
Cerrado
Publicado
Pagado a la entrega
Context We’re a global SaaS in identity/signature/2FA. The company and product are starting from scratch, yet we already have a solid technical baseline (AWS/EKS/Terraform/GitHub) and several freelancers engaged (infra, security, compliance). We want to implement a practical, audit-ready ISMS integrated with our DevOps, with a preference for online/remote certification. Experience working with Certification Bodies (CBs) and remote audits is highly valued. Objective Make us ready for ISO/IEC 27001:2022 certification (Stage 1/Stage 2) with live processes and objective evidence. No infrastructure redesign: your work is to integrate controls/evidence over what’s already built. Include mappings to ISO 27017/27018 and alignment with ISO 27701 where appropriate. Scope & milestones (with acceptance criteria) H1) GAP, Scope, Context, RACI and ISMS Plan – Deliverables: GAP report; ISMS scope; context/stakeholders; RACI; master ISMS plan. – Acceptance: approved scope and plan; prioritized backlog. H2) Risk Management + SoA (Annex A:2022, 93 controls) – Deliverables: risk methodology and risk register; Statement of Applicability (SoA). – Acceptance: prioritized risks with treatment plan; SoA published. H3) Core Policies & Procedures (bundled by A.5/A.6/A.7/A.8) – Deliverables: policies/SOPs for incident management, change management (linked to CI/CD), IAM, information classification/handling, asset management, suppliers/third parties, logging/retention (CloudTrail/GuardDuty), backup/restore, vulnerability/patching, cryptography (KMS/HSM), secure development. – Acceptance: documents approved, coded, and in use. H4) Runbooks and Airtable Evidence Board – Deliverables: operational runbooks; master register in Airtable with UC-XXX → S3/Git URL + owner + date + commit SHA; auditor views. – Acceptance: live, traceable board; evidence uploaded. H5) Initial ISMS Operation – Deliverables: awareness/training plan; KPIs/KRIs; first operation records (incidents, changes, access reviews, backups, etc.). – Acceptance: KPIs tracked; regular evidence captured. H6) Internal Audit + NC/CAPA + Management Review – Deliverables: internal audit program and report; corrective actions plan; Management Review minutes. – Acceptance: critical findings closed; Management Review issued. H7) Readiness Pack & Stage 1 Support – Deliverables: ISO 27001 ↔ UC-XXX traceability matrix; evidence list with S3/Git paths; pre-cert guidance and remote audit support. – Acceptance: pack validated with our team. General acceptance criteria – Every control maps to objective evidence (UC-XXX → S3/Git URL + owner + date + commit SHA). – Documents coded TYPE-AREA-SUBAREA-№SEC, with status and revision (REV A/B/0/1…). – No destructive changes or infra redesign without RFC/ADR and approval. – Weekly status (RAG), risks and dependencies tracked. Requirements (must-have) – ISO/IEC 27001:2022 Lead Implementer and/or Lead Auditor (verifiable). – Proven ISMS implementations in SaaS/DevOps, integrating with CI/CD (GitHub Actions). – Practical knowledge of AWS/EKS/Terraform, KMS/HSM, and technical evidence (logs, backups, changes). – Experience coordinating with Certification Bodies and remote/online audits. – Professional English (Spanish is a plus). NDA required. Nice to have – ISO 27701, ISO 27017/27018, SOC 2, ENS (Spain), ISO 22301, ISO 9001. – Integrated matrices (security/privacy/quality). – CloudHSM/FIPS 140-3 experience. Out of scope – Redesigning infrastructure or developing product features. – Structural changes without PM and Security/Infra approval. – Substantive legal advice (we have Legal/DPO). Tools & ways of working – Airtable (controls/evidence register), Jira/Confluence, GitHub, S3, Slack. – Remote, milestone-based, coordination with our PM (20h/week) and other specialists. – Weekly cadence; preferred time zone CET/CEST (Europe/Madrid). – We aim to complete ISO 27001 certification online/remotely where feasible. Note We’re a new company with a significant part of the core infrastructure already built and multiple freelancers in motion. The pace is high and the environment dynamic; we need someone ready to lead from day one with maximum traceability and minimal overhead.
ID del proyecto: 39753269
14 propuestas
Proyecto remoto
Activo hace 9 meses
Fija tu plazo y presupuesto
Cobra por tu trabajo
Describe tu propuesta
Es gratis registrarse y presentar ofertas en los trabajos
14 freelancers están ofertando un promedio de $1.061 USD por este trabajo

