Senior Cyber Security Internal Auditor

SITA

Barcelona

Híbrido

EUR 48.000 - 74.000

Jornada completa

Hace 11 días

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Ventajas ofrecidas por este puesto de trabajo

Flex Week: Work from home up to 2 days
Flex Day
Flex-Location: up to 30 days abroad
Employee Wellbeing program
Professional development opportunities
Competitive benefits

Descripción de la vacante

At SITA, we perform cyber security, IT and privacy audits across the world to assess control design and operating effectiveness. The role involves independent fieldwork, data-driven techniques, and reporting to management on risk areas and remediation needs.

You'll work with senior stakeholders, apply standards like ISO 27001, NIST, CIS, COBIT, GDPR and NIS2, and contribute to the audit program with a focus on third-party risk and regulatory compliance. Hybrid work options are available.

Formación

  • 3 years of experience in external/internal cyber, IT, and privacy auditing.
  • Experience performing end-to-end audits independently.
  • Strong understanding of cybersecurity and IT controls.
  • Experience with technical audit techniques (not only policy reviews).
  • Familiarity with frameworks such as ISO 27001, NIST, CIS, COBIT, GDPR, NIS2.
  • Background in an audit environment (e.g. audit firm or internal audit team).
  • Ability to communicate effectively with senior stakeholders, including leadership level.

Responsabilidades

  • Perform independent cyber security, IT and Privacy audits in accordance with the audit schedule approved by the Audit and Risk Management Committee and hence prepare for independent cyber security, IT and Privacy audits and field work with the purpose of evaluating (but not limited to).
  • Apply data-driven and technical audit techniques (configuration reviews, log analysis, vulnerability assessment review, etc.).
  • Assess the design, implementation and operating effectiveness of cybersecurity, IT and Privacy controls.
  • Evaluate alignment with recognized frameworks and standards (e.g. NIST CSF, ISO 27001, CIS, COBIT, NIS2, GDPR).
  • Identify control gaps, weaknesses, and root causes.
  • Assess management’s remediation plans for adequacy, sustainability, and timeliness.
  • Assess compliance with Internal policies, Regulatory and contractual cyber requirements.
  • Provide assurance over third-party and supply-chain cyber, IT and Privacy risk management.
  • Present audit results to senior management and EMT.
  • Track and validate remediation actions, including follow-up testing where required.

Conocimientos

Cybersecurity auditing
IT auditing
Privacy auditing
Stakeholder communication

Herramientas

ISO 27001
NIST
CIS
COBIT
GDPR
NIS2

Descripción del empleo

Overview
WELCOME TO SITA

At SITA, we keep airports moving, airlines flying smoothly, and borders open. Our technology and communication innovations power the success of the global air travel industry.

You'll find us in 95% of international airports, working closely with over 2,500 transportation and government clients. Each partnership brings unique challenges, and we thrive on delivering fresh solutions and cutting-edge tech to keep operations running like clockwork. We don't just move the world forward-we're proud to be recognized as a Great Place to Work® by 79% of our employees and certified in most of our growing locations. Here, we feel empowered, supported, and inspired to grow.

Are you ready to love your job?

The adventure begins right here, with you, at SITA.

PURPOSE

The purpose of this role is to perform Cyber Security, IT and Privacy audits of SITA corporate procedures processes and sites throughout the world and to prepare factual audit reports and communications informing management and stakeholders of risk areas and issues.

Key Responsibilities

Perform independent cyber security, IT and Privacy audits in accordance with the audit schedule approved by the Audit and Risk Management Committee and hence prepare for independent cyber security, IT and Privacy audits and field work with the purpose of evaluating (but not limited to):

  • Cyber Security, IT and Privacy Policies, Standards and Procedures
  • Cyber, IT and Privacy governance and operating model
  • Cyber Security, IT and Privacy risk management
  • Identity & access management (IAM)
  • Network and infrastructure security
  • Cloud security
  • Application security and SDLC
  • Data protection and privacy controls
  • Incident response and cyber resilience

In order to perform the above, the candidate must demonstrate ability to:

  • Perform end-to-end audit activities: planning, fieldwork, testing, documentation, and reporting
  • Apply data-driven and technical audit techniques (configuration reviews, log analysis, vulnerability assessment review, etc.)
  • Assess the design, implementation and and operating effectiveness of cybersecurity, IT anmd Privacy controls
  • Evaluate alignment with recognized frameworks and standards (e.g. NIST CSF, ISO 27001, CIS, COBIT, NIS2, GDPR)
  • Identify control gaps, weaknesses, and root causes
  • Assess management’s remediation plans for adequacy, sustainability, and timeliness
  • Assess compliance with Internal policies, Regulatory and contractual cyber requirements
  • Provide assurance over third-party and supply-chain cyber, IT and Privacy risk management
  • Present audit results to senior management and EMT
  • Track and validate remediation actions, including follow-up testing where required
Qualifications
EXPERIENCE
  • 3 years of experience in external/internal cyber, IT, and privacy auditing
  • Experience performing end-to-end audits independently
  • Strong understanding of cybersecurity and IT controls
  • Experience with technical audit techniques (not only policy-level reviews)
  • Familiarity with frameworks such as ISO 27001, NIST, CIS, COBIT, GDPR, NIS2
  • Background in an audit environment (e.g. audit firm or internal audit team)
  • Ability to communicate effectively with senior stakeholders, including leadership level
Nice To Have
  • ISO 27001 Lead Auditor or similar certification (e.g. CISM)
  • Exposure to privacy topics alongside cybersecurity
What We Offer

We're all about diversity. We operate in 200 countries and speak 60 different languages and cultures. We're really proud of our inclusive environment. Our offices are comfortable and fun places to work, and we make sure you get to work from home too. Find out what it's like to join our team and take a step closer to your best life ever.

  • Flex Week: Work from home up to 2 days/week (depending on your team's needs)
  • Flex Day: Make your workday suit your life and plans.
  • Flex-Location: Take up to 30 days a year to work from any location in the world.
  • Employee Wellbeing: We have got you covered with our Employee Assistance Program (EAP), for you and your dependents 24/7, 365 days/year. We also offer Champion Health - a personalized platform that supports a range of wellbeing needs.
  • Professional Development: At SITA, we believe growth fuels innovation. Our learning ecosystem offers access to world-class platforms and programs designed to help you thrive. From LinkedIn Learning, Microsoft's Enterprise Skills Initiative, and Airport Council International -available to all employees-to specialized solutions like Pluralsight for technology upskilling, Harvard Business Publishing for people leadership, Stanford for strategic development and many others, we align learning opportunities with your Development Plan and our business priorities. Your development journey is supported every step of the way.
  • Competitive Benefits: Competitive benefits that make sense with both your local market and employment status.

SITA is an Equal Opportunity Employer. We value a diverse workforce. In support of our Employment Equity Program, we encourage women, aboriginal people, members of visible minorities, and/or persons with disabilities to apply and self-identify in the application process.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Senior Cyber Security & Privacy Auditor
Senior Cyber Security & Privacy Auditor

SITA • Barcelona

Híbrido
EUR 48.000 - 74.000
Flex Week: Work from home up to 2 days
Flex Day
Flex-Location: up to 30 days abroad
+3
Senior Business Consultant
Senior Business Consultant

SITA • Madrid

Híbrido
EUR 60.000 - 85.000
Work from home options
Flexible work hours
Employee Wellbeing Program
+2
Associate Project Manager - Strategy, M&A and Transformation
Associate Project Manager - Strategy, M&A and Transformation

SITA • Barcelona

Presencial
EUR 65.000 - 90.000
Flex Week
Flex Day
Flex-Location
+3
Head/Director Business Consulting
Head/Director Business Consulting

SITA • Madrid

Híbrido
EUR 90.000 - 120.000
Competitive Benefits
Professional Development
Flexible working options
Manager Internal Consulting
Manager Internal Consulting

SITA • Barcelona

Híbrido
EUR 60.000 - 80.000
Flex Week: Work from home up to 2 days a week
Flex Day: Flexible arrival and departure times
Professional Development: Access to training platforms
+1
Senior Infrastructure Engineer
Senior Infrastructure Engineer

SITA Switzerland Sarl • Barcelona

Híbrido
EUR 50.000 - 70.000
Flex Week: Work from home up to 2 days/week
Flex Day: Make your workday suit your life
Flex-Location: Work from any location up to 30 days/year
+2
Project Manager
Project Manager

SITA • Barcelona

Híbrido
EUR 65.000 - 85.000
Flex Week - Work from home up to 2 days/week
Flex Day - Adapt work schedule to personal life
Flex-Location - Work from any location for 30 days a year
+2
Customer Success Senior Consultant
Customer Success Senior Consultant

SITA • Barcelona

Híbrido
EUR 48.000 - 72.000
Senior Infrastructure Engineer
Senior Infrastructure Engineer

SITA • Barcelona

Presencial
EUR 60.000 - 80.000
Flex Week: Work from home up to 2 days/week
Flex Day: Make your workday suit your life
Flex-Location: Work from any location for 30 days a year
Senior Data Engineer
Senior Data Engineer

SITA • Madrid

Híbrido
EUR 45.000 - 75.000
Flex Week: Remote work up to 2 days
Professional development programs
Employee wellbeing program
+2