We are looking for a skilled ISMS Compliance Officer to lead the implementation, certification, and ongoing management of the ISO 27001 Information Security Management System (ISMS) at our Rawalpindi office. This role will primarily focus on achieving ISO 27001 certification and ensuring that our information security practices meet international standards. The position requires on-site presence in Rawalpindi, with working hours from 5:30 PM to 2:30 AM (PST).
Key Responsibilities
ISMS Implementation & Management:
Take charge of designing, documenting, and implementing the ISMS framework in accordance with ISO 27001 standards. Conduct thorough risk assessments and gap analyses, followed by the implementation of corrective actions. Develop, review, and maintain information security policies, standard operating procedures (SOPs), and control frameworks. Ensure that offshore operations in Islamabad comply with the security and compliance expectations of US clients.
Audit & Certification:
Prepare the organization for ISO 27001 certification audits, including both Stage 1 and Stage 2. Coordinate effectively with accredited external auditors and certification bodies. Lead internal ISMS audits and ensure timely resolution of any findings. Support future plans to expand the certification scope to include US headquarters operations.
Compliance & Regulatory Alignment:
Map ISMS controls against HIPAA and HITECH requirements, proactively identifying and addressing any compliance gaps. Assist in the future integration of ISO 9001 standards for quality management and continuous improvement. Monitor and ensure compliance with local Pakistan IT regulations as well as relevant international requirements affecting the business.
Training & Awareness:
Conduct ISMS awareness training sessions for employees across IT, network, and medical billing teams. Foster and promote a security-first culture throughout the Islamabad operations to enhance overall security posture.
Required Qualifications
- Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field.
- Minimum of 3 years’ experience in information security or compliance roles.
- Strong knowledge of HIPAA, HITECH, and risk management principles.
- Excellent communication skills with the ability to collaborate effectively with global teams.
Preferred Qualifications and Benefits
- Certifications such as ISO 27001 Auditor or Implementer, CISA, CISM, or CISSP are highly desirable.
- Opportunity to lead ISO 27001 implementation and certification efforts.
- Involvement in driving ISMS frameworks, risk assessments, and control mechanisms.
- Responsibility for ensuring compliance with HIPAA, HITECH, and other regulatory requirements.
- Lead both internal and external security audits.
- Play a key role in building a security-first culture through employee training and awareness programs.
This role offers a unique opportunity to be at the forefront of information security compliance within a dynamic environment, working closely with international teams and contributing to the organization’s global security standards.