ISO 27001 Information Security Auditor

BSI gGmbH
Frankfurt am Main, Germany
3 days ago
Apply on www.adzuna.de
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
€56,000.0
Working hours
Regular working hours
Languages
English, German
Job source

Tech stack

Control Objectives for Information and Related Technology (COBIT) Cyber Security Tisax Information Security Management System

Job description

As an Information Security Auditor, you will perform independent assessments against internationally recognized information security standards. You will work closely with clients to evaluate the effectiveness of their Information Security Management Systems (ISMS), provide valuable insights, and contribute to improving their security posture., * Prepare, plan, and conduct information security audits in accordance with applicable standards, accreditation requirements, and company procedures.

  • Assess clients’ Information Security Management Systems and produce clear, accurate, and professional audit reports.
  • Present audit findings to clients, ensuring they understand the assessment outcome and any required corrective actions.
  • Recommend the issuance, continuation, suspension, or withdrawal of certification in accordance with company policies and accreditation requirements.
  • Deliver recommendations within prescribed quality standards and reporting timelines.
  • Lead audit teams where required, ensuring effective planning, coordination, and delivery of audit activities.
  • Maintain overall responsibility for assigned client accounts, building strong long-term relationships while ensuring excellent service delivery and identifying opportunities for account growth.
  • Develop and maintain audit plans.
  • Work closely with internal support teams to ensure client records, audit documentation, and certification information remain accurate and up to date.
  • Plan and manage your own audit schedule to maximize efficiency, client satisfaction, and revenue-generating activities.
  • Contribute to achieving annual operational, utilization, and financial performance targets.
  • Stay current with developments in information security standards, regulations, and industry best practices.

Requirements

Are you passionate about information security and helping organizations build trust through internationally recognized standards? Do you enjoy working with a variety of clients and making a real impact on their information security management systems? If so, we’d like to hear from you., * Solid professional experience in information security, with a good understanding of security governance, risk management and controls.

  • Sound knowledge of relevant information security standards and frameworks, such as ISO/IEC 27001, BSI IT-Grundschutz, NIST CSF or COBIT.
  • Previous audit or assessment experience is an advantage.
  • Willingness to undertake further qualifications in related standards and assessment schemes, such as ISO 22301, ISO/IEC 20000-1, ISO 9001 or TISAX.
  • Strong analytical and problem-solving skills, with the ability to understand complex environments and evaluate information security risks and controls.
  • Excellent communication and stakeholder management skills, with the confidence to engage with both technical specialists and senior management.
  • Strong organizational and planning skills, with the ability to independently manage multiple client engagements and priorities.
  • Ability to build trusted client relationships and adapt effectively to diverse cultural environments in Germany and internationally.
  • Comfortable working independently as well as collaborating with and, where appropriate, leading audit teams.
  • Flexibility and willingness to travel to client locations when required (approximately 50% travel).

Language Skills Required

  • German: Excellent proficiency, both written and spoken (CEFR C1 or above)
  • English: Very good proficiency, both written and spoken (CEFR B2 or above)

Benefits & conditions

What We Offer

  • The opportunity to work with a diverse portfolio of clients across multiple industries.
  • Continuous professional development and training.
  • A collaborative and supportive international team environment.
  • Career progression opportunities within a global certification and assurance organization.
  • Competitive salary and benefits package.

About the company

BSI is a business improvement and standards company and for over a century BSI has been recognized for having a positive impact on organizations and society, building trust and enhancing lives. Today BSI partners with more than 77,500 clients in 195 countries and engages with a 15,000 strong global community of experts, industry and consumer groups, organizations and governments. Utilizing its extensive expertise in key industry sectors - including automotive, aerospace, built environment, food and retail, and healthcare - BSI delivers on its purpose by helping its clients fulfil theirs. Living by our core values of Client-Centricity, Agility, and Collaboration, BSI provides organizations with the confidence to grow by partnering with them to tackle society’s critical issues - from climate change to building trust in digital transformation and everything in between - to accelerate progress towards a better society and a sustainable world. BSI is an Equal Opportunity Employer dedicated to fostering a diverse and inclusive workplace.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.de
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:15 min

Overcoming cultural resistance to achieve international security compliance standards

Ali Yazdani Ali Yazdani · World Congress 2023

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:40 min

Addressing data sovereignty and compliance blind spots within AI

Sebastian Kister Sebastian Kister · World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

Videos

See all

Related articles

See all