  • Assess aspects related to governance, risk management, access controls, Microsoft 365 and SharePoint security, backups, and remote work. 
  • Identify nonconformities, gaps, risks, and opportunities for improvement. 
  • Document the assessment results and provide objective evidence supporting the findings. 
  • Issue an independent final report with conclusions and remediation recommendations

Bogotá, Colombia

To be agreed

In accordance with the service proposal submitted

1 vacancy

Contract Type

  • Independent Contractor 

Skills

  • Analytical thinking and ability to identify gaps and risks 
  • Objectivity and independence in assessment 
  • Documentation and report-writing skills 
  • Effective communication for interviews and presentation of findings 

Benefits

  • N/A
  • Bachelor’s degree in Systems Engineering, Computer Engineering, Information Security, Cybersecurity, Technology, or related fields. 
  • ISO/IEC 27001 Lead Auditor or Lead Implementer (preferred) 
  • CISA or CISSP (preferred) 
  • Experience in auditing or assessing Information Security Management Systems. 
  • Specific experience with ISO/IEC 27001 and information security control assessments. 
  • ISO/IEC 27001:2022 and Information Security Management Systems (ISMS) 
  • Information security auditing, control assessment, and risk management 
  • Microsoft 365 and SharePoint 
  • Access controls, backups, and security in remote work environments 

 

  • Spanish preferred 
  • English desirable 

At LOGAN Valuation, we are committed to equal employment opportunity. All hiring decisions are based on candidates’ qualifications, experience, and merit. We do not discriminate based on health status, gender, genetic information, national origin, socioeconomic background, age, disability, religion, sexual orientation, or any other characteristic protected by applicable law. 

Send your proposal to HR@Loganvaluation.com, with the position title in the subject line.