Job Summary
We are seeking an experienced and detail-oriented ISMS & SOC Documentation Specialist to support Information Security Governance, SOC compliance activities, and cybersecurity audit operations. The ideal candidate should possess strong expertise in ISMS documentation, SOC audit coordination, cyber resilience exercises, and operational security process documentation.
The role requires hands-on experience in preparing and maintaining security playbooks, policies, procedures, process documents, RACI matrices, incident response documentation, and conducting audit-related activities including tabletop exercises, cyber drills, BCP, and DR activities.
Key Responsibilities
ISMS & Governance
- Develop, maintain, and manage ISMS documentation aligned with industry standards such as ISO 27001, SOC 2, NIST, CIS, etc.
- Prepare and review:
- Information Security Policies
- SOPs (Standard Operating Procedures)
- Processes & Procedures
- Security Playbooks
- Runbooks
- Guidelines and Standards
- Maintain document version control and governance records.
- Support implementation and continual improvement of ISMS frameworks.
SOC Audit & Compliance
- Coordinate and support SOC audits, internal audits, external audits, and compliance assessments.
- Collect, organize, and validate audit evidence and documentation.
- Work closely with SOC teams, IT teams, and auditors during audit engagements.
- Track audit observations, remediation plans, and closure activities.
Cybersecurity Exercises & Resilience Activities
- Plan and conduct:
- Tabletop Exercises
- Cyber Drills
- Incident Simulation Exercises
- Business Continuity Planning (BCP) activities
- Disaster Recovery (DR) exercises
- Prepare post-exercise reports, gap analysis, and improvement recommendations.
- Ensure alignment of response procedures with organizational cyber resilience objectives.
Documentation & Operational Readiness
- Prepare and maintain:
- Incident Response Plans
- Cyber Incident Response Team (CIRT/CIRIT) documentation
- Escalation matrices
- RACI matrices
- Communication plans
- Risk registers
- Create documentation for SOC operational workflows and security monitoring procedures.
- Ensure documentation complies with audit and regulatory requirements.
Coordination & Reporting
- Coordinate with cross-functional stakeholders including SOC, IT, Risk, Compliance, and Business teams.
- Prepare management reports, compliance dashboards, and audit status updates.
- Support risk assessments and control reviews.
Required Skills & Qualifications
Mandatory Skills
- 4–6 years of experience in Information Security, ISMS, SOC Governance, Audit, or Cybersecurity Documentation.
- Strong understanding of:
- ISO 27001
- SOC Audit processes
- NIST Framework
- CIS Controls
- BCP & DR processes
- Incident Response lifecycle
- Hands-on experience in:
- Tabletop Exercises
- Cyber Drills
- Audit coordination
- Security documentation management
- Strong expertise in preparing:
- Playbooks
- Policies
- SOPs
- Procedures
- RACI matrices
- CIRT/CIRIT documentation
- Excellent technical writing and documentation skills.
- Strong analytical, coordination, and communication skills.
- Experience working in SOC environments or cybersecurity operations teams.
- Familiarity with governance and compliance tools.
Key Competencies
- Audit Management
- Cybersecurity Governance
- Documentation Excellence
- Stakeholder Coordination
- Risk & Compliance Awareness
- Attention to Detail
- Incident Management Understanding
- Business Continuity & Disaster Recovery Planning
Nice to Have
- Experience with regulatory compliance frameworks.
- Exposure to SIEM/SOC operations.
- Knowledge of threat management and incident handling processes.
- Experience in enterprise cybersecurity environments.