Associate Information Security Auditor

Center for Internet Security
      3 days ago

      Job Description

      The Associate Information Security Auditor is part of the Corporate department, which resides on the Information Security team and reports to the Director of Information Security. The Associate Information Security Auditor will partner with other cybersecurity team members to promote the CIS mission and support our growth. The primary purpose of this position is to evaluate, oversee, and support the implementation and operation of audit controls within the organization and measure compliance with internal standards and best practices.

      What You'll Do:

      • Define the required controls to be reviewed per the documentation framework and control implementation strategy

      • Review and assess control implementation and effectiveness in accordance with the organization’s information security program, including privacy and artificial intelligence

      • Actively participate in the information security audit engagements by serving as a liaison between external audit entities and internal teams

      • Coordinate with CIS business units to evaluate and promote alignment with control requirements, acting as a governance and oversight function

      • Produce, maintain, and provide control evidence remains with the designated control and evidence owners

      • Demonstrate understanding of the audit frameworks, audit artifact requests, and quality assurance process to ensure that the artifacts provided meet the applicable criteria, including the ability to recreate the artifacts

      • Implement risk-based monitoring to define risk treatment strategies and align to implemented control effectiveness when performing the reviews of the artifacts

      • Assist with day-to-day operational security to ensure functional alignment with applicable policies, standards, frameworks, laws, and regulations

      • Monitor security incidents, metrics, account review, and perform incident response as necessary when deviations from expected baselines occur

      • Provide input into new strategies, technologies, and projects within the organization to assure ‘secure by design’, ‘privacy by design’, and adherence to current control requirements

      • Ensure program level compliance with applicable laws, standards, and guidance

      • Other tasks and responsibilities as assigned

      What You'll Need: 

      • Bachelor’s degree in Computer Science, Cybersecurity, IT Compliance, or related field*

      • 1+ years’ experience in IT auditing, security operations, or related position

      • Experience with the CIS control and compliance evaluation requirements, examples would include (ISO27001, ISO27701, SOC 2, NIST Cybersecurity Framework (CSF), NIST 800-53, NIST 800-171, etc.)

      • Knowledge and application of the CIS Critical Security Controls and MITRE Framework

      • This position requires the individual to be a citizen of the United States of America

      It's a Plus if You Have:

      • Non-Profit experience

      • Contributed to or developed information technology policies, standards, and procedures

      • Experience performing audit, assessment, or compliance oversight activities and communicating control expectations, findings, and cybersecurity best practices to end users, system administrators, peers, and executive leadership

      • CISA certification

      • COBIT5, FIBF, CJIS or other related frameworks for implementing cybersecurity controls

      *Additional years of relevant experience or a combination of an Associate’s degree or equivalent and relevant experience may be substituted for the Bachelor’s degree.

      At CIS, we are committed to providing an inclusive environment in which the diverse backgrounds, experiences, and views of our employees, members, and customers are valued and respected. It is through this commitment that we are able to work together towards our common mission: to make the connected world a safer place.

      Compensation Range:

      USD$29.28 - $46.83

      Numbers & Facts

      Location

      Skills

      • Artificial Intelligence (AI)unmatched
      • Auditingunmatched
      • Best Practicesunmatched
      • Computer Scienceunmatched
      • Computer Securityunmatched
      • Control Objectives for Information and related Technology (COBIT)unmatched
      • Diversityunmatched
      • External Auditunmatched
      • Incident Responseunmatched
      • Information Technology & Information Systemsunmatched
      • Information Technology/Systems Auditunmatched
      • Information/Data Security (InfoSec)unmatched
      • Internal Auditunmatched
      • Internet Securityunmatched
      • Leadershipunmatched
      • Maintain Complianceunmatched
      • Metricsunmatched
      • Operational Auditunmatched
      • Operations Security (OPSEC)unmatched
      • Policy Developmentunmatched
      • Quality Assurance Methodologyunmatched
      • Regulationsunmatched
      • Regulatory Complianceunmatched
      • Risk Managementunmatched
      • Security Auditingunmatched
      • Security Monitoringunmatched
      • Systems Administration/Managementunmatched
      • Technical Strategyunmatched
      • United States Citizenunmatched

      Be found by employers

      5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

      Level up your application

      Professional resume templates

      Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

      Free resume templates

      Free resume builder

      Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

      Free resume builder