Security Consultant-Audit & Compliance
Core
Senior Consultant accountable for supporting processes to limit audit findings and non-compliances by managing internal audits, penetration tests, and annual assurance reports (ISAE 3000, 3402, SOC2 Type 2).
Role type
Senior IC Security Audit & Compliance Consultant
Builds
Internal and external audit processes, assurance reports, and control frameworks for global customers.
Domain
IT Security, Compliance, and Audit (ISAE, SOC2, SOx, PCI-DSS, GDPR)
Deliverable
client delivery
Required skills
Managing internal and external audits, executing annual assurance plans, monitoring Critical Service Levels and KPIs, drafting assurance reports, escalating management decisions, interpreting audit requests, documenting remediation in Jira, providing security awareness training
Preferred skills
CISM or CGEIT certification, project management, agile development methodology, data privacy regulations
Technologies
Jira, ISAE 3000, ISAE 3402, SOC1, SOC2, ISO 27002, CoBIT, ITIL
Responsibilities
Coordinate internal and external stakeholders for audit processes, propose and manage control framework elements, support corrective measures for audit findings, communicate audit details and findings to stakeholders, upload audit results to Jira, deliver written sections of draft assurance reports
Seniority
Senior, hands-on IC