Skip to main content
Associate Information Security Auditor

Associate Information Security Auditor - Remote

RemoteUnited States onlyArchived
Published
Role
Unknown
Experience
Junior
Employment
Full-time
$29.28–$46.83/hr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

We are seeking an Associate Information Security Auditor to evaluate, oversee, and support the implementation and operation of audit controls within our organization and measure compliance with internal standards and best practices.

Core skills

CISACOBIT 5FIBF (FBI? probably typo, but as in posting: FIBF?) Actually posting says 'FIBF' — keep as is: 'FIBF'

Required skills

ISO 27001ISO 27701SOC 2NIST CSFNIST 800-53NIST 800-171CIS Critical Security ControlsMITRE FrameworkInformation Technology Auditing/Security Operations

Optional skills

CISA certificationCOBIT5FIBFCJISExperience contributing to or developing IT policies, standards, proceduresExperience performing audit, assessment, or compliance oversight activitiesNon-Profit experience

Required languages

English unknown

What you'll do

  • Define the required controls to be reviewed per the documentation framework and control implementation strategy
  • Review and assess control implementation and effectiveness in accordance with the organization’s information security program, including privacy and artificial intelligence
  • Actively participate in the information security audit engagements by serving as a liaison between external audit entities and internal teams
  • Coordinate with CIS business units to evaluate and promote alignment with control requirements, acting as a governance and oversight function
  • Produce, maintain, and provide control evidence remains with the designated control and evidence owners
  • Demonstrate understanding of the audit frameworks, audit artifact requests, and quality assurance process to ensure that the artifacts provided meet the applicable criteria, including the ability to recreate the artifacts
  • Implement risk-based monitoring to defining risk treatment strategies and align to implemented control effectiveness when performing the reviews of the artifacts
  • Assist with day-to-day operational security function
  • Monitor security incidents, metrics, account review, and perform incident response as necessary
  • Provide input into new strategies, technologies, and projects to assure ‘secure by design’, ‘privacy by design’, and adherence to current control requirements
  • Ensure program level compliance with applicable laws, standards, and guidance
  • Other tasks and responsibilities as assigned

What they require

  • Bachelor’s degree in Computer Science, Cybersecurity, IT Compliance, or related field
  • 1+ years’ experience in IT auditing, security operations, or related position
  • Experience with the CIS control and compliance evaluation requirements, examples would include (ISO27001, ISO27701, SOC 2, NIST CSF, NIST 800-53, NIST 800-171)
  • Knowledge and application of the CIS Critical Security Controls and MITRE Framework
  • Individual must be a citizen of the United States of America
  • Additional years of relevant experience or a combination of an Associate’s degree or equivalent and relevant experience may be substituted for the Bachelor’s degree

CIS

Cybersecurity (Information Security)

Details

Apply routeWorkday
$29.28–$46.83/hr