Senior IT Cybersecurity Auditor
Summary
Leads audits of cybersecurity controls and IT risk frameworks for a global financial firm, assessing risks in areas like cloud security and identity management while advising senior stakeholders.
Senior Information & Cyber Security Auditor
Overview
A leading global financial institution is seeking a Senior Audit Manager to join its Information & Cyber Security Audit team. This role is responsible for delivering technology and cyber security audits, assessing cyber risks and controls, and partnering with senior stakeholders to strengthen the organisation's control environment.
Key Responsibilities
- Lead end-to-end internal audits across information and cyber security.
- Assess the effectiveness of cyber security controls, technology risk frameworks, and IT governance.
- Evaluate areas including identity & access management, vulnerability management, security operations, code security, threat intelligence, penetration testing, and cloud security.
- Provide risk-based recommendations and monitor remediation of audit findings.
- Engage with senior stakeholders, support regulatory and governance activities, and mentor junior team members.
- Promote the use of data analytics and emerging technologies to enhance audit effectiveness.
Requirements
- 10+ years' experience in IT Audit, Information Security, Cyber Security, or Technology Risk within financial services.
- Strong understanding of cyber security frameworks, risk management, and IT controls (e.g. NIST, CIS).
- Experience auditing areas such as IAM, vulnerability management, SOC, cloud infrastructure, application security, and third-party risk.
- Excellent stakeholder management, analytical, and communication skills.
- Professional certifications such as CISA, CISSP, CISM, CRISC, CEH, GIAC, CCSP, or CIA are highly regarded.
- Bachelor's degree in Information Technology, Computer Science, Information Systems, or a related discipline.