
Application Deadline : 18 Oct 2026
Education
- Bachelor/Honors, Bachelor of Science (BSc)
Experience
- 5-8 Year
Skills
- Audit
- Risk Assessment
Additional Requirements
Experience Requirements
-
Relevant experience in Information Security, GRC, Risk Management, or Compliance roles.
-
Hands-on experience with Drata or equivalent GRC/compliance platforms such as Vanta, Secureframe, or Sprinto, including control monitoring, evidence management, and remediation of failed tests.
-
Practical knowledge of ISO/IEC 27001 audits, including ISMS implementation, internal audits, certification/surveillance audits, evidence preparation, and coordination with external auditors.
-
Strong understanding of security risk assessment, vulnerability management, and security operations.
-
Experience coordinating penetration testing and reviewing vulnerability scan results.
-
Familiarity with incident response and access management processes.
Professional Certifications – Preferred
-
ISO 27001 Lead Implementer certification is highly desirable. Lead Auditor certification is also valued for audit coordination and evidence preparation, considering the role’s operational nature.
-
CISM, CISSP, CRISC, or equivalent information security/risk management certification.
-
**UK GDPR/Data Protection certifications
Responsibilities & Context
Key Responsibilities
1. ISMS & Compliance Management
-
Operate and monitor the Drata trust management platform, reviewing failed tests, findings, and KPIs in coordination with the external GRC partner.
-
Maintain audit-ready evidence and documentation for ISO/IEC 27001:2022 certification and surveillance audits.
-
Support the implementation, maintenance, and continuous improvement of the Information Security Management System (ISMS).
-
Manage compliance documentation and audit evidence.
-
Support UK GDPR and DPA 2018 compliance activities in coordination with the Data Protection Officer.
-
Coordinate with Drata and penetration-testing vendors regarding scheduling, scope, remediation tracking, and budget requirements.
2. Security Risk & Asset Management
-
Conduct and review information security risk assessments in accordance with organizational policies.
-
Act as an Information Security Risk Owner for assigned risks and ensure appropriate treatment.
-
Monitor implementation and effectiveness of security controls across information assets.
-
Support periodic user access reviews.
-
Conduct and support supplier and third-party security risk assessments, including onboarding due diligence, contractual requirements, and periodic reviews.
3. Vulnerability Management & Penetration Testing
-
Coordinate annual and event-driven penetration testing, including tests following major infrastructure changes.
-
Review vulnerability assessment results and coordinate with IT and Engineering teams on timely remediation.
-
Monitor emerging security threats through advisories, bulletins, and intelligence sources.
4. Access Control & Authorisation
-
Review and endorse system and physical access requests based on least-privilege principles.
-
Ensure privileged and restricted-data access follows segregation-of-duties and second-approval requirements.
-
Review BYOD and remote-working arrangements in line with relevant policies and Microsoft Intune/MDM requirements.
5. Incident Response & Security Operations
-
Investigate and assess security incidents, including suspected credential compromises, according to the Incident Response Plan.
-
Support security monitoring, detection, and response activities.
-
Prepare incident reports and track corrective actions through the Continuous Improvement and Non-Conformity process.
6. Disaster Recovery & Business Continuity
-
Maintain and update the Disaster Recovery (DR) Plan in coordination with the DPO and IT Operations Officer.
-
Define DR testing criteria, schedule exercises, and ensure proper execution and evidence collection.
-
Contribute to the broader Business Continuity Plan (BCP), including crisis communication procedures.
7. Internal Audit & Governance
-
Prepare required evidence and participate as an auditee during internal and external certification audits.
-
Support ISO/IEC 27001 surveillance and recertification audits, including preparation and audit sessions.
-
Contribute to governance reporting, security metrics, management reviews, and continuous improvement initiatives.
-
Maintain appropriate audit independence by not auditing controls directly operated by the role.
Compensation & Other Benefits
- Lunch Facilities: Partially Subsidized
- Festival Bonus: 2 (Yearly)
- Salary Review: Yearly
Workplace
hybrid
Employment Status
Full Time/Permanent
Job Location
Anywhere in Bangladesh
Job Shift
Day Shift
Company Information
Information Technology (IT)
Address:
House-31, Road-20, Banani, Dhaka , Dhaka, Bangladesh
Website:
https://indetechs.com/সতর্কীকরণ-বিজ্ঞপ্তি
এই চাকরির বিজ্ঞাপনে প্রদত্ত তথ্যের ভিত্তিতে যদি বিজ্ঞাপন দাতা প্রতিষ্ঠান আপনার কাছ থেকে কোন অর্থ দাবি করে, অথবা কোন ধরনের ভুল বা বিভ্রান্তিকর তথ্য প্রদান করে, তবে অনুগ্রহ করে অবিলম্বে আমাদেরকে জানান অথবা সংশ্লিষ্ট জবটি রিপোর্ট করুন। চাকরি পাওয়ার জন্য BDJobs Live কাউকে কোন ব্যক্তিগত বা প্রতিষ্ঠানকে অর্থ প্রদান করতে উৎসাহিত করে না। কোন ধরনের অর্থ লেনদেনের দায় BDJobs Live বহন করবে না।