Job description
ISO 27001 LEAD AUDITOR Kerndell is looking to expand our network of experienced contract ISO 27001 Lead Auditors. In this role, you will work directly with clients across the energy, industrial, and technology sectors to help them evaluate and strengthen their information security management systems. Engagements may include ISO 27001 gap assessments, internal audits, supplier audits, and certification-readiness assessments.
We are looking for someone who understands ISO/IEC 27001:2022, knows how to lead a well-organized audit, and can clearly explain findings to everyone from technical teams to senior leadership. You will be responsible for planning and conducting assessments, documenting clear and evidence-based findings, and delivering reports that meet Kerndell’s quality standards.
You will also serve as a trusted representative of Kerndell and help clients understand what they are doing well, where gaps exist, and what they should address as they prepare for certification. This is a contract position based in Houston, Texas, with work assigned based on client needs, auditor availability, location, and experience.
Some engagements may be completed remotely, while others will require travel to client locations.
RESPONSIBILITIES
Current ISO/IEC 27001 Lead Auditor certification from a recognized organization, such as PECB, BSI, CQI/IRCA, or an equivalent provider. Bachelor’s degree in information technology, cybersecurity, computer science, engineering, or a related field. Relevant professional experience may be considered in place of a degree.
At least five years of experience in information security, ISMS implementation, cybersecurity compliance, IT auditing, or a related area. At least three years of direct ISO 27001 audit or assessment experience, including experience leading engagements. Strong working knowledge of ISO/IEC 27001:2022 requirements and Annex A controls.
Familiarity with ISO 19011 audit principles, including interviewing, sampling, evidence collection, and documenting findings. Working knowledge of at least one related framework or standard, such as NIST CSF, SOC 2, CIS Controls, NIS2, or ISO/IEC 27002. Ability to write clear, accurate, and professional assessment reports that require minimal editing.
Strong written and verbal communication skills. Ability to work independently, manage deadlines, and communicate professionally with clients.
Preferred qualifications
Lead Auditor certification in another management-system standard, such as ISO 9001, ISO 14001, or ISO 45001. Experience working in energy, oil and gas, utilities, manufacturing, industrial operations, or technology services. Familiarity with NIST Cybersecurity Framework, PCI DSS, SOC 2 Trust Services Criteria or other operational technology cybersecurity frameworks.
Experience conducting gap assessments, internal audits, supplier audits, or certification-readiness assessments. Previous consulting or professional-services experience. Experience helping organizations develop, implement, or improve an ISMS.
Requirements
Plan and lead ISO 27001 gap assessments, internal audits, and certification-readiness assessments. Review ISMS documentation, including the organization’s scope, risk assessment, Statement of Applicability, policies, procedures, and supporting records. Develop practical audit plans, interview schedules, checklists, and sampling approaches based on the client’s organization and ISMS scope.
Lead opening and closing meetings and keep client personnel informed throughout the engagement. Conduct interviews, review documents and records, observe processes, and evaluate other forms of objective evidence. Evaluate the organization’s alignment with ISO/IEC 27001:2022 requirements and applicable Annex A controls.
Clearly document nonconformities, gaps, observations, strengths, and opportunities for improvement. Prepare professional reports that clearly explain the evidence reviewed and the basis for each finding. Present findings in a way that is understandable and useful to executive, technical, and operational teams. Conduct follow-up reviews when included in the engagement.
Serve as Kerndell’s primary point of contact for assigned engagements and help keep the work on schedule and within scope. Represent Kerndell professionally and provide clients with a positive and valuable experience.