Hi , I have 15 year of experience in iso 27001 standard. I have done more than 100 companies worldwide. More info you can check my profile in freelancer
$1.125 USD en 7 días
6,0
6,0

Hello Dear! I write to introduce myself. I'm Engineer Toriqul Islam. I was born and grew up in Bangladesh. I speak and write in English like native people. I am a B.S.C. Engineer of Computer Science & Engineering. I completed my graduation from Rajshahi University of Engineering & Technology ( RUET). I love to work on Web Design & Development project. Web Design & development: I am a full-stack web developer with more than 10 years of experience. My design Approach is Always Modern and simple, which attracts people towards it. I have built websites for a wide variety of industries. I have worked with a lot of companies and built astonishing websites. All Clients have good reviews about me. Client Satisfaction is my first Priority. Technologies We Use: Custom Websites Development Using ======>Full Stack Development. 1. HTML5 2. CSS3 3. Bootstrap4 4. jQuery 5. JavaScript 6. Angular JS 7. React JS 8. Node JS 9. WordPress 10. PHP 11. Ruby on Rails 12. MYSQL 13. Laravel 14. .Net 15. CodeIgniter 16. React Native 17. SQL / MySQL 18. Mobile app development 19. Python 20. MongoDB What you'll get? • Fully Responsive Website on All Devices • Reusable Components • Quick response • Clean, tested and documented code • Completely met deadlines and requirements • Clear communication You are cordially welcome to discuss your project. Thank You! Best Regards, Toriqul Islam
$750 USD en 10 días
3,5
3,5

Hey, I can help turn your existing systems and processes into a fully operational, audit-ready Information Security Management System (ISMS) aligned with standards. My approach ensures minimal disruption while integrating security practices directly into your current workflows supported by real-time evidence and traceable documentation. My process begins with a GAP analysis, scope definition, and a clear ISMS implementation plan. From there, I’ll develop your risk management framework, Statement of Applicability (SoA), and structured documentation for core policies, procedures, and operational controls. All evidence will be recorded and managed in a centralized register for audit readiness. With experience working across cloud environments, DevOps teams, and compliance-driven projects, I focus on delivering streamlined documentation, operational runbooks, and metrics that prove ongoing control effectiveness. I’ve successfully supported remote audits, built certification packs, and aligned practices with industry standards . I offer a complete rollout including training plans, awareness programs, internal audit readiness, and performance tracking designed to meet your timelines and certification objectives. I promise clarity, structure, and full traceability at every step of the process! Warm regards, Arwa M
$750 USD en 2 días
2,7
2,7

Saludos estimados, me interesa el proyecto. Estas son las razones por las que puede ser el candidato: Amplia experiencia: he desarrollado normativas de ciberseguridad para diversos sectores y he trabajado como auditor y consultor en proyectos que siguen marcos como NIST CSF, NIST, PCI DSS e ISO 27001. Líder certificado: soy implementador líder certificado en ISO 27001, capaz de dirigir y gestionar proyectos de seguridad de la información. Desarrollo de políticas: Amplia experiencia en la creación de políticas y procedimientos, incluyendo la continuidad del negocio, la recuperación ante desastres y la seguridad de los datos. Función de CISO virtual: Puedo desempeñar la función de CISO virtual, realizando evaluaciones iniciales, desarrollando planes de acción y proporcionando informes finales sobre los niveles de seguridad. Enfoque propuesto: Evaluación inicial: Evaluar la situación actual en su SGSI. Plan de acción: desarrollar un plan para abordar las deficiencias y mejorar la seguridad. Creación de políticas, configuraciones, diagramas, entre otros, que sean requeridas. Defensa en las auditorías: participación y defensa con los auditores de ISO. Adicionalmente, he apoyado a más de tres organizaciones en la obtención de la certificación ISO 27001:22. Espero poder discutir cómo mis habilidades se ajustan a sus necesidades y contribuir al éxito de su auditoría de seguridad.
$1.125 USD en 20 días
2,5
2,5

