Sign in to auto-apply
Job Description
Information Management Consultant
Dovre Solutions is a trusted global provider of high-value project management services. We have over 30 years of experience as a global provider of project professionals and engineers for large investment projects within our Project Personnel business area.
Arbeidsoppgaver
Hands-on information security lead responsible for driving and maintaining ISO 27001 compliance across the team's SaaS products hosted on Azure. You'll own the day-to-day execution of security controls, lead internal and external audit engagements, coordinate across developers, DevOps, product, and management, and ensure compliance activities are embedded in how the team actually works, not treated as a separate audit exercise.
Responsibilities
- Own and drive ISO 27001 and SOC 2 compliance activities end-to-end: gap assessments, control implementation, evidence collection, and audit readiness.
- Maintain the Information Security Management System (ISMS): policies, risk register, treatment plans, and control documentation.
- Lead internal audits and management reviews; prepare the team and evidence base for external certification and surveillance audits.
- Serve as the primary point of contact for external auditors and certification bodies: managing scope, scheduling, walkthroughs, and findings responses.
- Coordinate with developers, DevOps, and product teams to ensure security controls are implemented and verifiable in the Azure-hosted SaaS environment.
- Triage and track SAST/DAST findings and vulnerability reports; drive remediation to closure with the engineering team.
- Monitor and respond to security incidents; maintain and test incident response procedures.
- Conduct regular risk assessments and translate findings into concrete, actionable remediation work.
- Keep security policies and procedures current and aligned with evolving standards and business needs.
- Provide practical security guidance to developers and other team members: security by education, not just enforcement.
- Track relevant regulatory and compliance changes (ISO, SOC 2, GDPR where applicable) and assess their impact on the team.
Requirements
- You must have 5+ years of hands-on experience in information security, with direct ownership of ISO 27001 programs through full audit cycles.
- You must possess a strong understanding of cloud security in Azure, including IAM, networking, logging, encryption, and security tooling.
- You must be familiar with SAST/DAST tooling and the software development lifecycle in agile teams.
- You must have the ability to translate compliance requirements into practical engineering tasks and work directly with developers.
- You must be a strong written and verbal communicator, comfortable producing audit-ready documentation and presenting to stakeholders.
Skills
ISO 27001 ComplianceSOC 2 ComplianceAzure SecurityInformation Security Management System (ISMS)Audit managementRisk assessmentAgile software development
Experience
senior
