Associate Information Security Auditor - Remote
- Роль
- Безопасность
- Опыт
- Джуниор
- Занятость
- Полная занятость
Доступно для: US only. Укажите, откуда вы работаете, чтобы проверить доступность.
Коротко по делу
Associate-level information security auditor, 1+ years experience, Bachelor's in Computer Science/Cybersecurity/related (or equivalent). Must be a United States citizen and work for a US-based role. Requires experience with audit frameworks (ISO27001, SOC 2, NIST CSF, NIST 800-53/800-171) and CIS Controls/MITRE.
Ключевые навыки
Обязательные навыки
Желательные навыки
The Associate Information Security Auditor is part of the Corporate department, which resides on the Information Security team and reports to the Director of Information Security. The Associate Information Security Auditor will partner with other cybersecurity team members to promote the CIS mission and support our growth. The primary purpose of this position is to evaluate, oversee, and support the implementation and operation of audit controls within the organization and measure compliance with internal standards and best practices. What You'll Do: Define the required controls to be reviewed per the documentation framework and control implementation strategy Review and assess control implementation and effectiveness in accordance with the organization’s information security program, including privacy and artificial intelligence Actively participate in the information security audit engagements by serving as a liaison between external audit entities and internal teams Coordinate with CIS business units to evaluate and promote alignment with control requirements, acting as a governance and oversight function Produce, maintain, and provide control evidence remains with the designated control and evidence owners Demonstrate understanding of the audit frameworks, audit artifact requests, and quality assurance process to ensure that the artifacts provided meet the applicable criteria, including the ability to recreate the artifacts Implement risk-based monitoring to define risk treatment strategies and align to implemented control effectiveness when performing the reviews of the artifacts Assist with day-to-day operational security to ensure functional alignment with applicable policies, standards, frameworks, laws, and regulations Monitor security incidents, metrics, account review, and perform incident response as necessary when deviations from expected baselines occur Provide input into new strategies, technologies, and projects within the organization to assure ‘secure by design’, ‘privacy by design’, and adherence to current control requirements Ensure program level compliance with applicable laws, standards, and guidance Other tasks and responsibilities as assigned What You'll Need: Bachelor’s degree in Computer Science, Cybersecurity, IT Compliance, or related field* 1+ years’ experience in IT auditing, security operations, or related position Experience with the CIS control and compliance evaluation requirements, examples would include (ISO27001, ISO27701, SOC 2, NIST Cybersecurity Framework (CSF), NIST 800-53, NIST 800-171, etc.) Knowledge and application of the CIS Critical Security Controls and MITRE Framework This position requires the individual to be a citizen of the United States of America It's a Plus if You Have: Non-Profit experience Contributed to or developed information technology policies, standards, and procedures Experience performing audit, assessment, or compliance oversight activities and communicating control expectations, findings, and cybersecurity best practices to end users, system administrators, peers, and executive leadership CISA certification COBIT5, FIBF, CJIS or other related frameworks for implementing cybersecurity controls *Additional years of relevant experience or a combination of an Associate’s degree or equivalent and relevant experience may be substituted for the Bachelor’s degree. At CIS, we are committed to providing an inclusive environment in which the diverse backgrounds, experiences, and views of our employees, members, and customers are valued and respected. It is through this commitment that we are able to work together towards our common mission: to make the connected world a safer place. Compensation Range: USD$29.28 - $46.83 Welcome to our employment section. Here you can view our current job openings and apply for positions online. Can't decide on just one opening? Our online application system allows you to easily apply to additional positions, after creating your profile! CIS takes pride in providing a comprehensive benefits package and supportive work environment. We offer a competitive total rewards package at the Center for Internet Security: Base salary is determined on a number of factors including, but not limited to, education, experience and skills Health (PPO, EPO, HSA), Dental & Vision Insurance eligibility starting from the first day of hire $500 wellness card for Health Coverage Participants 401(k) with 4% Company Match, vested from the first day of hire Flexible Spending Account (FSA) & Dependent Care Account (DCA) Life Insurance Bonding Leave Paid Volunteering Program Bonus eligibility Paid Time Off (PTO) inclusive of vacation, personal and sick time Paid Holidays Wellness Program Employee Engagement Activities Professional Development Opportunities Tuition Reimbursement Student Loan PayDown Program Employee Referral program Employee Assistance Program The Center for Internet Security (CIS) makes the connected world a safer place for people, businesses, and governments through our core competencies of collaboration and innovation. We are a community-driven nonprofit responsible for industry-leading best practices for securing IT systems and data. CIS is also a trusted resource for cyber threat prevention, protection, response, and recovery for U.S. State, Local, Tribal, and Territorial (SLTT) government entities and election offices. CIS has an award-winning reputation for investing in its people (click here to learn more), as well as continuous learning and development. We offer our employees diverse opportunities to expand their impact personally and professionally, in their local communities, and among one another. Core Leadership Principles drive our employees at every level of the organization, empowering them to be leaders in everything they do. We are a community-driven nonprofit, responsible for the CIS Controls® and CIS Benchmarks™, globally recognized best practices for securing IT systems and data. We lead a global community of IT professionals to continuously evolve these standards and provide products and services to proactively safeguard against emerging threats. Our CIS Hardened Images® provide secure, on-demand, scalable computing environments in the cloud. CIS is home to the Multi-State Information Sharing and Analysis Center® (MS-ISAC®), the trusted resource for cyber threat prevention, protection, response, and recovery for U.S. State, Local, Tribal, and Territorial government entities, and the Elections Infrastructure Information Sharing and Analysis Center® (EI-ISAC®), which supports the rapidly changing cybersecurity needs of U.S. elections offices.
Чем предстоит заниматься
- Define the required controls to be reviewed per the documentation framework and control implementation strategy.
- Review and assess control implementation and effectiveness in accordance with the organization’s information security program, including privacy and artificial intelligence.
- Actively participate in information security audit engagements by serving as a liaison between external audit entities and internal teams; coordinate with business units to evaluate alignment with control requirements.
- Produce, maintain, and provide control evidence with designated control and evidence owners; demonstrate understanding of audit frameworks, artifact requests, and quality assurance criteria.
- Implement risk-based monitoring, assist with day-to-day operational security, monitor incidents and metrics, and perform incident response as necessary.
Что требуется
- Bachelor’s degree in Computer Science, Cybersecurity, IT Compliance, or related field (or equivalent experience/substitution as described).
- 1+ years’ experience in IT auditing, security operations, or related position.
- Experience with compliance frameworks such as ISO27001, ISO27701, SOC 2, NIST CSF, NIST 800-53, NIST 800-171.
- Knowledge and application of the CIS Critical Security Controls and MITRE Framework.
- This position requires the individual to be a citizen of the United States of America.
Преимущества
- Health (PPO, EPO, HSA); Dental & Vision (eligibility from first day of hire)
- $500 wellness card for Health Coverage Participants
- 401(k) with 4% Company Match, vested from the first day of hire
- Paid Time Off (PTO) inclusive of vacation, personal and sick time; Paid Holidays
- Tuition Reimbursement and Student Loan PayDown Program
The Center for Internet Security (CIS) makes the connected world a safer place for people, businesses, and governments through our core competencies of collaboration and innovation. We are a community-driven nonprofit responsible for industry-leading best practices for securing IT systems and data. CIS is also a trusted resource for cyber threat prevention, protection, response, and recovery for U.S. State, Local, Tribal, and Territorial (SLTT) government entities and election offices.