25 km
Serrala Group GmbH
Information Security Auditor (all genders) 03.08.2024 Serrala Group GmbH Norderstedt (DE)
Weitere passende Anzeigen:

1

Passende Jobs zu Ihrer Suche ...

... immer aktuell und kostenlos per E-Mail.
Sie können den Suchauftrag jederzeit abbestellen.
Es gilt unsere Datenschutzerklärung. Sie erhalten passende Angebote per E-Mail. Sie können sich jederzeit wieder kostenlos abmelden.

Information Security Auditor (all genders)

Drucken
Serrala Group GmbH
Norderstedt (DE)

Informationen zur Anzeige:

Information Security Auditor (all genders)
Serrala Group GmbH
Norderstedt (DE)
Aktualität: 03.08.2024

Anzeigeninhalt:

03.08.2024, Serrala Group GmbH
Norderstedt (DE)
Information Security Auditor (all genders)
Aufgaben:
- Inspect and verify: Examine the technical implementation of information security controls. Review standard operating procedures, processes and documentation for compliance with standards. - Collect and record: Prepare for and perform the systematic collection of evidence, both to uncover weaknesses, problems and vulnerabilities, and to verify compliance with standards and certifications. - Follow up and report: Work closely with the Information Security Coordinator to help teams remediate findings and nonconformities in the agreed time and quality. Report regularly on the status of action items to remediate audit findings. - Support: Assist departments with recommendations for remediation of findings and nonconformities. Support the Information Security Officer and other departments in the preparation and execution of external audits (ISO 27001, TISAX, SWIFT, SOC 2).
Qualifikationen:
Languages: English & German - Technical expert: With a strong hands-on technical background, you understand the complexity of today's IT landscapes, the challenges of securing them properly, and the common pitfalls in design and implementation. Your experience helps you identify weaknesses and problems in technical areas such as network partitioning, server hardening, access management systems, encryption, backup and recovery strategies, and IT operations. You are familiar with traditional IT operations as well as all forms and levels of cloud computing. Ideally, you have successfully administered, operated, and managed an SMB IT landscape. - Look behind the curtain: Seeking out the unknown with an investigative mindset is your specialty. You are resistant to the «what you see is all there is» bias. You can spot evasive answers and won't be fooled by them. - Tenacity and diligence: You can confidently distinguish between observation, requirement, recommended action, and root cause, and describe them fluently and in a consistent format. You diligently gather all necessary evidence to support your recommendations and justify any findings of noncompliance. You prepare and compile your reports to good standards. - Data-driven: Your reports are based on facts from the tools and the evidence you collect. You know how to effectively generate and extract reports from the tools at your disposal, both to inform your own decisions and to provide concise and excellent reports to the Information Security Officer, and the SERRALA personnel at all levels with whom you interact. - Experience with GRC tools: It would be good if you have previously managed compliance using an integrated tool (such as SAP GRC, ServiceNow, Hyperproof, OneTrust). - Information security standards expertise: Experience with additional information security standards and certifications (BSI IT-Grundschutz, BSI C5, CC) is a plus. - Personal certification for auditing: Evidence of certified knowledge of auditing methodology would be good. An ISO 27001 Lead Auditor or CISA certification would be a plus.

Standorte