Audit Manager, Information Security

Auxis

Bogotá

Presencial

COP 120.000.000 - 180.000.000

Jornada completa

hace 2 horas
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

No envíes un currículum genérico: crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Descripción de la vacante

The Audit Manager, Information Security at Grant Thornton will join the Information Security and Risk Management team to organize and manage internal and external audits, supporting the design and maintenance of a cohesive governance, risk and compliance program.

The role requires deep technical knowledge of security controls, frameworks, and regulations, and strong cross-functional collaboration to coordinate multiple timelines across the lines of defense.

Formación

  • Experience with information security frameworks and standards
  • Experience with regulatory requirements (GDPR etc.)
  • Experience performing IT audits and control testing
  • Experience using GRC tools in assessment/audit process
  • Experience gathering information from various sources to identify security weaknesses
  • Expert with security control design, development, implementation and monitoring
  • Experience across multiple information security domains

Responsabilidades

  • Develop audit program and plans, determine scope of audit coverage and organize internal and external audits
  • Oversee audits and ensure compliance obligations are met
  • Review audit reports, management responses and supporting workpapers
  • Draft recommendations and action plans for management
  • Collaborate with stakeholders across lines of defense on assessment results
  • Identify and implement new compliance requirements/controls from regulation changes (ISO 27001, SOC 2, NIST, GDPR)
  • Participate in policy reviews and provide input for policy operationalization
  • Educate control owners to submit risks/exceptions and support risk assessments
  • Design automated and manual control testing methods
  • Conduct compliance assessments and internal control testing of critical processes and systems
  • Promote culture of compliance and develop scalable risk/gov models
  • Assimilate risk data into leadership-ready reports

Conocimientos

InfoSec frameworks
Regulatory requirements
IT audits
GRC tools
Security domains

Educación

Bachelor's degree in CS/Engineering or related field

Herramientas

GRC tools

Descripción del empleo

Job Summary

The Audit Manager, Information Security position will be an integral member of the Information Security and Risk Management team. This role will be responsible for organizing and managing internal and external audits. Work in Chief Information Security Officer (CISO) office under Director, Information Security Governance, Risk and Compliance, this role serves as an information security technology professional for Grant Thornton to support the design, implementation, and maintenance of a cohesive information security governance, risk and compliance program. The successful candidate will have a good mix of deep technical knowledge, understanding of industry best practice, frameworks and regulations, and a demonstrated background in information security risk management program. An experienced and motivated risk and compliance individual contributor is needed to work across a matrixed team in place today and growing in the future. The successful candidate has a track record of developing strong relationships, collaborating across teams, coordinating multiple timelines, and managing complex, cross discipline projects.

Responsibilities
  • Develop audit program and plans, determine scope of audit coverage, and organize and manage internal and external audit engagements.
  • Oversee the process of audits, making recommendations on policies, and ensuring that the organization fulfills compliance obligations.
  • Coordinates and/or performs audit work, reviews audit reports prior to formal release, reviews management responses and reviews supporting workpapers to ensure reports are properly supported.
  • Identifies factors causing deficient conditions and provides constructive, economical, and practical recommendations for audit findings. Drafts recommendations for management responses and corrective action plans.
  • Support iterative review of assessment results, working with appropriate stakeholders across the lines of defense.
  • Follows-up to determine adequacy and implementation of corrective actions.Identify and manage implementation of new compliance requirements/controls that are introduced by changes to regulations/standards/frameworks (new compliance requirements introduced per changes to ISO 27001, SOC 2, NIST 800-53, NIST CSF, GDPR)
  • Participate and provide input during policy annual reviews.
  • Educate control owners to submit risks/exceptions and support risk assessments.
  • Design automated and manual control testing methods.
  • Conduct compliance assessments and internal control testing of critical business processes, critical information systems/assets (technology/application) and processes to evaluate design and operating effectiveness of controls, and proactively prepare stakeholders for external audits.
  • Participate in policy reviews and provide meaningful feedback; facilitate policy operationalization
  • Establishes and maintains effective working relationships with Control Owners and Control Operators.
  • Support and advise Control Owners and Control Operators to:
  • build programs based on principles: compliance-by-design and security-by-design
  • proactive evidence collection for audits using GRC Tool
  • validate evidence for sufficiency per control requirements
  • remediate findings
  • Create collateral to promote culture of compliance aligned to firm’s risk tolerance.
  • Contribute to the development of scalable models and tools that speed up both decision making and accuracy for the organization.
  • Assimilate risk and compliance assessment/audit data into concise and meaningful reports/dashboards for leadership
Skills And Experience
Experience
  • Experience with information security frameworks, industry standards (i.e., NIST 800-53; ISO 27001, ISO 27017, COSO, HITRUST)
  • Experience with regulatory requirements (i.e., GDPR etc.)
  • Experience performing IT audits and control testing
  • Experience using GRC tools and technologies in support of the assessment/audit process
  • Experience gathering information from a range of different sources to help identify weaknesses in security controls
  • Expert with security control design, development, implementation, and monitoring
  • Demonstrated experience across multiple information security domains preferred
Qualifications
  • Bachelor's degree in Computer Science, Engineering or related field or equivalent work experience
  • CISA, CRISC, CISM, or CISSP certifications (one or more) preferred
  • Demonstrated advanced verbal and written communication skills
  • Excellent organization skills and be a self-motivated learner
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Information Security Audit Manager: Risk & Compliance Lead
Information Security Audit Manager: Risk & Compliance Lead

Auxis • Bogotá

Presencial
COP 120.000.000 - 180.000.000
INTERNAL CONTROL SPECIALIST RBS
INTERNAL CONTROL SPECIALIST RBS

SGS • Colombia

Presencial
COP 120.000.000 - 180.000.000
GRC, Cybersecurity, and Compliance Professional
GRC, Cybersecurity, and Compliance Professional

Yuxi Global powered by Veritas Automata • Medellín

Presencial
COP 286.205.000 - 477.008.000
Senior Information Security Analyst
Senior Information Security Analyst

Ibope • Colombia

Presencial
COP 183.143.000 - 293.030.000
Security Risk Governance
Security Risk Governance

Laborintos • Bogotá

Presencial
COP 156.905.000 - 235.359.000
SOX Controls and Compliance Manager
SOX Controls and Compliance Manager

Liberty Latin America • Colombia

Presencial
COP 293.427.000 - 366.785.000
Junior Internal Auditor
Junior Internal Auditor

Confidential • Bogotá

Híbrido
COP 40.000.000 - 70.000.000
Data Security Posture Management
Data Security Posture Management

Auxis • Bogotá

Presencial
COP 180.000.000 - 320.000.000
Gerente de Auditorías IT
Gerente de Auditorías IT

Empresa Confidencial • Medellín

Presencial
COP 120.000.000 - 180.000.000
CSIRT Incident Responder / Threat Hunter
CSIRT Incident Responder / Threat Hunter

Auxis • Bogotá

Presencial
COP 90.000.000 - 180.000.000