ISMS And ISO 27001 Security Process Specialist

Damen

Abu Dhabi

On-site

AED 180,000 - 280,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Damen Shipyards Group seeks an ISMS & Security Process Specialist to lead the implementation of ISO/IEC 27001:2022, document governance, and drive audit readiness across the organization. You’ll collaborate with CISO, process owners, and IT teams to embed structured security processes in daily operations.

This role focuses on transforming existing controls into auditable processes, maintaining evidence, and enabling scalable security management within Damen's global operations using BPM

Qualifications

  • 4-7 years of experience in Information Security, ISMS, IT Governance, GRC, ITSM, Quality Management, or Process Management
  • Experience implementing or maintaining an ISO/IEC 27001:2022–compliant management system
  • Experience documenting processes, controls, procedures, and governance frameworks
  • Experience supporting internal audits, certification audits, or compliance assessments
  • Experience working within complex international organizations
  • Experience with BPM or process management tools such as Mavim, ARIS, Signavio, Visio, or similar platforms

Responsibilities

  • Build and maintain the ISMS aligned with ISO/IEC 27001:2022
  • Create policies, procedures, standards, registers, and governance documentation
  • Establish traceability between risks, controls, owners, processes, and evidence
  • Support maintenance of the Information Security Risk Register and SoA
  • Build governance structures that support certification readiness
  • Identify and document security, IT, and governance processes across the organization
  • Interview stakeholders to understand how controls operate in practice
  • Translate operational activities into auditable and repeatable processes
  • Map practices against ISO/IEC 27001:2022 clauses and Annex A controls
  • Support control owners in documenting controls and evidence requirements
  • Track remediation activities through to completion
  • Build and maintain security processes within Damen's Mavim platform
  • Maintain process ownership, version control, and review cycles
  • Drive continuous improvement of the management system
  • Establish and maintain ISMS evidence repository
  • Coordinate collection and validation of audit evidence
  • Ensure evidence remains current and accessible
  • Support internal and external audits and management reviews
  • Track findings and corrective actions

Skills

Stakeholder engagement
Documentation
Analytical thinking
Detail-oriented

Tools

Mavim
ARIS
Signavio
Visio
ServiceNow

Job description

Job Description:

We offer you an Ocean of Possibilities. Join our family.

ISMS & ISO 27001 Security Process Specialist

Location: DMESS, Abu Dhabi, UAE

Department: Cyber Security/ Group IT

Employment Type: Full-Time

Shape the Future of Data & AI at Damen

At Damen Shipyards Group, we are strengthening our Information Security Management System (ISMS) and advancing our journey toward ISO/IEC 27001:2022 certification readiness. To support this strategic objective, we are looking for a hands-on ISMS & Security Process Specialist who will help build, structure, document, and operationalize our security management framework across the organization.

This is not a role focused solely on compliance administration or policy maintenance.

We are looking for someone who can take existing processes, controls, and ways of working and transform them into a structured, auditable, and sustainable Information Security Management System. You will work alongside the Group CISO and key stakeholders to establish the documentation, process architecture, evidence management, and governance foundations required to support ISO/IEC 27001:2022 compliance and certification readiness.

This is a unique opportunity to influence security maturity across a global maritime leader while helping to create a management system that is practical, scalable, and embedded into day-to-day operations.

The Role

As an ISMS & Security Process Specialist, you will act as the operational driver behind Damen's ISO/IEC 27001:2022 implementation efforts. You will identify existing security and IT processes, document them, formalize control activities, establish traceability between risks and controls, and ensure evidence can be consistently produced for audits and certification activities.

You will work closely with Process Owners, Control Owners, IT Service Owners, Quality Management teams, Security stakeholders, and business functions across the organization. Success in this role requires strong process documentation skills, practical ISO 27001 knowledge, attention to detail, and the ability to transform fragmented information into a structured and auditable management system.