My name is Rabia Faisal, I am working in the writing industry since 2011. During this time, I have served countless clients with a full amount of satisfaction by providing them with TOP Quality Solutions. I have command of all references APA, Harvard, IEEE, MLA & Chicago, etc. I will provide plagiarism-free work with 100 percent accurate grammar within your given deadline. Please message me to get Top Class Services. I am waiting; https://www.freelancer.com/u/TopWritingGuru
$750 USD en 1 día
2,2
2,2

Hola Felipe, He trabajado extensamente en implementaciones de ISMS para SaaS, integrando CI/CD y cumpliendo con ISO 27001. Estoy listo para liderar desde el primer día, asegurando máxima trazabilidad y efectividad con mínima carga administrativa. Mi experiencia reciente con auditorías remotas y cuerpos de certificación será valiosa para alcanzar la certificación de tu organización sin rediseñar la infraestructura existente. Me especializo en integrar controles prácticos y pruebas objetivas, alineando con ISO 27017/27018 y 27701 donde sea necesario. Estoy emocionado de colaborar contigo para lograr un sistema de gestión de la seguridad de la información listo para auditoría y completamente funcional. Gracias, Zeljko
$1.250 USD en 6 días
0,0
0,0

.─── ⚡⭐⋆☆⋆⭐⚡ ── Hello! Could you clarify if you already have risk criteria defined and which CI/CD workflows you want prioritized for control integration? I bring strong experience implementing ISO/IEC 27001:2022 ISMS in SaaS and cloud-native stacks (AWS/EKS/Terraform). A recurring challenge has been embedding controls into live DevOps pipelines while keeping them audit-ready—solved by creating evidence frameworks that map policies, SOPs, and artifacts (logs, commits, backups) directly to controls, with automation for evidence capture. For your project, I’d begin with a GAP analysis, defining scope, context, RACI, and an ISMS plan. Next: risk management, Statement of Applicability aligned with Annex A:2022 (and ISO 27017/27018/27701 if relevant), then operationalize key policies (incident, change, IAM, asset, supplier, logging, backup, patching, crypto, secure dev) integrated into CI/CD. I’d set up an Airtable evidence board with traceability (UC-XXX → S3/Git URL + owner + commit SHA), train the team, and establish KPIs/KRIs for continuous compliance. Internal audits, CAPA, and management reviews would prepare you for Stage 1 readiness and coordination with your Certification Body. I’d be excited to apply my ISO 27001 and DevOps expertise to deliver audit-ready compliance efficiently and sustainably.
$1.056,67 USD en 7 días
0,0
0,0

Hello I am an ISO/IEC 27001:2022 Lead Implementer & Lead Auditor with proven experience helping SaaS companies integrate audit-ready ISMS into AWS/DevOps environments without infrastructure redesign. I specialize in embedding controls directly into CI/CD workflows (GitHub Actions, Terraform, EKS) and mapping them with full traceability for Certification Bodies. I can support your project end-to-end: GAP analysis, risk management, SoA, policies, evidence boards, internal audit, and Stage 1/2 readiness, with alignment to ISO 27017/27018/27701 where applicable. My approach is practical, lightweight, and focused on delivering live processes with objective evidence. Looking forward to collaborating and ensuring a smooth, remote ISO 27001 certification for your company. Thanks!
$800 USD en 15 días
0,0
0,0

