
Closed
Posted
I need a seasoned cybersecurity professional to carry out ISO/IEC 27001:2022-aligned internal audits for my clients. Each engagement is focused squarely on security risk assessment, so I am looking for someone who can dive deep into threats, vulnerabilities, and controls and translate their findings into clear, actionable guidance. To be considered you must hold: • CISSP, CISM or CRISC, and • An IRCA, PECB, or Exemplar Global ISO/IEC 27001:2022 Lead Auditor credential. A minimum of five years of ISMS auditing experience is essential. Prior work in Muslim-majority countries is strongly preferred, as many of my clients are based [login to view URL] is associated to this work. You will work from client location for a short term coordinating with client teams via secure collaboration tools and delivering a concise, evidence-based audit report for each assignment. Your report must map findings to ISO 27001 clauses and annex controls, rate the associated risks, and recommend remediation steps that prepare the organisation for external certification. You will be also doing Threat modelling based on STRIDE and or MITRE ATT&CK framework. Deliverables for every audit • Audit plan defining scope, objectives, and sampling • Completed checklist with objective evidence captured • Comprehensive audit report ranking findings by likelihood and impact • Executive-level summary slide deck Acceptance criteria • All reports must conform to ISO/IEC 27001:2022 guidance. • Final documentation is due within five business days after fieldwork ends. Please attach proof of certifications and a brief summary of three comparable audits you have led in the last five years, along with your typical turnaround time for the deliverables noted above. I look forward to working with the right expert.
Project ID: 40508574
1 proposal
Remote project
Active 4 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
1 freelancer is bidding on average ₹1,875 INR/hour for this job

Vijay – ISO 27001 Lead Auditor | CISSP | Cybersecurity Risk Specialist Credentials CISM (ISACA) ISO/IEC 27001:2022 Lead Auditor – exempler certified 15+ years in ISMS auditing, security risk assessment, and controls evaluation Three Comparable Engagements 1. Gulf-based Financial Services Firm (UAE, 2023) Led end-to-end internal audit for a regional bank preparing for ISO 27001:2022 certification. Conducted threat modelling using STRIDE, mapped 47 findings to Annex A controls, rated by likelihood/impact matrix. Client achieved Stage 2 certification with zero major nonconformities. 2. Telecom Operator – Southeast Asia (Malaysia, 2022) Scoped and executed ISMS audit across 3 business units. Delivered MITRE ATT&CK-aligned threat assessment covering network infrastructure and third-party access risks. Executive summary presented to CISO and board. Turnaround: 4 business days post-fieldwork. 3. Government IT Services – Jordan (2022) Internal audit for a public sector entity with strict data sovereignty requirements. Reviewed risk register, SoA, and incident response procedures. Identified 12 high-risk gaps in access control and supplier management. Full remediation roadmap delivered within deadline. Approach Per Engagement Audit plan with defined scope, sampling rationale, and objectives — shared before fieldwork Evidence-based checklist completed during fieldwork, clause by clause
₹1,875 INR in 40 days
0.0
0.0

Bengaluru, India
Member since Jun 12, 2026
₹150000-250000 INR
£18-36 GBP / hour
$30-250 USD
£250-750 GBP
$100-750 USD
₹600-1500 INR
₹750-1250 INR / hour
$250-750 USD
₹37500-75000 INR
$15-25 AUD / hour
$250-750 USD
$30-250 USD
$600-1500 USD
₹1250-2500 INR / hour
$30-250 USD
min $50 USD / hour
$10-30 USD
$250-750 USD
min $50 USD / hour
$250-750 USD