Key Responsibilities
Build & Maintain the ISMS
  • Develop and maintain the Information Security Management System aligned with ISO/IEC 27001:2022
  • Create policies, procedures, standards, registers, and governance documentation
  • Establish traceability between risks, controls, owners, processes, and evidence
  • Support maintenance of the Information Security Risk Register and Statement of Applicability (SoA)
  • Build sustainable governance structures that support certification readiness
Document & Formalize Processes
  • Identify existing security, IT, and governance processes across the organization
  • Interview stakeholders to understand how controls operate in practice
  • Create process flows, control descriptions, workflows, and supporting documentation
  • Translate operational activities into auditable and repeatable processes
  • Identify and remediate documentation and process gaps
Support ISO/IEC 27001 Compliance
  • Map existing practices against ISO/IEC 27001:2022 clauses and Annex A controls
  • Perform compliance and gap assessments
  • Define actions required to address identified deficiencies
  • Support control owners in documenting controls and evidence requirements
  • Track remediation activities through to completion
Develop the Security Management System
  • Build and maintain security processes within Damen's Mavim platform
  • Structure relationships between controls, risks, evidence, systems, and stakeholders
  • Ensure information security requirements are embedded into business processes
  • Maintain process ownership, version control, and review cycles
  • Support continuous improvement of the management system
Manage Evidence & Audit Readiness
  • Establish and maintain the ISMS evidence repository
  • Coordinate the collection and validation of audit evidence
  • Ensure evidence remains current, complete, and accessible
  • Support internal audits, certification audits, and management reviews
  • Track findings, corrective actions, and improvement initiatives
Drive Continuous Improvement
  • Promote best practices in security governance and process management
  • Support stakeholders in adopting structured and sustainable controls
  • Facilitate workshops and working sessions across the business
  • Translate ISO requirements into practical business guidance
  • Improve ISMS maturity, audit readiness, and process effectiveness
Experience
What We're Looking For
  • 4-7 years of experience in Information Security, ISMS, IT Governance, GRC, IT Service Management, Quality Management, or Process Management
  • Practical experience implementing or maintaining an ISO/IEC 27001-compliant management system
  • Experience documenting processes, controls, procedures, and governance frameworks
  • Experience supporting internal audits, certification audits, or compliance assessments
  • Experience working within complex international organizations
  • Experience with BPM or process management tools such as Mavim, ARIS, Signavio, Visio, or similar platforms
Technical Expertise
  • ISO/IEC 27001:2022 Framework
  • Information Security Management Systems (ISMS)
  • Risk and Control Management
  • Governance, Risk & Compliance (GRC)
  • Process Documentation and Process Modelling
  • Audit and Evidence Management
  • IT Service Management (ITIL)
  • Mavim, ARIS, Signavio, Visio, or equivalent BPM solutions
  • ServiceNow or similar governance platforms
  • Data Governance and Data Stewardship concepts
Personal Attributes
  • Structured and highly organized
  • Excellent documentation and analytical skills
  • Strong stakeholder engagement abilities
  • Detail-oriented with a focus on quality and compliance
  • Pragmatic and solution-oriented
  • Comfortable working independently and across organizational boundaries
  • Able to challenge existing practices constructively
  • Passionate about building sustainable security processes and management systems
Why Join Damen?

At Damen, you will play a key role in strengthening information security across a global maritime leader. You will work directly with senior security leadership and stakeholders across multiple countries and business functions, helping to establish the foundations required for long-term security governance and ISO/IEC 27001 certification readiness.

This role offers the opportunity to create lasting organizational impact by building a structured, auditable, and scalable security management system that supports both operational excellence and regulatory compliance. You will be part of an international environment that values ownership, continuous improvement, collaboration, and professional growth.

Ideal Candidate Profile

The ideal candidate is currently working as an ISMS Specialist, Information Security Analyst, ISO 27001 Consultant, Security Governance Analyst, GRC Specialist, Security Compliance Specialist, IT Governance Consultant, or Information Security Officer and has hands-on experience building, documenting, and operationalizing security management systems.

This individual understands how to convert policies, controls, and operational practices into a sustainable ISO/IEC 27001:2022-aligned management system and thrives in environments where structure, compliance, and continuous improvement are critical to success.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

ISMS & ISO 27001 Security Process Specialist
ISMS & ISO 27001 Security Process Specialist

Damen • Abu Dhabi

On-site
AED 180,000 - 280,000
ISMS & ISO 27001 Security Process Specialist
ISMS & ISO 27001 Security Process Specialist

Damen Schelde Naval Shipbuilding • Abu Dhabi

On-site
AED 279,000 - 469,000
null
ISMS & ISO 27001 Security Process Specialist
ISMS & ISO 27001 Security Process Specialist

963 Damen Middle East Shared Services Limited • Abu Dhabi

On-site
AED 200,000 - 360,000
ISMS & ISO 27001 Architect: Build Scalable Security
ISMS & ISO 27001 Architect: Build Scalable Security

Damen • Abu Dhabi

On-site
AED 180,000 - 280,000
ISMS & ISO 27001 Architect — Security Process Excellence
ISMS & ISO 27001 Architect — Security Process Excellence

Damen • Abu Dhabi

On-site
AED 180,000 - 280,000
ISO 27001 ISMS Architect & Process Lead
ISO 27001 ISMS Architect & Process Lead

963 Damen Middle East Shared Services Limited • Abu Dhabi

On-site
AED 200,000 - 360,000
ISO 27001 ISMS Architect & Process Lead
ISO 27001 ISMS Architect & Process Lead

Damen Schelde Naval Shipbuilding • Abu Dhabi

On-site
AED 279,000 - 469,000
null
QHSES Assurance Specialist - Quality Systems
QHSES Assurance Specialist - Quality Systems

Mc Dermott • Dubai

On-site
AED 167,400 - 256,680
Data Transformation & Change Manager
Data Transformation & Change Manager

Damen Schelde Naval Shipbuilding • Abu Dhabi

On-site
AED 350,000 - 550,000
Sr Information Security Governance & Assurance Manager
Sr Information Security Governance & Assurance Manager

Client of Michael Page • United Arab Emirates

On-site
AED 350,000 - 520,000