As a computer security expert with an extensive range of technical skills and an eye for detail, I believe I'm uniquely positioned to support your ISO/IEC 27001:2022 certification journey. Throughout my career, I've honed my abilities in risk management, policies and procedure creation, and evidentiary tracing - all of which align seamlessly with the tasks outlined in your project description. Moreover, my practical knowledge of AWS/EKS/Terraform, KMS/HSM, GitHub Actions makes me well-equipped to integrate control measures without the need for unnecessary infrastructure redesign. Beyond mere qualifications, one of my strengths is my adaptability to work with different stakeholders across multiple functions. My experience coordinating with Certification Bodies and overseeing remote audits will prove invaluable in navigating the unique challenges that online certifications might present. On top of that, my proficiency in English allows for clear communication and meticulous documentation, while also being able to read Spanish is an added bonus when it comes to compliance matters.
$750 USD en 1 día
0,0
0,0

Hi Felipe S., I understand your objective to implement an audit-ready ISMS integrated with your DevOps processes for ISO/IEC 27001:2022 certification. My experience in developing compliance frameworks in SaaS environments makes me a strong candidate for this role. I am Adil Yousuf, with over 6 years of experience in web security and compliance, including ISO9001 and ISO/IEC 27001:2022 implementation. I have successfully led ISMS projects, ensuring seamless integration with CI/CD pipelines like GitHub Actions. Furthermore, I possess practical knowledge of AWS and Terraform, which aligns well with your technical baseline. Here are some relevant examples of my work: https://www.freelancer.com/u/adily1 I am excited about the opportunity to collaborate and contribute to your project. Thank you and Regards, Adil Yousuf
$750 USD en 7 días
0,0
0,0

I’m an ISO/IEC 27001:2022 Lead Implementer & Auditor with proven experience delivering audit-ready ISMS programs for SaaS and DevOps organizations. I integrate ISO 27001 controls into existing AWS/EKS/Terraform environments without redesigns, using CI/CD pipelines and tools like GitHub, Airtable, and S3 for full evidence traceability. Key strengths: • End-to-end ISO 27001 delivery: GAP analysis to Stage 2 certification with remote audits and Certification Body coordination. • Technical expertise: AWS security (CloudTrail, GuardDuty, KMS/HSM), IAM, backup, and vulnerability management for real operational evidence. • Integrated frameworks: Mapping ISO 27001 to ISO 27017/27018, ISO 27701, and SOC 2 for unified compliance. • Practical, fast-paced approach: Policies, SOPs, runbooks, KPIs, and CAPAs delivered with minimal overhead and maximum automation. • Remote & multilingual: Experienced with distributed teams in CET/CEST time zones; fluent in English. I focus on traceable, automated compliance to meet certification goals quickly and efficiently.
$1.000 USD en 30 días
0,0
0,0

Buenas tardes, Soy Auditora Líder ISO/IEC 27001:2022 y Consultora en Seguridad de la Información, con experiencia en implementación y auditoría de sistemas de gestión en Latinoamérica (Colombia y Ecuador). He participado en proyectos de ISO 27001 e ISO 22301, apoyando a las organizaciones en la preparación para auditorías con organismos de certificación, incluyendo auditorías remotas. Cuento con conocimiento de ISO 27017, ISO 27018 e ISO 27701, y sé cómo alinear los requisitos de SOC 2 con ISO 27001 para fortalecer el cumplimiento. También he trabajado en proyectos de desarrollo seguro, apoyando la integración de controles en el ciclo de vida del software conforme a estándares internacionales. Estoy segura de que mis certificaciones, mi enfoque práctico y mi experiencia serán un aporte clave para lograr con éxito la certificación ISO/IEC 27001:2022. Saludos Cordiales
$1.125 USD en 10 días
0,0
0,0

Vitacuta, Chile
Forma de pago verificada
Miembro desde jun 22, 2020
$250-750 USD
$30-250 USD
$10-30 USD
$30-250 USD
$30-250 USD
₹600-1500 INR
$750-1500 USD
₹2000-3500 INR
$1500-3000 AUD
₹1500-12500 INR
$250-750 USD
$25-50 AUD /hora
$10-30 USD
$10-30 USD
$30-250 SGD
$50-70 USD
₹1500-12500 INR
€1500-3000 EUR
₹5000-8000 INR
$1500-3000 AUD
$250-750 USD
₹750-1250 INR /hora
£20-250 GBP
$750-1500 AUD
₹750-1250 INR /hora