9 дней назад
Senior IT Auditor (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior IT Auditor (Cybersecurity): Planning, executing, and reporting on operational IT audits across infrastructure, cloud, applications, data management, cybersecurity, and IT controls with an accent on SOX testing, data analytics, and AI-enabled processes. Focus on evaluating control effectiveness, identifying technology risks and deficiencies, and designing actionable recommendations for regulated business environments.
Location: Sleepy Hollow, New York, United States; onsite expectations may apply.
Company
is a biotechnology company that develops and commercializes medicines for serious diseases.
What you will do
- Plan, execute, and report on operational IT audits in line with IIA standards and department methodologies.
- Evaluate application, infrastructure, cloud, data management, SDLC, change management, and IT operations controls.
- Perform IT SOX control walkthroughs and testing and prepare supporting documentation.
- Assess cybersecurity controls covering identity and access management, vulnerability management, logging, monitoring, incident response, and security governance.
- Design data analytics-driven audit procedures using Dataiku, Alteryx, or equivalent tools to identify anomalies, trends, and control gaps.
- Communicate audit results, control deficiencies, root causes, risks, and practical recommendations to management and stakeholders.
Requirements
- Bachelor's degree and 3–4 years of progressive experience in IT audit, information security, or technology risk.
- Advanced knowledge of IT infrastructure, applications, cybersecurity, and automated controls.
- Strong understanding of SOX, COSO, COBIT, NIST, GxP, GDPR, and related governance frameworks.
- Experience auditing infrastructure, operating systems, cybersecurity risks, and controls.
- Strong analytical, critical-thinking, problem-solving, communication, writing, organization, and attention-to-detail skills.
- Ability to work independently and collaboratively in a regulated business environment.
Nice to have
- CISA, CISM, or CISSP certification.
- Experience with Dataiku, Alteryx, or equivalent data analytics tools.
- Understanding of AI concepts, model governance, data quality, access controls, ethical use, and AI-enabled processes.
- Pharmaceutical, life sciences, or other regulated-industry experience.
- Big Four or public accounting experience.
Culture & Benefits
- Inclusive workplace and equal opportunity employment.
- Comprehensive total rewards may include annual bonuses, equity awards, retirement benefits, health and wellness programs, insurance, paid time off, and family support benefits.
- Reasonable accommodations are provided during recruitment where required by law.
- Background checks may be conducted in accordance with the laws of the country where the position is based.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
12 дней назад
Analyst – IT Infrastructure Audit (Cybersecurity)
71 000 - 121 000$
10 дней назад
Senior Third Party Risk Analyst (Cybersecurity)
12 дней назад
Manager IT Audit (Healthcare)
11 дней назад
Senior Lead IT Auditor
115 000 - 140 000$
14 дней назад
Principal Agentic AI Security Engineer
141 500 - 268 500$
14 дней назад
Sr. Technical Program Manager, Cybersecurity Remediation
145 900 - 234 200$