Information Security Auditor (CISA / CISSP / CIA)
- Джерело:
- djinni.co
Що робити
- Plan and run information security and data protection audits, including on-site audits at client organisations (interviews, document reviews, sampling, process checks, physical security and access control inspections)
- Assess the effectiveness of security controls: access and role management, incident management, change and patch management, backup and recovery, monitoring and endpoint protection
- Scope, coordinate and review penetration tests of web applications, APIs and infrastructure, and turn technical findings into audit conclusions
- Carry out risk analyses and protection-needs assessments, and document residual risks
- Review and help develop ISMS and data protection concepts, security policies, minimum standards and business continuity / disaster recovery plans (BCM)
Що очікуємо
- A valid CISA, CISSP or CIA certification (mandatory)
- At least 5 years of experience in IT/information security auditing, IT risk management or security assessment
- Proven track record of planning and executing security audits in large, complex organisations
- Solid knowledge of ISO/IEC 27001/27002, NIST CSF or comparable frameworks, and of data protection requirements (Swiss FADP / GDPR)
- Good understanding of penetration testing methodologies (e.g. OWASP) and of common vulnerabilities in web applications and APIs
Що пропонуємо
- Knowledge of structured project methods (e.g. PRINCE2, SAFe)
- Additional certifications such as ISO 27001 Lead Auditor, CISM or CRISC
- French language skills
Схожі вакансії
З блогу Trackr
Усі статті →Знайдено через trackr.help/jobs · Канал: @trackrhelp · Бот для персональних сповіщень: @trackrhelpBot


