Назад
Company hidden
10 дней назад

Information Systems Auditor (Cybersecurity)

Формат работы
remote (только Turkey)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Turkey
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Systems Auditor (Cybersecurity) (ISO 27001/SOC 2): Planning and executing risk-based IT and internal audits while strengthening governance, risk, and compliance capabilities across secure SDLC, cloud infrastructure, software engineering, and AI security, with an accent on certification readiness, control maturity, and privacy. Focus on managing audit findings, leading international compliance programs, assessing third-party and SaaS risks, and guiding the secure adoption of AI, ML, and automation.

Location: Remote, Ankara, Turkey

Company

hirify.global develops a cybersecurity platform for continuous attack-surface, exposure, security-control, and breach-and-attack validation across on-premises, hybrid-cloud, and endpoint environments.

What you will do

  • Plan and execute risk-based IT and internal audits focused on secure SDLC, software engineering, cloud infrastructure, and AI security.
  • Evaluate security and governance controls and drive measurable improvements across policies and processes.
  • Manage audit and security vulnerability findings through remediation and control improvement.
  • Lead global compliance programs covering ISO/IEC 27001, 22301, 27701, 20000-1, SOC 2, NIST CSF, and CSA STAR.
  • Support third-party risk management, SaaS security assessments, vendor due diligence, and customer-facing compliance activities.
  • Define audit and compliance metrics, report insights to stakeholders, and assess the privacy impact of emerging technologies.

Requirements

  • 5+ years of experience in audit, compliance, risk management, or information security, preferably in a SaaS, cloud-native, or technology environment.
  • Hands-on experience with ISO/IEC 27001, 27701, 22301, and 20000-1, as well as SOC 2, including audit preparation, coordination, and evidence management.
  • Experience advising cross-functional stakeholders and improving controls in dynamic technology environments.
  • Practical knowledge of GDPR, CCPA, and related security and privacy compliance practices.
  • Experience with third-party risk management, vendor due diligence, and simultaneous audit or compliance initiatives.
  • Strong written and verbal English is required, including documentation and policy writing.

Nice to have

  • ISO 27001, 22301, 27701, or 20000-1 Lead Auditor certification.
  • CISA, CISM, or CRISC certification.
  • Experience with SOC 2, NIST, or CSA STAR reporting frameworks.
  • ITIL certification.

Culture & Benefits

  • Remote work within the Ankara, Turkey location context.
  • Opportunity to contribute to a cloud-native and AI-driven cybersecurity environment.
  • Work focused on continuous certification readiness, security control maturity, and customer trust.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →