Назад
2 дня назад

Risk and Audit Lead (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Страна
UK
vacancy_detail.hirify_telegram_tooltipВакансия из Telegram канала -

Мэтч & Сопровод

Покажет вашу совместимость и напишет письмо

Описание вакансии

TL;DR
Risk and Audit Lead (Cybersecurity): Building and running an independent enterprise-wide risk and audit function with an accent on risk frameworks, cybersecurity controls, compliance certifications, and resilience practices. Focus on assessing control gaps, driving audits and remediation, and conducting business continuity and disaster recovery exercises.

Risk and Audit Lead

Company

KAST

Conditions

1 week ago

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will build and run an independent enterprise-wide risk and audit function. You will own risk frameworks, assess controls and cybersecurity practices, drive audit activities, manage resilience exercises, partner with business functions while maintaining independence, and provide regular updates to leadership.

Requirements

  • Have 8 or more years of experience in risk, audit, cybersecurity, or controls with an enterprise-wide perspective
  • Understand enterprise risk management, information security, and technology risk
  • Have experience auditing business and technology environments and identifying control gaps
  • Have led or managed compliance certification projects, including ISO, SOC 2, or PCI DSS
  • Understand access management, data controls, secrets, API keys, and security testing
  • Have stakeholder-management experience with senior leaders, external auditors, and regulators

Responsibilities

  • Build and run an independent enterprise-wide risk and audit function
  • Own the enterprise risk framework and identify, assess, and track risks
  • Define and drive risk management activities, including RCSA and KRIs
  • Drive internal audits, management reporting, and closure of audit findings
  • Validate controls and compliance work independently
  • Review security and technology controls, systems, policies, and processes
  • Assess cybersecurity risks and gaps and ensure testing and remediation
  • Own business continuity, disaster recovery, and business impact assessment practices
  • Conduct annual business continuity and disaster recovery exercises
  • Develop and maintain risk and audit frameworks, policies, and processes
  • Provide regular risk and audit updates to leadership

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →

Текст вакансии взят без изменений

Источник -