Lead Auditor

2 days ago

Muntinlupa, Metro Manila, Philippines COFORGE BPS PHILIPPINES, INC. Full-time

Job Title: Lead Internal Auditor – ISMS & BCMS

Experience: 7+ Years in Internal Auditing, Information Security, Business Continuity, Compliance, and Risk Management, with at least 3 years in a Lead Auditor or audit leadership capacity

Skills: ISO 27001, ISO 22301, Information Security Management Systems (ISMS), Business Continuity Management Systems (BCMS), Internal Auditing, Risk-Based Auditing, Governance, Compliance Management, Internal Controls Assessment, Root Cause Analysis, Corrective Action Management, Stakeholder Management, Audit Reporting, Team Leadership

Location: Alabang, Philippines

We at Coforge are hiring a Lead Internal Auditor – ISMS & BCMS with the following skillset:

Key Responsibilities

  • Lead and execute internal audits for Information Security Management Systems (ISO 27001) and Business Continuity Management Systems (ISO 22301).

  • Develop and maintain risk-based internal audit programs and annual audit schedules.

  • Evaluate compliance with ISO requirements, organizational policies, regulatory obligations, and client-specific controls.

  • Assess the effectiveness of information security controls, business continuity plans, governance frameworks, and risk management practices.

  • Review policies, procedures, records, evidence, and operational processes to validate compliance and control effectiveness.

  • Identify non-conformities, control gaps, compliance risks, observations, and opportunities for improvement.

  • Prepare, review, and approve audit findings, reports, and supporting documentation.

  • Conduct follow-up audits and validate the effectiveness of corrective and preventive actions (CAPA).

  • Provide timely audit status reports, escalation updates, and compliance dashboards to leadership.

  • Support external audits, surveillance audits, certification audits, and client reviews.

  • Ensure audit readiness across business functions and maintain compliance with established audit methodologies.

  • Partner with process owners and business stakeholders to strengthen governance, compliance, and risk controls.

  • Drive continuous improvement initiatives across audit, risk, compliance, information security, and business continuity programs.

  • Coach, mentor, and provide guidance to Senior Auditors and Auditors.

  • Maintain confidentiality, objectivity, and independence throughout the audit lifecycle.

  • Stay updated on ISO standards, industry regulations, audit methodologies, and emerging risks.

  • Perform other duties and responsibilities as assigned.

Qualifications

  • Bachelor's degree in Information Technology, Information Security, Risk Management, Engineering, Business Administration, or a related field.

  • At least 7 years of experience in Internal Audit, Compliance, Risk Management, Information Security, Governance, or Business Continuity.

  • Minimum of 3 years of experience leading audit programs, audit teams, or compliance engagements.

  • Strong experience conducting audits against ISO 27001 (ISMS) and ISO 22301 (BCMS).

  • Strong understanding of risk-based auditing principles, governance frameworks, compliance requirements, and internal controls.

  • Experience managing audit observations, remediation activities, and corrective action plans.

  • Excellent analytical, documentation, problem-solving, and reporting skills.

  • Strong communication, presentation, and stakeholder management capabilities.

  • Ability to influence stakeholders and drive compliance initiatives across multiple functions.

  • Knowledge of Information Security, Risk Management, and Business Continuity best practices.

  • Experience supporting certification audits and surveillance audits is highly preferred.

Mandatory Certifications

  • ISO 27001 Lead Auditor Certification

  • ISO 22301 Lead Auditor Certification

Preferred Certifications

  • CISA (Certified Information Systems Auditor)

  • CISSP (Certified Information Systems Security Professional)

  • CIA (Certified Internal Auditor)

  • CRMA (Certification in Risk Management Assurance)

  • ISO 31000 Risk Management Certification

  • ISO 9001 Lead Auditor Certification

Preferred Candidate Profile

We are looking for a highly analytical and detail-oriented audit professional with strong expertise in Information Security Management Systems (ISMS) and Business Continuity Management Systems (BCMS). The ideal candidate should be capable of l