
Cybersecurity Auditor
Posted Sep 29

Posted Sep 29
This is a fully remote position, open to applicants in Brazil.
• Conduct risk-based audits by setting objectives, evaluating processes and associated risks, and designing as well as executing control tests.
• Evaluate the effectiveness of controls in mitigating risks.
• Convey impacts on objectives clearly.
• Formulate recommendations and compile final reports that outline the effectiveness of controls for each identified risk.
• Clearly and professionally articulate issues, risks, and technical information to both technical and non-technical audiences.
• Lead teams of IT auditors during assigned audit engagements.
• Perform or assist with cybersecurity audits, security assessments, risk reviews, and compliance activities.
• Review IT controls, processes, and security configurations, including change management, incident handling, access control, patch management, API security, inventory management, vulnerability assessments, operations, database management, and risk management.
• Assess authentication and authorization processes, secure system and application configurations, data integrity and protection measures, security assessments, business continuity strategies, and disaster recovery plans.
• A minimum of 5 years of professional experience in Information Technology, Cybersecurity, Information Security, Technology Risk, IT Operations, Application Development, Cloud Technologies, or a related technical field.
• Experience in Cybersecurity, SOX compliance, Risk Management, or IT auditing.
• Strong understanding of Cybersecurity laws, regulations, and standards.
• Familiarity with COBIT, ISO 27001/27002, NIST, COSO, and general security practices.
• Capability to execute risk-based audits by defining objectives, assessing processes and risks, testing control effectiveness, communicating impacts, formulating recommendations, and reporting effectiveness conclusions for each risk.
• In-depth knowledge of Cybersecurity processes and concepts, including incident response, secure software development, security governance, cloud computing, SDLC, third-party risk management, penetration testing, vulnerability management, disaster recovery, segregation of duties, audit logging, physical security, access management, and configuration management.
• Experience in conducting or supporting cybersecurity audits, security assessments, risk reviews, or compliance activities within a large or global organization.
• Exceptional time-management skills.
• Proficient in clearly and professionally communicating issues, risks, and technical information in English to both technical and non-technical audiences.
• Relevant professional certifications such as CISA, CISM, CISSP, PCIP, Security+, or CC.
• A bachelor's or master's degree in Information Security, Information Systems, Computer Science, or a related field is preferred.
• Working hours are from 8:00 AM to 5:00 PM, Monday to Friday.
• A flexible and supportive work environment.
• Well-being support through the Be Well programs, which encompass financial, mental, physical, and social health.
• Customized development goals with continuous feedback.
• Access to cutting-edge learning opportunities.
• Opportunities to obtain certifications with Microsoft, Google, and Amazon.
• Coaching and hands-on experiences.
• A hybrid-friendly culture.
• Employee referral opportunities.
Integrity360
Rackspace Technology
Efficient Computer
Presidio
Get handpicked remote jobs straight to your inbox weekly.