About the role
SGS is the world’s leading inspection, verification, testing and certification company. SGS is recognised as the global benchmark for quality and integrity. With more than 96,000 employees, SGS operates a network of over 2,600 offices and laboratories around the world.
As a champion of "Digital Trust," this role is the face of the organization in the fast-evolving tech landscape. Beyond auditing ISMS/PIMS, the Senior Auditor must be a proactive learner who anticipates cyber trends, supports Sales in penetrating the tech market, and communicates security risks as business opportunities. This role demands a modern, agile, and highly communicative professional.
Advanced Digital Auditing: Conduct ISO 27001, 27701, and cloud security audits. Evaluate AI-related risks and data privacy controls in modern tech environments.
Sales Enablement: Accompany Sales to pre-sales meetings to build technical credibility. Help design tailored solutions for tech giants and startups alike.
Market Vision & Scheme Expansion: Proactively research and develop expertise in new areas like ISO 42001 (AI Management), Cybersecurity Act, or ESG in Digital. Always be "ahead of the curve."
Stakeholder Communication: Translate complex cyber risks into clear business language for C-level executives. Maintain a collaborative and helpful posture, even during difficult audit findings.
Agility & Proactivity : Actively contribute to internal process improvements using digital tools. Show high initiative in solving problems and supporting teammates.
Education: University degree in Computer Science, Information Technology, or Cyber Security.
Experience: Total work experience ≥ 5 years in IT security, IT risk management, or IT auditing.
Auditing: Experience in ISO 27001 or specialized IT audits ≥ 1.5 year.
Certification: Mandatory ISO 27001 Lead Auditor certificate. Preferred: CISA, CISSP, or CISM.
Good command of English (both written and verbal).
Technical Skills: Knowledge of cloud security (AWS/Azure/Google), data privacy laws (GDPR/Vietnam Decree 13), and penetration testing methodologies.
Attributes : Highly proactive, curiosity-driven, and adaptable to rapid technological changes.
