Skip to main content
Schellman

Seasonal Senior Associate, ISO

RemoteUnited States only
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Enterprise
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior ISO-focused auditor/associate for security/privacy attestation work. Must have ISO 27001:2022 audit experience and ISO lead auditor certification; experience in information security auditing or relevant professional services. Remote (US-focused employer signals) with some travel required for training and client needs.

Core skills

ISO 27001 auditing

Required skills

ISO 27001:2022ISO lead auditor certificationMicrosoft WordMicrosoft ExcelMicrosoft PowerPoint

Optional skills

ISO 42001:2023ISO 27701:2025ISO 9001:2015CPACISACISSPISACA membershipISC2 membership

What you'll do

  • Comply with Schellman’s code of ethics and professional conduct, methodologies, policies, and procedures
  • Adhere to professional and regulatory standards relevant to assigned service line specialization(s)
  • Establish high quality relationships and rapport with client personnel
  • Manage client expectations to ensure expectations are exceeded
  • Complete assigned duties in a timely manner and with high attention to detail
  • Collaborate with fellow project team members throughout the life cycle of each project
  • Adhere to project schedules and keep fellow project team members apprised of progress
  • Escalate issues internally in a proper and timely manner
  • Use discretion and decorum in timing, form, and content of all client communications
  • Perform essential functions of other service delivery positions when qualified and called upon
  • Attend project kick-off and closing meetings
  • Execute assigned testing procedures, perform detailed analysis, reach conclusions, and document results
  • Draft project deliverables
  • Serve as a contact for clients' basic questions regarding an engagement
  • Develop expert knowledge of professional and regulatory standards relevant to assigned service line

What they require

  • Experience with auditing the requirements of the ISO 27001:2022 Standard
  • Requisite knowledge of applicable technology and security domains
  • High level of attention to detail and quality of work product
  • Client service oriented
  • Excellent time management, organizational, and verbal and written communication skills
  • Ability to work on-site or remotely as a valuable contributor to a collaborative team
  • Capable of simultaneously managing assigned tasks for multiple projects
  • Proficient using Microsoft Word, Excel, and PowerPoint, as well as Schellman’s service delivery applications
  • Full understanding and application of ethics, independence and Schellman’s values
  • Bachelor's degree in accounting, finance, business management, technology, or other relevant subject area, or equivalent years of experience
  • Has completed at least one year of service at Schellman or relevant professional services experience in financial auditing, operational auditing, information systems auditing, internal auditing, information security management or consulting and/or risk consulting
  • Maintains an active ISO lead auditor certification, ISO 27001:2022 Lead Auditor at minimum

Benefits

  • Flexible and balanced environment with opportunity to work remotely
  • Travel annually for internal training, team meet-ups, and strategy meetings
  • Culture emphasizing 'People Come First'; Great Place to Work certified and Glassdoor Best Places to Work recognition
  • Equal opportunity employer; supportive of diversity

Schellman is a Top 50 CPA firm and a leading provider of attestation and compliance services. Our professional services focus on security and privacy audits, assessments, and certifications. Schellman has become one of the largest cybersecurity assessment firms in the United States without providing any traditional accounting services. We are an accredited multi-framework ISO Certification Body for security, privacy, business continuity, and quality; a globally licensed PCI Qualified Security Assessor and a top provider to clients serving the federal DoD space as a leading FedRAMP 3PAO and the first assessment firm authorized as a CMMC C3PAO.

CybersecurityEnterprise
Salary not disclosed