Share
Key job responsibilities
- Dive deep into the control environment to develop a technical understanding of control implementation and articulate compliance implications to internal and external audit functions.- Improve documentation, coordinate improvement efforts, and monitor process improvement effectiveness.- Operate and plug into organizational mechanisms for managing changes to the control environment and external industry standards requirements; document organizational control activities and confirm readiness of controls for audit.
A day in the life
- 5+ years in security or commercial compliance work in support of highly technical, complex cloud services environment(s) or experience as an IT auditor in direct support of ISO 27001 and SOC 2 examinations- Bachelor's Degree in Information Systems Management, Computer Science, Informatics, or other related fields.- Certified Information Systems Auditor (CISA) or Certified Information Systems Manager (CISM)- Experience communicating audit/assessment results and corrective action (i.e. remediation) plans to partners, and prioritizing and remediating findings with service/system owner.- Solid technical background with experience in cloud technologies, cloud deployment models (IaaS/PaaS/SaaS), and familiarity with AWS core services (Lambda, ECS, EC2, S3, DDB, KMS, etc.)- Experience working with auditors/regulators for these types of assessments.
- Certified Information Systems Security Professional (CISSP), ISO 27001 Lead Auditor, ISO 27001 Lead Implementer, Certified Cloud Practitioner, or equivalent certifications- Experience scoping and leading organizational risk assessments and documenting risk treatment plans- Experience engaging software development teams, who are building cloud products or services, defining technical security specifications to meet control requirements, and monitoring the team’s progress from development to release.- Experience building certification roadmaps based on customer requirements, compliance documentation, and ensuring that committed assessments are delivered on schedule.- Knowledge and proficiency with Project Management tools, like Asana and ServiceNow.
- Strong organization, writing, and communication skills
These jobs might be a good fit