TL;DR
Cloud Technology Auditor (Cybersecurity): Independently assessing the firm’s internal control structure related to cloud computing environments with an accent on integrity, security, and compliance. Focus on evaluating cloud security configurations, identity and access management, data encryption, and network security within cloud platforms.
Location: Onsite in Dallas, Texas, United States
Company
hirify.global is a leading global investment banking, securities, and investment management firm committed to helping clients, shareholders, and communities grow.
What you will do
- Perform regular risk assessments for the cloud technology coverage area.
- Lead audit work, including defining the scope of risks and controls, and assessing controls design and effectiveness.
- Review audit work and report findings to internal and external management.
- Validate the closure of management action points.
- Continuously monitor business and technology developments, regulatory requirements, and industry standards.
- Manage, coach, and develop the audit team.
Requirements
- More than 8 years of relevant audit experience, focusing on Financial Services.
- Possess a degree in Computer Science, Information Security, Engineering, or equivalent.
- Must be highly motivated with strong analytical skills, willing and able to learn new business and system processes quickly.
- Ability to work effectively across a large audit team, understanding the team's role in the overall strategy of the firm.
- Must be able to multitask while managing both time and workload.
- Written and verbal communication skills are a must; strong interpersonal skills are essential for frequent interaction with technology management.
Nice to have
- Deep understanding of Cloud computing, technologies, risks, and mitigating controls.
- In-depth understanding of cloud computing concepts, architecture, and service models (IaaS, PaaS, SaaS).
- Familiarity with cloud-native security tools and services (e.g., AWS Security Hub, Azure Security Center, GCP Security Command Center).
- Proficiency in auditing various cloud services, including compute, storage, networking, databases, and serverless functions.
- Proficiency in auditing controls related to cloud security configurations, identity and access management (IAM), data encryption, network security, logging and monitoring, and incident response within cloud platforms.
- Understanding of DevOps, CI/CD pipelines, and infrastructure as code (IaC) in a cloud context.
- Relevant certification or industry accreditation.
Culture & Benefits
- Commitment to fostering and advancing diversity and inclusion in the workplace.
- Opportunities for professional and personal growth through training and development.
- Access to firmwide networks, benefits, wellness, personal finance offerings, and mindfulness programs.
- Commitment to finding reasonable accommodations for candidates with special needs or disabilities during the recruiting process.
- Offers best-in-class benefits.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →