TL;DR
Senior IT Security Controls Assurance Analyst: Evaluating and testing the effectiveness of security controls both on-premise and in the cloud with an accent on control design, performance, and compliance with industry standards and regulatory requirements. Focus on identifying control gaps, documenting findings, and providing recommendations for improvements to mitigate risks.
Location: Heredia
Company
hirify.global is a global data and technology company, powering opportunities for people and businesses around the world.
What you will do
- Conduct security control assessments, using documented control activities and regulatory requirements.
- Develop and execute test plans, test cases, and procedures, using data from security tools to capture evidence.
- Use queries and dashboards to identify potential control failures as part of the control testing process.
- Document findings, including root cause analysis and applicable recommendations for remediation.
- Liaise with business stakeholders, delivering clear progress updates and results.
- Integrate partner feedback to improve the control testing program.
Requirements
- Bachelor's degree in computer science, management information systems, relevant field, or equivalent demonstrable experience.
- Advanced English proficiency.
- 3+ years' experience performing IT Audit or security control testing.
- 5+ years' of experience in Information Security or Information Technology.
- Professional certification such as CISA, CISM, CISSP, ISO 27001 Lead Auditor, or equivalent.
- Familiarity with industry standards and frameworks e.g., NIST 800-53, ISO 27001/27002, CIS Controls, COBIT.
Culture & Benefits
- Medical, life and dental insurance.
- Flex Work/Work from home options.
- Paid time off and Birthday day off.
- Annual Performance Bonus.
- Education Reimbursement.
- Focus on DEI, work/life balance, development, authenticity, collaboration, wellness, reward and recognition, and volunteering.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →