1

Iso 27001 Jobs (NOW HIRING)

ISO Analyst

Irving, TX · On-site

$100K - $125K/yr

NIST (800-53/CSF), ISO/IEC 27001, SOC2, and enterprise ISRP-style review processes. - Experience producing audit-ready evidence and formal compliance reports; comfortable interacting with auditors ...

Experience in managing and ISO 27001 audit * Have experience in performing a risk assessment and can set up the required processes * Experience in tracking ISO remediation efforts * Knowledge of ...

IT/IS Manager

Eau Claire, WI · On-site

$95K - $125K/yr

We are seeking an experienced IT/IS Manager with strong, hands-on ISO 27001 expertise to lead our IT infrastructure and information security program, ensuring our systems, data, and network are ...

IT/IS Manager

Eau Claire, WI · On-site

$94K - $115K/yr

This role carries direct, primary ownership of our ISO 27001-aligned Information Security Management System (ISMS): you will lead the build-out, maturation, and ongoing governance of our security ...

Support ISO 27001 certification, audits, and continuous compliance activities * Perform risk assessments and assist with remediation planning * Review, update, and maintain security policies ...

NY · On-site

$120 - $160/hr

Lead and maintain the company's ISO 27001 Information Security Management System (ISMS) and SOC 2 Trust Services Criteria certification programs. * Serve as the primary point of contact for engaging ...

New

Support ISO 27001 certification, audits, and continuous compliance activities * Perform risk assessments and assist with remediation planning * Review, update, and maintain security policies ...

Support ISO 27001 certification, audits, and continuous compliance activities * Perform risk assessments and assist with remediation planning * Review, update, and maintain security policies ...

... ISO 27001, NIST SP 800-53, PCI DSS, and SOC2. Great understanding of IT control frameworks (COBIT) and IT general controls Strong knowledge of information security concepts, risk and controls ...

Security Manager

Dallas, TX · On-site

$150K - $165K/yr

Review SOC 2 reports, ISO 27001 certifications, penetration test results, privacy controls, and cloud security practices. * Develop and improve vendor risk methodologies, onboarding processes, and ...

This role contributes directly to maintaining ISO 27001:2022 certification, supporting surveillance and external audits, driving KPI/KRI reporting, and enabling the maturity and scalability of GRC ...

NY · On-site

$93.19 - $134.62/hr

Tieto söker Security Compliance Manager i Solna. Fokus på GRC, DORA/NIS2, ISO 27001/ISAE 3402, audits, RFI/RFP och leverantörssäkerhet. Ansök med CV eller LinkedIn. Ny tjänst: Tieto söker ...

This role owns the day-to-day execution of NMC²'s SOC 2 Type II and ISO 27001 compliance programmes - from readiness assessments and control mapping through to evidence collection and external audit ...

Showing results 21-40

Iso 27001 information

See salary details

$43K

$106.7K

$159.5K

How much do iso 27001 jobs pay per year?

As of Aug 9, 2026, the average yearly pay for iso 27001 in the United States is $106,734.00, according to ZipRecruiter salary data. Most workers in this role earn between $88,000.00 and $124,000.00 per year, depending on experience, location, and employer.

How do you become ISO 27001 certified?

To become ISO 27001 certified, an organization must implement an Information Security Management System (ISMS) aligned with ISO 27001 standards, conduct a thorough internal audit, and then undergo a certification audit by an accredited certification body. For professionals, gaining knowledge through ISO 27001 training and certification can enhance expertise in managing information security compliance.

What are typical responsibilities for someone working in an ISO 27001 role?

Professionals in ISO 27001 roles are often responsible for developing, implementing, and maintaining an organization's information security management system (ISMS) in line with the ISO 27001 standard. This usually involves conducting risk assessments, developing and enforcing security policies and procedures, training staff on security awareness, and leading internal or external audits. Collaboration with IT, compliance, and business units is common to ensure security objectives are aligned with broader organizational goals. Many professionals also document processes and manage corrective actions to address security gaps. These responsibilities help ensure continual compliance and the ongoing effectiveness of the ISMS.

What is an ISO 27001?

An ISO 27001 job typically involves implementing, managing, and maintaining an organization's Information Security Management System (ISMS) based on the ISO/IEC 27001 standard. Professionals in this role ensure compliance with security policies, conduct risk assessments, and implement controls to protect sensitive data. They may work as ISO 27001 auditors, consultants, or compliance managers, focusing on securing information assets and improving cybersecurity practices.

What are the key skills and qualifications needed to thrive in the ISO 27001 position, and why are they important?

