Cyber Security Architect – ISO/IEC 27001 & GRC Specialist
Quess Lanka · Colombo
Job description
About the role
We are seeking a mature, proactive Cyber Security Architect to lead and own our information security, governance, risk and compliance (GRC) initiatives. The role operates independently as an individual contributor, ensuring security, compliance, and audit activities are executed with minimal supervision.
Key responsibilities
- Manage and support cyber security initiatives aligned with ISO/IEC 27001:2022 and internal security requirements.
- Handle GRC activities, including risk management, control assessments, compliance monitoring, and remediation tracking.
- Prepare evidence for internal and external audits, address findings, and coordinate remediation.
- Lead incident response: investigation, documentation, escalation, root‑cause analysis, and corrective actions.
- Support SOX compliance and related IT controls and governance.
- Assess and monitor cloud security across AWS, Microsoft Azure, and Google Cloud platforms.
- Implement and maintain privacy and data‑protection controls.
- Conduct security risk assessments, identify control gaps, and recommend mitigations.
- Maintain and improve ISMS documentation, policies, procedures, standards, and controls.
- Coordinate with technical teams and stakeholders to ensure effective implementation of security and compliance requirements.
- Stay current on emerging threats, regulatory changes, industry standards, and best practices.
Required profile
- 8+ years of relevant cyber security experience (10 years total professional experience preferred).
- Strong practical experience across technical security, GRC, ISO/IEC 27001, incident management, risk management, and audit processes.
- Hands‑on knowledge of ISO/IEC 27001:2022 implementation.
- Good understanding of SOX, SOC, internal audit, privacy, and cloud security requirements.
- Ability to work independently with minimal supervision.
- Excellent analytical, problem‑solving, documentation, communication, and stakeholder‑management skills.
- Mature, professional approach to handling sensitive security and compliance matters.
Required skills
- ISO/IEC 27001:2022
- Governance, Risk & Compliance (GRC) frameworks
- SOX compliance
- Incident management
- Risk management
- Audit coordination (internal & external)
- Cloud security – AWS, Microsoft Azure, Google Cloud
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Sri Lanka.
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 1 month ago
Expires 3 weeks from now
41 views · 1 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Quess Lanka
Colombo
Related job offers
-
Junior ERP Consultant - Service & Maintenance
Inivos Colombo -
Lead Generative AI Engineer & Architect
GSS HR Solutions Private Limted Colombo -
Lead Gen AI Architect
GSS HR Solutions Private Limted Colombo -
AI Context Engineer
Efimind -
Senior Tech Lead
Intervest Software Technologies (Private) Limited Province de l'Ouest