
Information Systems Auditor
Posted Sep 18

Posted Sep 18
This is a fully remote position, open to applicants in Turkey.
• Strategically plan and implement risk-based IT and internal audits, concentrating on secure SDLC, software engineering methodologies, cloud infrastructure, and AI security areas.
• Assess and improve security and governance controls, promoting ongoing enhancement of policies and processes.
• Oversee the management of audit and security vulnerability findings from start to finish, ensuring sustainable remediation and quantifiable control advancements.
• Direct and manage global compliance initiatives, including ISO/IEC 27001, 22301, 27701, 20000-1, SOC 2, NIST CSF, and CSA STAR.
• Ensure continuous readiness for audits and global certifications.
• Contribute to the Third-Party Risk Management program through SaaS security evaluations and vendor due diligence efforts.
• Define and monitor audit and compliance metrics, providing insights to leadership and stakeholders.
• Evaluate the risk and privacy implications of emerging technologies such as AI, ML, and automation.
• Counsel engineering teams on secure technology adoption practices.
• Enhance governance, risk, and compliance capabilities, control maturity, and security and privacy practices throughout the organization.
• A minimum of 5 years of practical experience in audit, compliance, risk management, or information security, ideally in a SaaS, cloud-native, or technology-focused setting.
• Direct experience with ISO/IEC standards (27001, 27701, 22301, 20000-1) and SOC 2, encompassing preparation, audit coordination, and evidence management.
• Proven experience advising diverse stakeholders and driving control improvements in fast-paced technology environments.
• Solid understanding of international security and privacy regulations, including GDPR and CCPA.
• Background in supporting or overseeing Third-Party Risk Management (TPRM), vendor due diligence, and customer-facing compliance activities.
• Capability to manage multiple audits and compliance projects concurrently in a dynamic environment.
• Excellent verbal and written communication skills in English, including documentation and policy formulation.
• Preferred certifications: ISO 27001, 22301, 27701, 20000-1 LA.
• Preferred certifications: CISA, CISM, or CRISC.
• Familiarity with SOC 2, NIST, and CSA STAR reporting frameworks.
• ITIL certification is a desirable addition.
• Candidates must undergo reference and identity verifications upon conditional offer in accordance with local labor laws and company policy.
• Engaging work with the chance to shape and lead an innovative, rapidly growing cybersecurity segment.
• Opportunities for career advancement and increased responsibilities.
• Global exposure and interaction with clients worldwide.
• A remote team environment that spans across the globe.
• Commitment to equal opportunity employment.
• Reference and identity checks will be conducted according to local labor laws and company policy upon conditional offer.
• Candidate personal data will be processed in compliance with applicable data protection regulations.
St. Charles Health System
ExamWorks
ExamWorks
Get handpicked remote jobs straight to your inbox weekly.