Title: Senior IT Security Officer
Company Name: Indetechs Software Limited.
Vacancy: 1
Age: At least 30 years
Job Location: Anywhere in Bangladesh
Salary: Negotiable
Experience:
Bachelor’s degree in Cyber Security, Information Technology, Computer Science, Information Assurance, or equivalent experience.
Experience Requirements (Required)
• Experience in Information Security, GRC, risk management, or compliance roles.
• Hands-on experience with Drata or an equivalent GRC/compliance automation platform (Vanta, Secureframe, Sprinto) — including control monitoring, evidence management, and remediation of failing tests.
• Working knowledge of ISO/IEC 27001 audits — direct experience of implementation, internal audit, or certification/surveillance audits, including evidence preparation and liaising with external auditors.
• Strong knowledge of security risk assessment, vulnerability management, and security operations.
• Experience conducting or coordinating penetration testing and reviewing scan results.
• Familiarity with incident response processes and access management.
Professional Certifications (Preferred)
• ISO 27001 Lead Implementer (highly desirable) — for candidates with a Lead Auditor qualification, this is valued only for audit liaison and evidence preparation, given this role's operational (non-auditing) function.
• CISM, CISSP, CRISC, or equivalent security management/risk certification.
• UK GDPR/Data Protection certification, such as CIPP/E or CIPM (privacy program/operational focus). Full DPO-level qualifications are not required, as the DPO function is independent of this role.
• CEH, Security+, or similar technical security certification (advantageous, not essential, given this role coordinates rather than performs penetration testing).
• ITIL Foundation (added benefit).
Key Skills & Competencies
• Strong understanding of security governance, standards, frameworks, and controls.
• Ability to interpret and evaluate control evidence and risk documentation.
• Excellent communication skills with the ability to work across technical and non-technical teams, including external consultants and auditors.
• Strong analytical and problem-solving capabilities.
• Attention to detail and strong documentation skills.
• Ability to work independently and manage workloads in a dynamic environment.
About the Role
We are seeking a highly skilled Senior IT Security Officer to support the day-to-day management of the Information Security Management System (ISMS), regulatory compliance, and security governance.
This role is critical in ensuring the confidentiality, integrity, and availability of our information assets while maintaining compliance with ISO/IEC 27001:2022, UK GDPR, the Data Protection Act 2018, and internal security policies.
You will operate our Drata GRC platform, manage security risks, coordinate vulnerability testing, support incident response, contribute to access governance, and collaborate cross-functionally — working alongside our external vCISO/GRC partner under a clearly defined division of responsibilities. This is a hands-on and strategic role ideal for professionals passionate about security, governance, and continuous improvement.
Key Responsibilities
1. ISMS & Compliance Management (ISO/IEC 27001:2022, UK GDPR, TISAX, ISO 9001)
•Operate the Drata trust management platform, ensuring timely review of failing tests, findings, and KPIs, in coordination with the external GRC partner.
•Maintain audit-ready evidence in Drata for certification and annual surveillance audits.
•Support the implementation, maintenance, and continual improvement of the ISMS.
•Prepare, review, and maintain compliance documentation and audit evidence.
•Support UK GDPR and DPA 2018 compliance activities, supporting the Data Protection Officer (the DPO function remains independent of this role).
•Manage the operational relationship with the GRC platform (Drata) and coordinate with penetration testing vendors, including scheduling, scope confirmation, and remediation tracking within budget guidelines set by the CTO.
2. Security Risk & Asset Management
•Conduct and review information security risk assessments in line with the Risk Assessment Policy.
•Maintain and treat assigned risks as an Information Security Risk Owner.
•Ensure security controls are implemented and monitored across information assets.
•Lead or support periodic user access reviews.
•Support supplier and third-party risk assessments in line with ISO/IEC 27001:2022, including onboarding due diligence, contractual security requirements, and periodic supplier reviews.
3. Vulnerability Management & Penetration Testing
•Coordinate annual penetration tests (internal or external) and event-driven tests following major infrastructure changes.
•Review vulnerability scan results and work with IT and Engineering to remediate risks within policy timescales.
•Monitor emerging threats through advisories, bulletins, and intelligence feeds.
4. Access Control & Authorisation
•Review and endorse system and physical access requests based on least-privilege principles; privileged and restricted-data access requires a second approver (CTO or system owner) in line with segregation-of-duties requirements.
•Review BYOD and remote-working arrangements in line with the Mobile & Teleworking Policy and MDM (Microsoft Intune) enrolment requirements.
5. Incident Response & Security Operations Support
•Investigate and assess incidents, including suspected credential compromise, in accordance with the Incident Response Plan.
•Support security monitoring, detection, and response activities.
•Produce incident reports and ensure corrective actions are logged and tracked through the Continuous Improvement and Non-Conformity process.
6. Disaster Recovery & Business Continuity
•Maintain and update the Disaster Recovery (DR) Plan in collaboration with the Data Protection Officer and the IT Operations Officer.
•Define DR validation criteria, schedule tests, and ensure testing execution and evidence capture.
•Contribute to the wider Business Continuity Plan (BCP), including crisis communication procedures, beyond IT-specific disaster recovery.
7. Internal Audit & Governance
•Prepare evidence and act as auditee for internal and external (certification body) audits; this role does not audit controls it operates, preserving internal audit independence.
•Participate in ISO/IEC 27001 surveillance and recertification audit preparation and audit sessions with the certification body.
•Support governance reporting, metrics, management review inputs, and continuous improvement initiatives.