Internal Governance Officer
- Hiring from
- Ireland
- Work type
- Hybrid
- Posted
- Sep 30, 2026
Is this job info correct?
Nostra is a leading Managed Service Provider (MSP) in Ireland, dedicated to delivering advanced IT solutions that enable businesses to build reliable, secure, and scalable IT foundations. With a commitment to continuous improvement, we serve a diverse range of industries, providing exceptional services that empower our clients to focus on their core business goals.
The Internal Governance Officer is the day-to-day custodian of Nostra's Integrated Management System (IMS), which is built on the ISO/IEC 27001 information security management standard. The role keeps the IMS current, evidenced and audit-ready, and makes sure it works as a living system that the business actually uses rather than a set of documents that are only refreshed before an audit.
Nostra has offices in Dublin (HQ), Galway, Cork and Belfast.
Responsibilities:
IMS Ownership & Maintenance:
The Internal Governance Officer is the day-to-day custodian of Nostra's Integrated Management System (IMS), which is built on the ISO/IEC 27001 information security management standard. The role keeps the IMS current, evidenced and audit-ready, and makes sure it works as a living system that the business actually uses rather than a set of documents that are only refreshed before an audit.
Nostra has offices in Dublin (HQ), Galway, Cork and Belfast.
Responsibilities:
IMS Ownership & Maintenance:
- Own and maintain the IMS documentation set, including the scope statement, Statement of Applicability, information security policies, procedures, standards and records, with clear version control and scheduled review cycles.
- Maintain the information security risk register and risk treatment plans, working with risk and control owners to run the annual risk assessment and track treatment actions to closure.
- Plan and run the internal audit programme, and coordinate external certification, surveillance and recertification audits with the certification body.
- Manage nonconformities, observations and corrective actions, including root-cause analysis and verification that actions are effective.
- Define, collect and report IMS performance measures and control effectiveness metrics.
- Maintain the control ownership model and a well-organised evidence repository so that evidence is always available for audits and customer requests.
- Support the delivery of information security awareness and policy training and track policy acknowledgements.
- Maintain a unified control framework that maps the IMS to ISO/IEC 27001, DORA and NIS2 requirements, so that one control and one piece of evidence can satisfy several obligations.
- Extend IMS policies and procedures to cover DORA and NIS2 areas such as ICT risk management, incident classification and reporting, business continuity and resilience testing, supply chain and ICT third-party risk, and management body accountability.
- Support incident reporting procedures so that regulatory notification timelines (for example the NIS2 early warning, notification and final report stages) can be met.
- Monitor regulatory developments and guidance from relevant EU and Irish authorities, assess the impact on the IMS and recommend changes.
- Track and report remediation actions arising from GDPR, DORA and NIS2.
- Support responses to customer security questionnaires, due diligence requests, tenders and RFP security sections.
- Prepare and manage customer assurance evidence packs, including certificates, policy summaries and control descriptions.
- Support customer audits and annual governance reviews, including coordinating the dates and status of policies and other requested documents.
- Attend customer meetings on the when required.
- Help translate contractual and regulatory security requirements from customers into IMS controls and actions.
- At least three years' experience in information security governance, risk and compliance (GRC) or management system role.
- Hands-on experience maintaining an ISO/IEC 27001 information security management system, including the Statement of Applicability, risk assessment and management review.
- Strong working knowledge of ISO/IEC 27001 and ISO/IEC 27002 controls and of information security risk assessment methods.
- Sound understanding of GDPR, DORA and NIS2 and the ability to translate regulatory text into practical controls, policies and evidence.
- Excellent written skills, with experience drafting clear policies, procedures, minutes and reports.
- Highly organised, with the ability to manage review cycles, audit schedules and multiple deadlines at once.
- Confident communicator who can explain governance requirements to technical, non-technical and customer audiences.
- Good working knowledge of Microsoft 365 tools such as SharePoint, Teams and Excel for document control, action tracking and reporting.
- Generous Professional Development Budget.
- Company Pension.
- Health Insurance.
- Wellness Benefit.
- On-site Gym.
- Health & Fitness Benefit.
- Employee Assistance Program.
- Company Events.