Save Job Back to Search Job Description Summary Similar Jobs6 Months ContractISO 27001 Insurance ProjectAbout Our ClientThis opportunity is with a well-established organization within the insurance industry with a strong presence, offering a collaborative and professional environment.Job DescriptionAs an IT Security Analyst, your main responsibilities will include:Governance, Risk & Compliance (GRC)Act as the main point of contact for internal and external IT/security auditsLead and support ISO 27001 certification, surveillance, and internal auditsOwn and maintain the Statement of Applicability (SoA)Prepare audit evidence, manage auditor queries, and coordinate responsesTrack, manage, and close audit findings and non-conformitiesMaintain and manage the risk register and perform formal risk assessmentsTranslate technical risks into business impact for stakeholdersDevelop and maintain security policies, procedures, and documentationDrive security awareness programs, including phishing simulationsAzure / Microsoft 365 SecurityReview and manage Microsoft 365 security controls, including:Defender for Office 365Intune (MDM / device compliance)Data Loss Prevention (DLP)Assess the effectiveness of security configurations implemented by external IT providersSupport security documentation and control validation for cloud environmentsSecurity Operations & OversightSupport incident response and investigationsProvide oversight of SOC provider performance and detection capabilitiesMonitor security risks and ensure remediation activities are tracked and completedThe Successful ApplicantA successful IT Security Analyst should have:Proven hands-on experience with ISO 27001 ISMSStrong audit experience:Certification, surveillance, and internal auditsEvidence preparation and audit responsesManaging non-conformities and remediation trackingExperience as audit owner / primary audit contactSolid experience with Microsoft 365 security controls (Defender, Intune, DLP)Experience in risk management, including risk assessments and register ownershipHands-on experience running security awareness and phishing simulation programsAbility to communicate technical risks to non-technical stakeholdersExperience with NIST CSF, SOC 2, or GDPR control mappingExposure to incident response and SOC vendor oversightBackground in insurance or regulated industriesRelevant certifications such as:CISA, CRISC, or CGEITAzure Security Engineer or M365 Security AdministratorCompTIA Security+5+ years of experience in information security, GRC, or audit rolesStrong communication and stakeholder management skillsDetail-oriented, proactive, and able to work independentlyComfortable working in a fast-paced, contract-based environmentWhat's on Offer If you are ready to contribute to IT security and compliance within the insurance industry, we encourage you to apply for this exciting opportunity.ContactAgnes ChowQuote job refJN-052026-7025861Phone number+852 25306125Job summaryFunctionITSpecialisationSecurityWhat is your area of specialisation?InsuranceLocationHong KongJob Type:TemporaryConsultant nameAgnes ChowConsultant phone+852 25306125Job ReferenceJN-052026-7025861