To thrive as an ISO 27001 Consultant or Lead Implementer, you need a solid understanding of information security management systems, risk assessment, and compliance best practices, typically backed by ISO 27001 certification. Familiarity with tools such as GRC (Governance, Risk, and Compliance) platforms and knowledge of IT audit methodologies is highly beneficial. Strong problem-solving, communication, and project management skills help bridge technical requirements and business needs. These abilities are crucial to ensure organizations maintain compliance, manage risks effectively, and build robust information security frameworks.

More about Iso 27001 jobs
What are the most commonly searched types of Iso 27001 jobs? The most popular types of Iso 27001 jobs are:
What states have the most Iso 27001 jobs? States with the most job openings for Iso 27001 jobs include:
Infographic showing various Iso 27001 job openings in the United States as of August 2026, with employment types broken down into 90% Full Time, 2% Part Time, 6% Contract, and 2% Nights. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution, with an average salary of $106,734 per year, or $51.3 per hour.

$100K - $125K/yr

Full-time

Re-posted 22 days ago


Job description

ISO Analyst
Must Have Technical/Functional Skills
- 5+ years in information security with at least 3 years focused on cloud security architecture and compliance reviews (AWS, GCP, or Azure).
- Hands-on familiarity with cloud infrastructure and services: VPC/VNet, compute (EC2, GCE), storage (S3, GCS), IAM, networking,
logging/monitoring, and KMS/CMEK concepts.
- Strong knowledge of security controls and implementation patterns in IaC/CI-CD pipelines (Terraform, policy-as-code concepts preferred).
- In-depth understanding of compliance and risk frameworks: NIST (800-53/CSF), ISO/IEC 27001, SOC2, and enterprise ISRP-style review
processes.
- Experience producing audit-ready evidence and formal compliance reports; comfortable interacting with auditors, risk owners, and business
stakeholders.
- Excellent written and verbal communication; ability to present residual risk and remediation trade-offs to technical and non-technical audiences.
- Relevant certifications preferred: CISSP, CISM, CRISC, CCSK, AWS/GCP security certs, or ISO 27001 Lead Auditor.
Desired Skills & Attributes
- Prior experience participating in cloud solution certification programs or gate-based security reviews.
- Familiarity with MITRE ATT&CK mapping and interpreting threat model outputs.
- Ability to work cross-functionally with threat modelers, control engineers, IAM, SOC, and business owners; pragmatic approach to
remediation and risk acceptance.
- Strong organizational skills; ability to maintain and present consolidated evidence bundles and tracking for multiple concurrent services.
Outcomes & Deliverables
- Timely ISRP/ISO review reports and certification gate sign-off recommendations.
- Policy compliance checklists, gap analyses, and prioritized remediation/corrective action plans with owners and timelines.
- Audit-ready evidence bundles for each certified service (diagrams, test results, control artifacts).
- Documented residual risk decisions, accepted exceptions, and monitoring or remediation commitments.
- Regular status reports on certification progress, non-compliance items, and escalations.
Role Overview
As an ISO Analyst with deep cloud security and architecture expertise, you will validate solutions against enterprise security policy,
drive ISRP/ISO reviews for cloud services and enable certification readiness. You will work closely with threat modelers,
security controls engineers, cloud IAM engineers, architects, and business owners to assess residual risk, document compliance evidence,
and support certification gates across cloud-native deployments (GCP/AWS).
Key Responsibilities
- Perform ISRP/ISO reviews of cloud solutions from design through certification, validating adherence to enterprise security policies,
control specifications, and acceptance criteria.
- Assess cloud infrastructure and architecture (VPC/VNet, subnets, routing, NSGs, firewalls, EC2/GCE, S3/GCS, IAM, KMS/CMEK,
managed services) for policy compliance and residual risks.
- Verify implementation evidence for preventative, detective, and auto-remediation controls produced by security controls engineers and
threat modelers.
- Map solution controls and risks to compliance and risk frameworks (NIST CSF/800-53, ISO/IEC 27001, relevant regulatory requirements)
and produce gap analyses.
- Drive residual risk decisions and coordinate risk exception or corrective action plans with business owners, CSP/vendor representatives,
and risk & control functions.
- Prepare and maintain audit-ready documentation: review reports, policy checklists, evidence bundles, sign-off forms, and remediation tracking.
- Liaise with onboarding and training leads to ensure external consultants meet required entitlements and threat-modeling certifications prior to
productive work.
- Participate in stakeholder reviews and certification gate meetings; provide formal sign-off recommendations.
- Track and report certification progress, outstanding non-compliance items, remediation timelines, and escalations.
Salary Range- $100,000-$125,000 a year
#LI-CO1
#LI-SN1