Назад
Company hidden
9 дней назад

Senior IT Auditor (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior IT Auditor (Cybersecurity): Planning, executing, and reporting on operational IT audits across infrastructure, cloud, applications, data management, cybersecurity, and IT controls with an accent on SOX testing, data analytics, and AI-enabled processes. Focus on evaluating control effectiveness, identifying technology risks and deficiencies, and designing actionable recommendations for regulated business environments.

Location: Sleepy Hollow, New York, United States; onsite expectations may apply.

Company

hirify.global is a biotechnology company that develops and commercializes medicines for serious diseases.

What you will do

  • Plan, execute, and report on operational IT audits in line with IIA standards and department methodologies.
  • Evaluate application, infrastructure, cloud, data management, SDLC, change management, and IT operations controls.
  • Perform IT SOX control walkthroughs and testing and prepare supporting documentation.
  • Assess cybersecurity controls covering identity and access management, vulnerability management, logging, monitoring, incident response, and security governance.
  • Design data analytics-driven audit procedures using Dataiku, Alteryx, or equivalent tools to identify anomalies, trends, and control gaps.
  • Communicate audit results, control deficiencies, root causes, risks, and practical recommendations to management and stakeholders.

Requirements

  • Bachelor's degree and 3–4 years of progressive experience in IT audit, information security, or technology risk.
  • Advanced knowledge of IT infrastructure, applications, cybersecurity, and automated controls.
  • Strong understanding of SOX, COSO, COBIT, NIST, GxP, GDPR, and related governance frameworks.
  • Experience auditing infrastructure, operating systems, cybersecurity risks, and controls.
  • Strong analytical, critical-thinking, problem-solving, communication, writing, organization, and attention-to-detail skills.
  • Ability to work independently and collaboratively in a regulated business environment.

Nice to have

  • CISA, CISM, or CISSP certification.
  • Experience with Dataiku, Alteryx, or equivalent data analytics tools.
  • Understanding of AI concepts, model governance, data quality, access controls, ethical use, and AI-enabled processes.
  • Pharmaceutical, life sciences, or other regulated-industry experience.
  • Big Four or public accounting experience.

Culture & Benefits

  • Inclusive workplace and equal opportunity employment.
  • Comprehensive total rewards may include annual bonuses, equity awards, retirement benefits, health and wellness programs, insurance, paid time off, and family support benefits.
  • Reasonable accommodations are provided during recruitment where required by law.
  • Background checks may be conducted in accordance with the laws of the country where the position is based.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →