Nostra logo

Internal Governance Officer

Hiring from
Ireland
Work type
Hybrid
Posted
Sep 30, 2026
Is this job info correct?
Nostra is a leading Managed Service Provider (MSP) in Ireland, dedicated to delivering advanced IT solutions that enable businesses to build reliable, secure, and scalable IT foundations. With a commitment to continuous improvement, we serve a diverse range of industries, providing exceptional services that empower our clients to focus on their core business goals.

The Internal Governance Officer is the day-to-day custodian of Nostra's Integrated Management System (IMS), which is built on the ISO/IEC 27001 information security management standard. The role keeps the IMS current, evidenced and audit-ready, and makes sure it works as a living system that the business actually uses rather than a set of documents that are only refreshed before an audit.

Nostra has offices in Dublin (HQ), Galway, Cork and Belfast.

Responsibilities:

IMS Ownership & Maintenance:

  • Own and maintain the IMS documentation set, including the scope statement, Statement of Applicability, information security policies, procedures, standards and records, with clear version control and scheduled review cycles.
  • Maintain the information security risk register and risk treatment plans, working with risk and control owners to run the annual risk assessment and track treatment actions to closure.
  • Plan and run the internal audit programme, and coordinate external certification, surveillance and recertification audits with the certification body.
  • Manage nonconformities, observations and corrective actions, including root-cause analysis and verification that actions are effective.
  • Define, collect and report IMS performance measures and control effectiveness metrics.
  • Maintain the control ownership model and a well-organised evidence repository so that evidence is always available for audits and customer requests.
  • Support the delivery of information security awareness and policy training and track policy acknowledgements.
DORA & NIS2 Alignment:
  • Maintain a unified control framework that maps the IMS to ISO/IEC 27001, DORA and NIS2 requirements, so that one control and one piece of evidence can satisfy several obligations.
  • Extend IMS policies and procedures to cover DORA and NIS2 areas such as ICT risk management, incident classification and reporting, business continuity and resilience testing, supply chain and ICT third-party risk, and management body accountability.
  • Support incident reporting procedures so that regulatory notification timelines (for example the NIS2 early warning, notification and final report stages) can be met.
  • Monitor regulatory developments and guidance from relevant EU and Irish authorities, assess the impact on the IMS and recommend changes.
  • Track and report remediation actions arising from GDPR, DORA and NIS2.
Customer-Facing Support:
  • Support responses to customer security questionnaires, due diligence requests, tenders and RFP security sections.
  • Prepare and manage customer assurance evidence packs, including certificates, policy summaries and control descriptions.
  • Support customer audits and annual governance reviews, including coordinating the dates and status of policies and other requested documents.
  • Attend customer meetings on the when required.
  • Help translate contractual and regulatory security requirements from customers into IMS controls and actions.
Requirements:
  • At least three years' experience in information security governance, risk and compliance (GRC) or management system role.
  • Hands-on experience maintaining an ISO/IEC 27001 information security management system, including the Statement of Applicability, risk assessment and management review.
  • Strong working knowledge of ISO/IEC 27001 and ISO/IEC 27002 controls and of information security risk assessment methods.
  • Sound understanding of GDPR, DORA and NIS2 and the ability to translate regulatory text into practical controls, policies and evidence.
  • Excellent written skills, with experience drafting clear policies, procedures, minutes and reports.
  • Highly organised, with the ability to manage review cycles, audit schedules and multiple deadlines at once.
  • Confident communicator who can explain governance requirements to technical, non-technical and customer audiences.
  • Good working knowledge of Microsoft 365 tools such as SharePoint, Teams and Excel for document control, action tracking and reporting.
Benefits:
  • Generous Professional Development Budget.
  • Company Pension.
  • Health Insurance.
  • Wellness Benefit.
  • On-site Gym.
  • Health & Fitness Benefit.
  • Employee Assistance Program.
  • Company Events.
At Nostra we value our people. We are a passionate team committed to doing our best, our values are trust, accountability, expertise, people, integrity, and empathy. These values form a central part of our recruitment process. Nostra is an equal opportunity employer committed to diversity and inclusion.

Similar jobs

Apply for this job