Job description
Role Overview
ISMS & ISO 27001 Security Process Specialist at Damen Shipyards Group, located at DMESS, Abu Dhabi, UAE. Full-time position within the Cyber Security / Group IT Department.
Company Overview
Damen Shipyards Group is a global maritime leader strengthening its Information Security Management System (ISMS) and advancing toward ISO/IEC 27001:2022 certification readiness.
Role Purpose
Act as the operational driver behind Damen's ISO/IEC 27001:2022 implementation efforts. Identify existing security and IT processes, document and formalize them, establish traceability between risks and controls, and ensure evidence can be consistently produced for audits and certification activities. Transform fragmented information into a structured, auditable, and sustainable Information Security Management System embedded into day-to-day operations across the organization.
Key Responsibilities
Build & Maintain the ISMS
- Develop and maintain the Information Security Management System aligned with ISO/IEC 27001:2022.
- Create policies, procedures, standards, registers, and governance documentation.
- Establish traceability between risks, controls, owners, processes, and evidence.
- Support maintenance of the Information Security Risk Register and Statement of Applicability (SoA).
- Build sustainable governance structures that support certification readiness.
Document & Formalize Processes
- Identify existing security, IT, and governance processes across the organization.
- Interview stakeholders to understand how controls operate in practice.
- Create process flows, control descriptions, workflows, and supporting documentation.
- Translate operational activities into auditable and repeatable processes.
- Identify and remediate documentation and process gaps.
Support ISO/IEC 27001 Compliance
- Map existing practices against ISO/IEC 27001:2022 clauses and Annex A controls.
- Perform compliance and gap assessments.
- Define actions required to address identified deficiencies.
- Support control owners in documenting controls and evidence requirements.
- Track remediation activities through to completion.
Develop the Security Management System
- Build and maintain security processes within Damen's Mavim platform.
- Structure relationships between controls, risks, evidence, systems, and stakeholders.
- Ensure information security requirements are embedded into business processes.
- Maintain process ownership, version control, and review cycles.
- Support continuous improvement of the management system.
Manage Evidence & Audit Readiness
- Establish and maintain the ISMS evidence repository.
- Coordinate the collection and validation of audit evidence.
- Ensure evidence remains current, complete, and accessible.
- Support internal audits, certification audits, and management reviews.
- Track findings, corrective actions, and improvement initiatives.
Drive Continuous Improvement
- Promote best practices in security governance and process management.
- Support stakeholders in adopting structured and sustainable controls.
- Facilitate workshops and working sessions across the business.
- Translate ISO requirements into practical business guidance.
- Improve ISMS maturity, audit readiness, and process effectiveness.
Qualifications & Experience
- 4β7 years of experience in Information Security, ISMS, IT Governance, GRC, IT Service Management, Quality Management, or Process Management.
- Practical experience implementing or maintaining an ISO/IEC 27001-compliant management system.
- Experience documenting processes, controls, procedures, and governance frameworks.
- Experience supporting internal audits, certification audits, or compliance assessments.
- Experience working within complex international organizations.
- Experience with BPM or process management tools such as Mavim, ARIS, Signavio, Visio, or similar platforms.
Skills & Competencies
- ISO/IEC 27001:2022 Framework.
- Information Security Management Systems (ISMS).
- Risk and Control Management.
- Governance, Risk & Compliance (GRC).
- Process Documentation and Process Modelling.
- Audit and Evidence Management.
- IT Service Management (ITIL).
- Mavim, ARIS, Signavio, Visio, or equivalent BPM solutions.
- ServiceNow or similar governance platforms.
- Data Governance and Data Stewardship concepts.
- Structured and highly organized approach to work.
- Excellent documentation and analytical skills.
- Strong stakeholder engagement abilities.
- Detail-oriented with a focus on quality and compliance.
- Pragmatic and solution-oriented mindset.
- Able to work independently and across organizational boundaries.
- Ability to challenge existing practices constructively.
- Passionate about building sustainable security processes and management systems.
Additional Information
Work directly with the Group CISO and key stakeholders across multiple countries and business functions. This role offers the opportunity to create lasting organizational impact by building a structured, auditable, and scalable security management system that supports both operational excellence and regulatory compliance. Part of an international environment that values ownership, continuous improvement, collaboration, and professional growth.