· Maintain and continuously improve the ISMS documentation — policies, procedures, SOA (Statement of Applicability), risk treatment plans, and operational procedures aligned to ISO 27001:2022
· Plan and conduct the annual internal audit programme — schedule audits across all ISMS scope areas, conduct audits (or manage internal/external auditors), and produce findings with specific evidence
· Manage the ISO 27001 certification lifecycle — prepare for surveillance audits and recertification, coordinate with the certification body, manage audit logistics, and track NCR (non-conformity report) resolution
· Conduct and facilitate information security risk assessments using the organisation’s risk methodology — identify threats, assess likelihood and impact, and recommend risk treatment options
· Drive corrective and preventive actions (CAPA) to closure — track remediation progress, validate effectiveness, and escalate overdue items to the GRC Department Manager
· Manage the security policy review cycle — ensure all policies and procedures are reviewed at defined intervals, updated to reflect changes, and communicated to relevant stakeholders
· Support business units in understanding and implementing ISMS requirements — translate ISO 27001 controls into practical operational guidance
· Maintain the risk register and treatment plans — ensure risk assessments are current, treatment plans are progressing, and risk acceptance decisions are properly documented
· Produce ISMS performance metrics and management review inputs — control effectiveness, audit findings trends, risk posture changes, and improvement opportunities
· Coordinate with other compliance frameworks (PDPA, PCI-DSS) to identify synergies and reduce duplicate effort across compliance programmes