> Markdown version of [/jobs/ext/2173643-senior-conformity-assessment-program-specialist-information-security-management-system](https://www.wearedevelopers.com/jobs/ext/2173643-senior-conformity-assessment-program-specialist-information-security-management-system). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Conformity Assessment Program Specialist - Information Security Management System - **Company:** UL, LLC - **Location:** Saint-Aubin, France - **Experience:** Expert - **Salary:** €55,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Tisax, Information Security Management System, Information Technology - **Published:** August 22, 2026 - **Apply:** https://dejobs.org/x/x/E8FA434A222F448381B87A98AE0FE40A/job/ ## About the Role * Bachelor's or Master's degree in Information Security, Computer Science, Cybersecurity, Risk Management, or a related field. * Minimum 5 years of experience in information security, IT compliance, or risk management roles, preferably within a TIC (Testing, Inspection, Certification) organization. * Proven experience in implementing and maintaining ISO/IEC 27001 and TISAX-conformant/compliant ISMS. * Preferred certifications: ISO/IEC 27001 or TISAX Lead Implementer. * Strong understanding of and experience with risk management methodologies, processes, and tools (e.g., risk registers, threat modeling). * Demonstrated experience supporting ISO/IEC 27001/TISAX implementations, including contributing to the resolution of corrective actions and supporting continuous improvement initiatives led by ISMS Managers. * Excellent analytical, organizational, and project management skills. * Strong interpersonal, networking and communication skills, with the ability to influence internal and external stakeholders at all levels. * Fluency in English required. ## Description The Senior ISO/IEC 27001 + TISAX Compliance Specialist is responsible for developing, implementing, and maintaining the organization's Information Security Management Systems (ISMS) global conformance/compliance requirements to ensure alignment with ISO/IEC 27001 and TISAX requirements across multiple business/customer operating units. This role ensures conformance/compliance with the requirements, supports the management of information security risks, and support of the culture of information and cybersecurity security awareness across the organization where ISO/IEC 27001 /TISAX conformance/compliance is required. * Develop and maintain global ISO/IEC 27001 and TISAX conformance/compliance requirements documentation in support of local UL Solutions Statements of Applicability (SoAs), information security policies, procedures, processes, and controls. * Collaborate with ISMS Managers to ensure local conformance/compliance with ISO/IEC 27001 and TISAX requirements, including legal, regulatory, and contractual obligations. * Partner with Global Technology, Global Cybersecurity, and other key functional teams (e.g., Legal, Business Continuity) to advise on applicable ISMS control requirements and potential solutions to address ISO/IEC 27001 and TISAX conformance/compliance issues. * Support locations in conducting information security risk assessments and treatment, providing advice and guidance to ensure a consistent and aligned approach across the organization. * Support the development of global processes that enable conformance/compliance with ISO/IEC 27001 and TISAX requirements. * Support continuous improvement initiatives led by ISMS Managers. * Assist in resolving corrective actions managed by ISMS Managers, leveraging prior experience in managing corrective actions to provide effective support. * Stay current with changes in ISO/IEC 27001, TISAX, and other relevant best practice standards and regulatory frameworks. ## Related Videos - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Best Companies to Work For in Paris: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/190-best-companies-to-work-for-in-paris-top-25-companies-in-2023) - [Best Companies to Work For in France: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/189-best-companies-to-work-for-in-france-top-25-companies-in-2023) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Average Salary in France](https://www.wearedevelopers.com/magazine/269-average-salary-in-france)