ISO 27001 Information Security Auditor
About this role
We exist to create positive change for people and the planet. Join us and make a difference too!
Location: Germany
The base salary for this position starts from 56 000 Euro gross annually
Information Security Auditor
Are you passionate about information security and helping organizations build trust through internationally recognized standards? Do you enjoy working with a variety of clients and making a real impact on their information security management systems? If so, we'd like to hear from you.
As an Information Security Auditor, you will perform independent assessments against internationally recognized information security standards. You will work closely with clients to evaluate the effectiveness of their Information Security Management Systems (ISMS), provide valuable insights, and contribute to improving their security posture.
Key Responsibilities
- Prepare, plan, and conduct information security audits in accordance with applicable standards, accreditation requirements, and company procedures.
- Assess clients' Information Security Management Systems and produce clear, accurate, and professional audit reports.
- Present audit findings to clients, ensuring they understand the assessment outcome and any required corrective actions.
- Recommend the issuance, continuation, suspension, or withdrawal of certification in accordance with company policies and accreditation requirements.
- Deliver recommendations within prescribed quality standards and reporting timelines.
- Lead audit teams where required, ensuring effective planning, coordination, and delivery of audit activities.
- Maintain overall responsibility for assigned client accounts, building strong long-term relationships while ensuring excellent service delivery and identifying opportunities for account growth.
- Develop and maintain audit plans.
- Work closely with internal support teams to ensure client records, audit documentation, and certification information remain accurate and up to date.
- Plan and manage your own audit schedule to maximize efficiency, client satisfaction, and revenue-generating activities.
- Contribute to achieving annual operational, utilization, and financial performance targets.
- Stay current with developments in information security standards, regulations, and industry best practices.
What We're Looking For
- Solid professional experience in information security, with a good understanding of security governance, risk management and controls.
- Sound knowledge of relevant information security standards and frameworks, such as ISO/IEC 27001, BSI IT-Grundschutz, NIST CSF or COBIT.
- Previous audit or assessment experience is an advantage.
- Willingness to undertake further qualifications in related standards and assessment schemes, such as ISO 22301, ISO/IEC 20000-1, ISO 9001 or TISAX.
- Strong analytical and problem-solving skills, with the ability to understand complex environments and evaluate information security risks and controls.
- Excellent communication and stakeholder management skills, with the confidence to engage with both technical specialists and senior management.
- Strong organizational and planning skills, with the ability to independently manage multiple client engagements and priorities.
- Ability to build trusted client relationships and adapt effectively to diverse cultural environments in Germany and internationally.
- Comfortable working independently as well as collaborating with and, where appropriate, leading audit teams.
- Flexibility and willingness to travel to client locations when required (approximately 50% travel).
Language Skills Required
- German: Excellent proficiency, both written and spoken (CEFR C1 or above)
- English: Very good proficiency, both written and spoken (CEFR B2 or above)
What We Offer
- The opportunity to work with a diverse portfolio of clients across multiple industries.
- Continuous professional development and training.
- A collaborative and supportive international team environment.
- Career progression opportunities within a global certification and assurance organization.
- Competitive salary and benefits package.
If you're committed to helping organizations strengthen their information security while delivering exceptional client experiences, we'd love to welcome you to our team.
#LI- KW1
#LI-HYBRID
About Us
BSI is a business improvement and standards company and for over a century BSI has been recognized for having a positive impact on organizations and society, building trust and enhancing lives.
Today BSI partners with more than 77,500 clients in 195 countries and engages with a 15,000 strong global community of experts, industry and consumer groups, organizations and governments.
Utilizing its extensive expertise in key industry sectors - including automotive, aerospace, built environment, food and retail, and healthcare - BSI delivers on its purpose by helping its clients fulfil theirs.
Living by our core values of Client-Centricity, Agility, and Collaboration, BSI provides organizations with the confidence to grow by partnering with them to tackle society’s critical issues – from climate change to building trust in digital transformation and everything in between - to accelerate progress towards a better society and a sustainable world.
BSI is an Equal Opportunity Employer dedicated to fostering a diverse and inclusive workplace.
Company at a glance
We are a business improvement and standards company that partners with more than 77,500 clients globally across multiple industry sectors. BSI provides organizations with the confidence to grow by working with them to tackle society’s critical issues – from climate change to building trust in AI and everything in between - to accelerate progress towards a fair society and a sustainable world.
For over a century BSI has been recognized for having a positive impact on organizations and society, building trust and enhancing lives. Today BSI engages with a 15,000 strong global community of experts, industry and consumer groups, organizations and governments to deliver on its purpose by helping its clients fulfil theirs.
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?