> Markdown version of [/jobs/ext/2207257-iso-27001-information-security-auditor](https://www.wearedevelopers.com/jobs/ext/2207257-iso-27001-information-security-auditor). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ISO 27001 Information Security Auditor - **Company:** BSI gGmbH - **Location:** Frankfurt am Main, Germany - **Salary:** €56,000.0 - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Tisax, Information Security Management System - **Published:** August 24, 2026 - **Apply:** https://www.adzuna.de/details/5835747307 ## About the Role Are you passionate about information security and helping organizations build trust through internationally recognized standards? Do you enjoy working with a variety of clients and making a real impact on their information security management systems? If so, we'd like to hear from you., * Solid professional experience in information security, with a good understanding of security governance, risk management and controls. * Sound knowledge of relevant information security standards and frameworks, such as ISO/IEC 27001, BSI IT-Grundschutz, NIST CSF or COBIT. * Previous audit or assessment experience is an advantage. * Willingness to undertake further qualifications in related standards and assessment schemes, such as ISO 22301, ISO/IEC 20000-1, ISO 9001 or TISAX. * Strong analytical and problem-solving skills, with the ability to understand complex environments and evaluate information security risks and controls. * Excellent communication and stakeholder management skills, with the confidence to engage with both technical specialists and senior management. * Strong organizational and planning skills, with the ability to independently manage multiple client engagements and priorities. * Ability to build trusted client relationships and adapt effectively to diverse cultural environments in Germany and internationally. * Comfortable working independently as well as collaborating with and, where appropriate, leading audit teams. * Flexibility and willingness to travel to client locations when required (approximately 50% travel). Language Skills Required * German: Excellent proficiency, both written and spoken (CEFR C1 or above) * English: Very good proficiency, both written and spoken (CEFR B2 or above) ## Description As an Information Security Auditor, you will perform independent assessments against internationally recognized information security standards. You will work closely with clients to evaluate the effectiveness of their Information Security Management Systems (ISMS), provide valuable insights, and contribute to improving their security posture., * Prepare, plan, and conduct information security audits in accordance with applicable standards, accreditation requirements, and company procedures. * Assess clients' Information Security Management Systems and produce clear, accurate, and professional audit reports. * Present audit findings to clients, ensuring they understand the assessment outcome and any required corrective actions. * Recommend the issuance, continuation, suspension, or withdrawal of certification in accordance with company policies and accreditation requirements. * Deliver recommendations within prescribed quality standards and reporting timelines. * Lead audit teams where required, ensuring effective planning, coordination, and delivery of audit activities. * Maintain overall responsibility for assigned client accounts, building strong long-term relationships while ensuring excellent service delivery and identifying opportunities for account growth. * Develop and maintain audit plans. * Work closely with internal support teams to ensure client records, audit documentation, and certification information remain accurate and up to date. * Plan and manage your own audit schedule to maximize efficiency, client satisfaction, and revenue-generating activities. * Contribute to achieving annual operational, utilization, and financial performance targets. * Stay current with developments in information security standards, regulations, and industry best practices. ## Related Videos - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Communicate efficiently with Software Architecture Diagrams](https://www.wearedevelopers.com/videos/379-communicate-efficiently-with-software-architecture-diagrams) - [The Future of Recruiting: Innovations and Challenges in the European IT Sector](https://www.wearedevelopers.com/videos/1056-the-future-of-recruiting-innovations-and-challenges-in-the-european-it-sector) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Jobs in Germany for Americans](https://www.wearedevelopers.com/magazine/423-jobs-in-germany-for-americans) - [Finding Jobs in Germany](https://www.wearedevelopers.com/magazine/375-finding-jobs-in-germany) - [German Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/328-german-business-culture-and-etiquette) - [Best Companies to Work For in Berlin: Top 14 Companies in 2023 ](https://www.wearedevelopers.com/magazine/188-best-companies-to-work-for-in-berlin-top-14-companies-in-2023)