Lead Auditor - Info Security & Digital Trust

Shah Alam, MalaysiaFull-timePosted Jul 29, 2026

Lead Auditor - Info Security & Digital Trust

  • Full-time

Company Description

We are SGS – the world’s leading testing, inspection and certification company. We are recognized as the global benchmark for sustainability, quality and integrity. Our 99,600 employees operate a network of 2,600 offices and laboratories, working together to enable a better, safer and more interconnected world.

Job Description

Primary Resposibilities

  • Lead and support audits, assessments and assurance activities for information security and Digital Trust schemes, with focus on ISO/IEC 27001 ISMS and related standards.
  • Support SGS Malaysia in obtaining, maintaining or expanding accreditation, certification or licensing capability for Digital Trust services.
  • Validate technical proposals, audit scopes, certification assumptions, man-day calculations, competency requirements and commercial feasibility for new or expanded Digital Trust services.
  • Support customer engagement and solution selling by providing expert technical input during client meetings, proposal clarification, pre-sales discussions and service presentations.
  • Develop and maintain service methodologies, audit checklists, technical guidance, customer-facing materials and internal knowledge resources for Digital Trust service delivery.
  • Provide technical input for service expansion in areas such as information security, privacy, AI governance, industrial cybersecurity, business continuity, SOC 2, PCI DSS and TISAX.
  • Collaborate with regional and global SGS technical teams to ensure consistent service delivery, auditor competence, technical review quality and customer satisfaction.

Specific Responsibilities

  • Plan, conduct and/or support audits and assessments for ISO/IEC 27001 Information Security Management Systems and related Digital Trust schemes, in accordance with applicable accreditation and certification requirements.
  • Support technical development and delivery readiness for ISO/IEC 27701 Privacy Information Management Systems, ISO/IEC 42001 Artificial Intelligence Management Systems, IEC 62443 industrial cybersecurity and ISO 22301 Business Continuity Management Systems.
  • Provide technical advisory support for Digital Trust assurance services, including SOC 2 assurance, cybersecurity governance and risk management, privacy and data protection audits, business continuity and resilience, PCI DSS, TISAX and independent assurance services.
  • Support AI governance service development, including AI management system certification, AI cybersecurity, AI risk testing, dataset quality testing, AI robustness and bias assessment, and responsible AI assurance or certification.
  • Review customer requirements, audit scope, boundaries, systems, controls, risks, legal / regulatory considerations and evidence requirements to ensure appropriate audit approach and deliverables.
  • Prepare and review audit plans, audit reports, nonconformity statements, technical recommendations, certification decision inputs and customer-facing documentation.
  • Support internal capability building by training and coaching internal teams on Digital Trust schemes, audit methodology, technical standards, customer expectations and service positioning.
  • Provide market and competitor insight on certification and cyber assurance providers such as BSI, LRQA, TÜV SÜD Malaysia, DNV and Bureau Veritas to support SGS service differentiation.
  • Maintain impartiality, confidentiality, technical integrity and proper documentation control in all audits, assessments, commercial support and customer engagements.
  • Ensure all activities comply with SGS Code of Integrity, accreditation requirements, applicable standards, information security expectations and professional conduct standards.
  • Adherence to SGS Health, Safety and Environment (HSE) Policy by upholding good safety behaviour and exercising necessary standards and processes when carrying out responsibilities at all times to ensure compliance with the HSE requirements.
  • Perform any other responsibilities as assigned by your reporting manager and/or Senior Management.

Qualifications

Minimum Qualification

  • Bachelor’s Degree in Information Technology, Cybersecurity, Computer Science, Information Systems, Engineering, Business Continuity, Risk Management or a related discipline.
  • Qualified Lead Auditor or auditor competency in ISO/IEC 27001 Information Security Management Systems is required; competence across one or more additional Digital Trust schemes is preferred.
  • Relevant experience in certification, third-party audit, cybersecurity governance, risk management, privacy, information security, business continuity, industrial cybersecurity or digital assurance is required.

Preferred Technical Exposure

  • Experience with ISO/IEC 27701, ISO/IEC 42001, IEC 62443, ISO 22301, SOC 2, PCI DSS, TISAX, privacy audits, AI governance or responsible AI assurance will be a strong advantage.
  • Experience supporting accreditation, certification programme development, technical review, audit planning, nonconformity review or certification decision support is desirable.
  • Experience engaging customers in regulated or digital-heavy sectors such as financial services, fintech, cloud services, manufacturing, government, smart manufacturing, technology services or ESG digital reporting will be advantageous.
  • Able and willing to travel up to 75% of the time for audits, client meetings, technical discussions, training, assessments and business development support.

Additional Information

Behavioural Competencies

  • Customer-focused and service-oriented approach.
  • Strong collaboration and partnership mindset.
  • Adaptable and resilient in a fast-paced environment.
  • Demonstrates sound judgment and decision-making capabilities.
  • Committed to SGS values, quality standards, and ethical conduct.

Travel Requirement: Up to 10%

Employment Type: Permanent

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

I'm interestedI'm interestedPrivacy Notice

Want jobs like this matched to you?

SimpleCareer scores fresh postings against your résumé so you only see the matches that matter.

Get started free