Automated evidence is worthless until an auditor accepts it. This post is about making that case, properly.
A multinational defence organisation in The Hague, Netherlands is piloting continuous assurance over its cloud estate. You would lead the governance side of that pilot: define it, test whether the evidence really holds, and show the leadership what it means.
What You Would Be Doing
- Running the stakeholder discussion that fixes the pilot's scope, target environment, priority application, success criteria and risk areas
- Agreeing roles, responsibilities, dependencies and decision points with the cloud, compliance, audit and business sides
- Judging whether automated evidence from cloud and software services is complete, reliable, traceable and fit for purpose
- Mapping that digital evidence to the controls, audit requirements and assurance expectations it is supposed to satisfy
- Reviewing the dashboard so that it reflects live risk, control status and compliance rather than a comfortable picture
- Preparing the demonstration that explains the dashboard, the insights and the business value to an executive audience
- Running review sessions to validate assumptions and mappings, and tracking issues to remediation
What you would bring
- A bachelor's degree in a related discipline with three years of related experience
- Three years across all of: leadership; communication; strategy; risk management; audit standards; and building a return-on-investment case people can follow
- Documented experience of process analysis and design
Nice to have
- Real technical knowledge of how allied organisations achieve interoperability
- A working understanding of defence cloud strategy
- ITIL, COBIT or an equivalent
Why this one is worth a look
It is the rare governance post with a technical spine: you would be judging real automated evidence, not writing policy about it.