Hopp til innhold

We are seeking a Information Management Consultant

Arbeidsgiver

Folk AS

Sted

1366 Lysaker

Om jobben

Stillingstittel
3708 - Information Management Consultant
Type ansettelse
Prosjekt, heltid 100%
Antall stillinger
1
Arbeidsspråk
Engelsk

Søk på jobben

Frist: We are evaluating candidates continuously!

We are seeking a Information Management Consultant!

 

Responsibilities:
  • Own and drive ISO 27001 and SOC 2 compliance activities end-to-end: gap assessments, control implementation, evidence collection, and audit readiness
  • Maintain the Information Security Management System (ISMS): policies, risk register, treatment plans, and control documentation
  • Lead internal audits and management reviews; prepare the team and evidence base for external certification and surveillance audits
  • Serve as the primary point of contact for external auditors and certification bodies: managing scope, scheduling, walkthroughs, and findings responses
  • Coordinate with developers, DevOps, and product teams to ensure security controls are implemented and verifiable in the Azure-hosted SaaS environment
  • Triage and track SAST/DAST findings and vulnerability reports; drive remediation to closure with the engineering team
  • Monitor and respond to security incidents; maintain and test incident response procedures
  • Conduct regular risk assessments and translate findings into concrete, actionable remediation work
  • Keep security policies and procedures current and aligned with evolving standards and business needs
  • Provide practical security guidance to developers and other team members: security by education, not just enforcement
  • Track relevant regulatory and compliance changes (ISO, SOC 2, GDPR where applicable) and assess their impact on the team

 

Qualifications:
  • 5+ years of hands-on experience in information security, with direct ownership of ISO 27001 programs through full audit cycles
  • Proven track record of leading compliance
  • Strong understanding of cloud security in Azure (IAM, networking, logging, encryption, security tooling)
  • Familiar with SAST/DAST tooling and the software development lifecycle in agile teams
  • Able to translate compliance requirements into practical engineering tasks and work directly with developers to get them done
  • Strong written and verbal communicator, comfortable producing audit-ready documentation and presenting to auditors, management, and customers


Nice to have:

  • Relevant certifications: ISO 27001 Lead Implementer/Auditor, CISSP, CISM, or equivalent
  • Experience securing SaaS products across web and mobile (iOS/Android)
  • Familiarity with GDPR compliance requirements in a European operating context
  • Experience with Azure security tooling: Defender for Cloud, Sentinel, or equivalent

 

Please upload diploma and transcripts with your application.


Folk can offer:

  • Good long-term opportunities with our clients
  • Individual and adapted follow-up while on assignment
  • Good career development opportunities in an interesting and innovative sector
  • Competitive terms and conditions
  • Social events and pleasant tokens of appreciation throughout the year


We see possibilities in your competence!
In Folk, we work in accordance with our values: ethical, personal, enthusiastic and flexible.

Kontaktperson for stillingen

Thomas Aase

Rådgiver

+4791327405

thomas@folkas.com

Om bedriften

Since the establishment in 2004, Folk AS has assisted Norwegian and international companies by selecting and recruiting skilled people within technical and administrative disciplines – for project-based, temporary and permanent positions 
This is what we are good at – here lies our expertise.
Our values are: ethical, personal, committed and flexible.

Sektor

Privat

Del annonsen

Annonsedata

Rapporter annonse
Stillingsnummer

9d225a5d-b912-4aaf-b19c-c5deccda5023

Sist endret

11. mai 2026

Hentet fra

recman

Referanse

476600

Lignende annonser

Laster lignende annonser